CN103617402B - A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system - Google Patents

A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Download PDF

Info

Publication number
CN103617402B
CN103617402B CN201310607114.8A CN201310607114A CN103617402B CN 103617402 B CN103617402 B CN 103617402B CN 201310607114 A CN201310607114 A CN 201310607114A CN 103617402 B CN103617402 B CN 103617402B
Authority
CN
China
Prior art keywords
electronic data
report
file
multimedia
multimedia electronic
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201310607114.8A
Other languages
Chinese (zh)
Other versions
CN103617402A (en
Inventor
张建明
鲜文兵
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Ruian Technology Co Ltd
Original Assignee
Beijing Ruian Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Ruian Technology Co Ltd filed Critical Beijing Ruian Technology Co Ltd
Priority to CN201310607114.8A priority Critical patent/CN103617402B/en
Publication of CN103617402A publication Critical patent/CN103617402A/en
Application granted granted Critical
Publication of CN103617402B publication Critical patent/CN103617402B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures

Abstract

The present invention relates to a kind of multimedia electronic data forensic report and generation, methods of exhibiting and system, this system comprises, the harvester of multimedia electronic data forensic report; Multimedia electronic data forensic report generating apparatus; Certification exhibiting device, adopting data decryption, the self-extracting inspection header file when report of collecting evidence is shown of compression algorithm, method of calibration, irreversible cryptographic algorithm and correspondence, merging and generating multimedia reports by the data file of compression when collecting evidence report generation.Method and system of the present invention can guarantee the integrality of electronic multimedia data, anti-tamper and security on the whole.No matter Computer forensics is text or audiovisual materials, can carry out integrity techniques anti-tamper by the tamper resistant device closed, and adds electronic evidence and show authentication mechanism, and processing procedure is safer, hidden.

