WO2020253068A1 - 共享文件安全管理方法、装置、终端及可读存储介质 - Google Patents

共享文件安全管理方法、装置、终端及可读存储介质 Download PDF

Info

Publication number
WO2020253068A1
WO2020253068A1 PCT/CN2019/118599 CN2019118599W WO2020253068A1 WO 2020253068 A1 WO2020253068 A1 WO 2020253068A1 CN 2019118599 W CN2019118599 W CN 2019118599W WO 2020253068 A1 WO2020253068 A1 WO 2020253068A1
Authority
WO
WIPO (PCT)
Prior art keywords
level file
answer
password
file
secret
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/118599
Other languages
English (en)
French (fr)
Inventor
刘翔
殷兆芳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ping An Technology Shenzhen Co Ltd
Original Assignee
Ping An Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ping An Technology Shenzhen Co Ltd filed Critical Ping An Technology Shenzhen Co Ltd
Publication of WO2020253068A1 publication Critical patent/WO2020253068A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2113Multi-level security, e.g. mandatory access control
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices

Definitions

  • This application relates to the technical field of cloud desktop office, and in particular to a method, device, terminal and readable storage medium for the security management of shared files.
  • the first aspect of the present application provides a shared file security management method, which is applied to a terminal, and the method includes:
  • the first security level file is opened, and the first security level file includes a second security level file, and the second security level file is displayed There is an encryption identifier, and the encryption identifier is used to prompt a user who does not have the operation authority to operate the second-secret level file not to operate the second-secret level file;
  • the second operation is performed on the second secret level file.
  • a second aspect of the present application provides a shared file security management device, the device includes:
  • An obtaining module configured to obtain the face image of the user who performed the first operation on the first security file when the first operation on the first security file is received;
  • a display module configured to display a password input box corresponding to the face image when the face image is recognized as a face image in the preset whitelist;
  • the first judgment module is configured to judge whether the password matches the password corresponding to the preset first secret level file when it is detected that the password is received in the password input box;
  • the opening module is configured to open the first security level file when the first judgment module determines that the password matches the password corresponding to the preset first security level file, and the first security level file includes the second A secret level file, where an encryption mark is displayed on the second secret level file, and the encryption mark is used to remind users who do not have the operation authority to operate the second secret level file not to operate on the second secret level file;
  • the pop-up module is configured to randomly pop up a question dialog box when a second operation on the second-secret file is received;
  • the second judgment module is used for judging whether the pending answer matches the preset standard answer of the question when it is detected that the pending answer is received in the question dialog box;
  • the execution module is configured to execute the second operation on the second secret level file when the second judgment module determines that the answer to be verified matches the standard answer.
  • a third aspect of the present application provides a terminal.
  • the terminal includes a processor configured to implement the shared file security management method when executing at least one computer-readable instruction stored in a memory.
  • a fourth aspect of the present application provides a non-volatile computer-readable storage medium having at least one computer-readable instruction stored on the non-volatile computer-readable storage medium, and the computer-readable instruction is executed by a processor
  • the security management method for shared files is realized at the time.
  • the shared file security management method, device, terminal, and readable storage medium described in this application first determine whether the face image of the user who performs the first operation on the first-secret file is a person in the whitelist Face image, and then verify the correctness of the password received in the password input box corresponding to the face image to double ensure the security of the first-secret file in the shared disk; secondly, the second-secret file is in the first Among the secret level files, only the first secret level file is normally opened, the second secret level file can be displayed, and the second secret level file has a secret level mark, which indicates that personnel without operation authority cannot perform the second operation on the second secret level file; again, When the second operation on the second-secret level file is detected, a question dialog box is randomly displayed, and the second degree is ensured by verifying the matching degree between the tentative answer received in the randomly displayed question dialog box and the standard answer to the question Security of confidential files.
  • FIG. 1 is a flowchart of a method for security management of shared files provided in Embodiment 1 of the present application.
  • Fig. 2 is a structural diagram of a shared file security management device provided in the second embodiment of the present application.
  • FIG. 3 is a schematic structural diagram of a terminal provided by Embodiment 3 of the present application.
  • FIG. 1 is a flowchart of a method for security management of shared files provided in Embodiment 1 of the present application.
  • the shared file security management method can be applied to a terminal.