Description

A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system
Technical field
The invention belongs to Computer forensics field, relate to fixing, the transmission of electronic multimedia data evidence, reproduce.
Background technology
In the face of information-based, digitized today, the collection of Computer forensics and fixing behavior require the primitiveness principle based on electronic evidence, must ensure that electronic evidence is from producing to the completeness and efficiency exported.The electronic evidence of traditional content of text, by printing, indicating evidence obtaining time, evidence obtaining personnel, Data Source etc., and after stamping an offical seal, being fixed preservation with the form of documented evidence, preventing the integrality of electronic evidence fixation procedure from being destroyed; Traditional has audiovisuals, as comprised the evidence of audio frequency, video, adopts the method for taking pictures and making a video recording to be fixed evidence.
Prior art is mainly used in digital signature technology, by calculating the unique digital digest value of electronic data or check code, ensure the integrality of Computer forensics, but all do not relate to the total solution how electronic multimedia data evidence to fix, transmit and reproduce in the prior art.It is as follows that prior art forms the weak area of existence to electronic evidence: how (1) electronic multimedia data evidence is fixed, and does not have corresponding informationization technology scheme; (2) in electronic multimedia data evidence, relate to a large amount of sounds, video data, if traditionally signed one by one, so certain file and corresponding signature can be deleted simultaneously and be not found in transmitting procedure, thus destroy the integrality of evidence; If to the sound related to, video data entirety packing signature, whether the showing problem related to has the solution of specification; (3) do not add encryption mechanism in employing digital signature procedure, the intrusion of rogue program may be there is, destroy the validity of signature.
Summary of the invention
An object of the present invention is to provide the generation of a kind of multimedia electronic data forensic report, methods of exhibiting, guarantees the integrality of electronic multimedia data, anti-tamper and security on the whole.No matter Computer forensics is text or audiovisual materials, can carry out integrity techniques anti-tamper by the tamper resistant device closed, and adds electronic evidence and show authentication mechanism, and processing procedure is safer, hidden.
A kind of multimedia electronic data forensic report generation method, its step comprises:
1) the preliminary electron evidence obtaining that the electronic data extracting at least one type is also set up based on file directory is reported;
2) described preliminary electron file evidence obtaining report is compressed be merged into single compressed file and log file memory location;
3) using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document;
4) preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout.
Preferably, the described evidence obtaining of the preliminary electron based on file directory report is based on html Hypertext Markup Language.
Preferably, MD5 or SHA1 is adopted to calculate document.
Preferably, the method verifying the electronic data evidence obtaining report be not tampered according to described document is:
Whether the document that the document relatively calculated produces when reporting with generation electronic data evidence obtaining is identical, if identical, then multimedia electronic data forensic file is complete and is not tampered; If not identical, then multimedia electronic data forensic file was tampered, and reminder-data is imperfect, needed to regain evidence obtaining report from raw data source.
Preferably, run in displaying in multimedia evidence obtaining report, add signature authentication mechanism, display authentication signature unit, makes multimedia reports safer and more effective in transmitting procedure.
Preferably, the electronic data of at least one type comprises: word document, excel document, note, message registration, photo, recording, video recording.
Further, according to the checking methods of exhibiting of a kind of multimedia electronic data forensic report that described multimedia electronic data forensic report generation method generates, its step comprises:
1) computing machine and/or the mobile terminal device Bootloader that described multimedia electronic data forensic report are transferred to needs displaying decrypt document, file storage location and file symmetric cryptographic key;
2) verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown;
3) described report boot deletes temporary file automatically, completes displaying.
Preferably, described multimedia electronic data forensic report, when showing, adds signature authentication mechanism, display authentication signature unit.
Preferably, described multimedia electronic data forensic report to be transferred to the computing machine and/or mobile terminal device that need to show by the mode transmitted by USB flash disk copy, network.
Another object of the present invention is to provide a kind of multimedia electronic data forensic report, comprise through asymmetric encryption: document, file storage location, compressed file symmetric cryptographic key and a boot;
Stochastic generation character string key obtains by described compressed file symmetric cryptographic key;
Described document is by being encrypted acquisition to described compressed file;
Described boot is used for after user runs this multimedia electronic data forensic report, verifies the integrality of multimedia evidence obtaining report;
Automatically this multimedia show catalogue is shown when described file storage location is for recording and preserving this multimedia electronic data forensic report.
Another object of the present invention is to provide a kind of multimedia electronic data forensic report to generate display systems, solve fixing, transmit and showing of electronic multimedia data evidence on the whole, concrete technical scheme is as follows:
The present invention also proposes the generation of a kind of multimedia electronic data forensic report, display systems, comprising: the harvester of multimedia electronic data forensic report; Multimedia electronic data forensic report generating apparatus; Certification exhibiting device;
The harvester of described multimedia electronic data forensic report, for gathering the electronic data of at least one type from computing machine and/or mobile terminal device;
Described multimedia electronic data forensic report generating apparatus, for also setting up the preliminary electron evidence obtaining report based on file directory according to the electronic data extracting at least one type obtained; Described preliminary electron file evidence obtaining report is compressed and is merged into single compressed file and log file memory location; Using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document; Preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout;
Described certification exhibiting device, decrypts document, file storage location and file symmetric cryptographic key for the computing machine and/or mobile terminal device Bootloader described multimedia electronic data forensic report being transferred to needs displaying; Verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown; Described report boot deletes temporary file automatically, completes displaying.
Beneficial effect of the present invention:
Compared with prior art, the present invention is reported in data in transmitting procedure carries out integrity protection to multimedia evidence obtaining.
1) by compressing multimedia data, calculation document proof test value, generates enciphered data, inspection header file, and to and the proof test value encryption that generates, effectively prevent malicious user from changing the object of proof test value.
2) data file of compression is adopted the data decryption of compression algorithm, method of calibration, irreversible cryptographic algorithm and correspondence, self-extracting inspection header file, merge and generate multimedia reports.
3) run in displaying in multimedia evidence obtaining report, add signature authentication mechanism, display authentication signature unit, makes multimedia reports safer and more effective in transmitting procedure.
Accompanying drawing explanation
Fig. 1 is the schematic diagram realizing using multimedia electronic data forensic report in one embodiment of the invention;
Fig. 2 is multimedia electronic data forensic report file generated flowchart in one embodiment of the invention
Fig. 3 is that process flow diagram is shown in the certification of multimedia electronic data forensic report in one embodiment of the invention:
Fig. 4 is the schematic flow sheet for certain electronic data evidence obtaining evaluating center, certain mobile phone being reconnoitred to qualification in one embodiment of the invention.
Fig. 5 is that in one embodiment of the invention, expert assignment raiser can, by multimedia electronic data forensic report on general computing machine, carry out browsing, showing schematic diagram.
Embodiment
In order to make object of the present invention, technical scheme definitely, coordinate accompanying drawing below by way of specific embodiment, the present invention is described in detail.
Fixing, the transmission of multimedia electronic data forensic report and displaying process have related to a kind of multimedia electronic data forensic report and have generated display systems in one embodiment of this invention, comprise three parts: the harvester of multimedia electronic data forensic report; Multimedia electronic data forensic report generating apparatus; Certification exhibiting device; Below the detailed description to device:
Multimedia electronic data forensic report harvester, for gathering text, photo, audio frequency, audio-visual-materials from computing machine, mobile terminal device.In computing machine and mobile terminal device, there is a large amount of electronic data, harvester can according to the requirement of electronic multimedia data report user, and electronic data evidence obtaining personnel can preset the multiple media types read, choose.Preset and which which kind electronic data can be selected as Computer forensics, as word document, excel document, note, message registration, photo, recording, video recording etc.
Select specific electronic data type after collecting multi-medium data, as Computer forensics, be supplied to user.The files such as the text collected, photo, audio frequency, video, generally directly can carry out browsing, analyzing on collecting device.The text that multimedia evidence collecting apparatus collects, photo, audio frequency, video file, will import multimedia electronic data forensic report generating apparatus into as input.
Multimedia electronic data forensic report generating apparatus, for text, photo, audio frequency, the audio-visual-materials that will gather, forms Single document after the form of catalogue, compression, summary, encryption.
Understand that the form of catalogue refers to those skilled in the art know that: the electronic data extracted from mobile communication equipment or computing machine, the conveniently analysis and understanding of the user of multimedia electronic data forensic report, according to electronic data type, as address list, message registration, photos etc., show step by step with the form of catalogue.
In the present invention by after compression, multiple multimedia electric document is merged into a single file.
The integrality of object to file of described summary verifies, and after calculating summary, is encrypted summary.Once file is modified, just by comparing summary, can find that file is modified.Because summary encryption adopts rivest, shamir, adelman, the summary after encryption therefore cannot be forged.
Described encryption refers to: what adopt the encryption of summary is rivest, shamir, adelman, and what adopt the encryption of whole file is symmetric encipherment algorithm.
The certification exhibiting device of described multimedia electronic data forensic report, for after confirmation multimedia electronic data forensic report integrality and consistance, shows multimedia electronic data forensic report.
Multimedia electronic data forensic report generates a methods of exhibiting in one embodiment of this invention, the steps include:
The first step, after user selects specific electronic data from electronic multimedia data collector, sends multimedia electronic data forensic report generating apparatus to as input.Multimedia electronic data forensic report generating apparatus is according to the internal association relation of electronic data, and the electronic data evidence obtaining based on file directory conveniently browsed set up based on html identifiable language is reported.After this step completes, namely form preliminary html evidence obtaining report, by the catalogue format of html, various forensic information can be browsed easily.Html i.e. " hypertext " just refers in the page and can comprise picture, link, the even non-legible element such as music, program.The structure of HTML (Hypertext Markup Language) comprises head part (Head) and main part (Body), and wherein head (head) provides the information about webpage, and main body (body) part provides the particular content of webpage.
Second step, report of being collected evidence by html based on file directory form is carried out compression and is merged, form a single compressed file (compressed file is merged in the evidence obtaining report compression by html), and (html file is as the displaying catalogue of multimedia electronic data forensic report to record the file storage location of html file, need the relative position in compressed package recording this file, be convenient to like this, when showing media evidence obtaining report, automatically show this multimedia catalogue.)。Automatic generation character string password, namely inputs as to the key of the symmetric encipherment algorithm of file after compression, is encrypted the compressed file generated.The document adopting MD5 or SHA1 to calculate this compressed file obtains proof test value, employing be the method for calibration of standard, namely irreversible hash value compares, and does not do concrete restriction in the present invention.By the document, symmetric cryptography password (character string of automatically producing is secret), the html file storage location information that generate, prefabricated rivest, shamir, adelman is used to be encrypted.
3rd step, document after data file after multimedia electronic data forensic report process boot, compress-encrypt, encryption and symmetric cryptography password, html file storage location information are carried out unifying process, generates the multimedia evidence obtaining report of single file layout.The effect of described boot is after double-click runs multimedia evidence obtaining report, the integrality of multimedia evidence obtaining report is verified, if multimedia evidence obtaining report is not modified, multimedia evidence obtaining report based on html catalogue can parse by it, and opens html catalogue for user and browse.
The certification exhibiting device of multimedia electronic data forensic report, for after confirmation multimedia electronic data forensic report integrality and consistance, show multimedia electronic data forensic report, methods of exhibiting is as follows:
The first step, multimedia electronic data forensic report boot, decrypts the key of document asymmetric encryption, symmetric cryptographic key and html file storage location information.
Second step, to the multimedia data file of compress-encrypt, makes a summary by the algorithm calculation document identical with production multimedia electronic data forensic report.The document that the document relatively calculated and the first step obtain, if identical, then think that multimedia electronic data forensic file is complete and was not tampered, enters the 3rd step; If not identical, illustrate that multimedia electronic data forensic file was tampered, reminder-data is imperfect, after needing to obtain evidence obtaining report from raw data source, exits processing procedure.
3rd step, uses the symmetric cryptographic key that the first step obtains, and is decrypted (when showing, using the compressed file after the key pair encryption in step 2 to be decrypted) the electronic multimedia data file after compress-encrypt, generates a single compressed file.To this compressed file, use decompression algorithm corresponding to compression algorithm to carry out decompress(ion), generation result is saved in temporary file directory.
4th step, multimedia electronic data forensic report boot calls the browser on demonstrating computer, using html file storage location information as input, according to the electronic multimedia data directory preset, shows forensic information.
5th step, has shown multimedia electronic data forensic report, after closing corresponding browser, and the temporary file that the automatic delete program of multimedia electronic data forensic report boot generates.
Above-mentioned exhibition method also comprises signature mechanism, is the authentication to multimedia electronic data forensic report collection people.
Fig. 1 is the schematic diagram realizing using multimedia electronic data forensic report in one embodiment of the invention.Electronic data evidence obtaining person carries out multi-medium data collection, has gathered rear formation multimedia electronic data forensic report.According to this multimedia electronic data forensic report, electronic multimedia report user directly can carry out displaying user with it.
Fig. 2 is multimedia electronic data forensic report file generated flowchart in one embodiment of the invention.Flow process is as follows:
1) electronic multimedia data multi-medium data collection obtained or the source data chosen for generating multimedia electronic data forensic report;
2) according to the electronic multimedia data report of the data genaration obtained based on the html of file directory;
3) single file layout is compressed into;
4) encryption, calculation document summary;
5) use rivest, shamir, adelman that document, file encryption password, html are existed to routing information and be encrypted;
6) electronic multimedia data report is generated.
Fig. 3 is that process flow diagram is shown in the certification of multimedia electronic data forensic report in one embodiment of the invention.Flow process is as follows:
1) multimedia electronic data forensic report is by modes such as USB flash disk copy, network transmission, is sent to the computing machine needing to carry out the displaying of electronic data evidence obtaining result;
2) multimedia electronic data forensic report file is double-clicked;
3) multimedia electronic data forensic report boot restores document, Crypted password, and html stores the information such as Lu Jing;
4) calculation document summary, and compare with the document stored, if summary is not identical, then points out multi-medium data evidence obtaining report to be tampered, terminate to open; Identical if make a summary, then by multimedia electronic data forensic file decryption, unzip to temporary path;
5) browser that use system carries is shown html, realizes the displaying to electronic multimedia data;
6) complete and rear cut out browser browses to multimedia evidence obtaining report, automatically delete the temporary path generated and file.
Be certain electronic data evidence obtaining evaluating center be as shown in Figure 4 that example reconnoitres the schematic flow sheet of qualification to certain mobile phone.When certain electronic data evidence obtaining evaluating center accepts a task, evaluating center assigns identifier to identify this mobile phone, after this identifier carries out evidence obtaining qualification to this mobile phone, utilize multimedia electronic data forensic report generation technique, generate the multimedia electronic data forensic report that can depart from evidence obtaining evaluation apparatus.This multimedia electronic data forensic report is copied in the form of a file or is sent to expert assignment raiser by network.Following operation is carried out in multimedia electronic data forensic report generating apparatus:
1) html generated based on file path reports;
2) document, symmetric cryptography password, the html file storage location information that will generate, use prefabricated rivest, shamir, adelman to be encrypted;
3) multimedia electronic data forensic report boot, compressed file and relevant information process are generated electronic multimedia evidence obtaining report.
Determine task raiser shown in Fig. 5, can by multimedia electronic data forensic report browsing on general computing machine, show schematic diagram.By the asymmetric encryption techniques applied in multimedia electronic data forensic report, integrality and the consistance of electronic data can be guaranteed.Idiographic flow is as follows:
1) expert assignment raiser, obtains multimedia electronic data forensic report file;
2) show in authenticate device in multimedia electronic data forensic report, multimedia electronic data forensic report boot is analyzed evidence obtaining report;
3) integrality and the consistance of evidence obtaining report is determined;
4) temporary folder is unziped to;
5) multimedia evidence obtaining report is browsed and shown;
6), after having shown, temporary file is deleted.

Claims (11)

1. a multimedia electronic data forensic report generation method, its step comprises:
1) the preliminary electron evidence obtaining that the electronic data extracting at least one type is also set up based on file directory is reported;
2) described preliminary electron file evidence obtaining report is compressed be merged into single compressed file and log file memory location;
3) using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document;
4) preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout.
2. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, the described evidence obtaining of the preliminary electron based on file directory report is based on html Hypertext Markup Language.
3. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, adopts MD5 or SHA1 to calculate document.
4. multimedia electronic data forensic report generation method according to claim 1, it is characterized in that, run in displaying in multimedia evidence obtaining report, add signature authentication mechanism, display authentication signature unit, makes multimedia reports safer and more effective in transmitting procedure.
5. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, the electronic data of at least one type comprises: word document, excel document, note, message registration, photo, recording, video recording.
6. the multimedia electronic data forensic report that multimedia electronic data forensic report generation method according to claim 1 generates verifies methods of exhibiting, and its step comprises:
1) computing machine and/or the mobile terminal device Bootloader that described multimedia electronic data forensic report are transferred to needs displaying decrypt document, file storage location and file symmetric cryptographic key;
2) verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown;
3) described report boot deletes temporary file automatically, completes displaying.
7. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, is characterized in that, the method verifying the electronic data evidence obtaining report be not tampered according to described document is:
Whether the document that the document relatively calculated produces when reporting with generation electronic data evidence obtaining is identical, if identical, then multimedia electronic data forensic file is complete and is not tampered; If not identical, then multimedia electronic data forensic file was tampered, and reminder-data is imperfect, needed to regain evidence obtaining report from raw data source.
8. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, it is characterized in that, described multimedia electronic data forensic report, when showing, adds signature authentication mechanism, display authentication signature unit.
9. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, it is characterized in that, copied by USB flash disk and/or network transmit mode described multimedia electronic data forensic report is transferred to need show computing machine and/or mobile terminal device.
10. a multimedia electronic data forensic report, is characterized in that, comprises through asymmetric encryption: document, file storage location, compressed file symmetric cryptographic key and a boot;
Described compressed file symmetric cryptographic key is obtained by stochastic generation character string;
Described document is by being encrypted acquisition to described compressed file;
Described boot is used for after user runs this multimedia electronic data forensic report, verifies the integrality of multimedia evidence obtaining report;
Automatically this multimedia show catalogue is shown when described file storage location is for recording and preserving this multimedia electronic data forensic report.
11. 1 kinds of multimedia electronic data forensic report generate, display systems, it is characterized in that, comprising: the harvester of multimedia electronic data forensic report; Multimedia electronic data forensic report generating apparatus; Certification exhibiting device;
The harvester of described multimedia electronic data forensic report, for gathering the electronic data of at least one type from computing machine and/or mobile terminal device;
Described multimedia electronic data forensic report generating apparatus, for also setting up the preliminary electron evidence obtaining report based on file directory according to the electronic data extracting at least one type obtained; Described preliminary electron file evidence obtaining report is compressed and is merged into single compressed file and log file memory location; Using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document; Preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout;
Described certification exhibiting device, decrypts document, file storage location and file symmetric cryptographic key for the computing machine and/or mobile terminal device Bootloader described multimedia electronic data forensic report being transferred to needs displaying; Verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown; Described report boot deletes temporary file automatically, completes displaying.
CN201310607114.8A 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Active CN103617402B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310607114.8A CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310607114.8A CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system

Publications (2)

Publication Number Publication Date
CN103617402A CN103617402A (en) 2014-03-05
CN103617402B true CN103617402B (en) 2016-03-30

Family

ID=50168105

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310607114.8A Active CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system

Country Status (1)

Country Link
CN (1) CN103617402B (en)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105049581B (en) * 2015-03-31 2018-05-29 杭州猿人数据科技有限公司 Telephonograph evidence processing system and processing method
CN105139322B (en) * 2015-07-02 2019-01-25 盘石软件(上海)有限公司 A kind of distributed electronic data evidence obtaining system and method
CN105354773B (en) * 2015-10-28 2020-05-12 重庆邮电大学 System for evidence preservation and verification on traffic accident scene
CN105635257A (en) * 2015-12-24 2016-06-01 福建天泉教育科技有限公司 Method and system for automatically detecting data update
CN106850793A (en) * 2017-01-23 2017-06-13 重庆邮电大学 A kind of method that remote trusted towards Android phone is collected evidence
CN107871063A (en) * 2017-11-16 2018-04-03 王磊 Anti-tamper video and audio recording digital signature method, device and storage medium
CN114065139A (en) * 2020-08-04 2022-02-18 成都鼎桥通信技术有限公司 Multimedia file tamper-proof method and device

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1928842A (en) * 2005-09-07 2007-03-14 创惟科技股份有限公司 Method for protecting enciphered data in high private non-sequential hidden block memory for large data memory device
CN102325139A (en) * 2011-09-14 2012-01-18 福建伊时代信息科技股份有限公司 Electronic document processing method, processing system and verification system
CN102724044A (en) * 2012-07-04 2012-10-10 东方金盾科技有限公司 Electronic evidence verification and preservation method
CN103400083A (en) * 2013-07-08 2013-11-20 福建伊时代信息科技股份有限公司 Method, device and system for protecting electronic evidence

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1928842A (en) * 2005-09-07 2007-03-14 创惟科技股份有限公司 Method for protecting enciphered data in high private non-sequential hidden block memory for large data memory device
CN102325139A (en) * 2011-09-14 2012-01-18 福建伊时代信息科技股份有限公司 Electronic document processing method, processing system and verification system
CN102724044A (en) * 2012-07-04 2012-10-10 东方金盾科技有限公司 Electronic evidence verification and preservation method
CN103400083A (en) * 2013-07-08 2013-11-20 福建伊时代信息科技股份有限公司 Method, device and system for protecting electronic evidence

Also Published As

Publication number Publication date
CN103617402A (en) 2014-03-05

Similar Documents

Publication Publication Date Title
CN103617402B (en) A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system
Li et al. LEChain: A blockchain-based lawful evidence management scheme for digital forensics
EP3710974B1 (en) Method and arrangement for detecting digital content tampering
CN110798315B (en) Data processing method and device based on block chain and terminal
CN103152182B (en) A kind of electronic data authentication verification method
CN103189872B (en) Safety in networked environment and the effectively method and apparatus of Content Selection
Accorsi BBox: A distributed secure log architecture
CN113378236B (en) Evidence data online security notarization platform and security method
JP2010050760A (en) Content protection apparatus, and content utilization apparatus
US11394538B2 (en) System and method for verifying the no-later-than date-of-existence, data integrity, identity of the recorder, and timestamp of the recording for digital content
CN110601848B (en) Appointment information processing method, device and system based on block chain and electronic equipment
CN105338119A (en) Electronic evidence fixing security system based on cloud storage
US20110055590A1 (en) Apparatus and method for collecting evidence data
Accorsi A secure log architecture to support remote auditing
CN110958319A (en) Method and device for managing infringement and evidence-based block chain
CN109151506A (en) A kind of method of video file operation, system and server
CN110175067A (en) A kind of mobile application tank force three-dimensional defence method and system
CN115982764A (en) Method, system, device and medium for storing electronic file based on block chain
Garfinkel Providing cryptographic security and evidentiary chain-of-custody with the advanced forensic format, library, and tools
CN108900472B (en) Information transmission method and device
KR101497067B1 (en) Electric document transfer method and apparatus based digital forensic
CN110493011B (en) Block chain-based certificate issuing management method and device
CN112583772B (en) Data acquisition and storage platform
CN108171078B (en) Data preservation method and device of cloud platform evaluation system facing third party
JP4842863B2 (en) Screening equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant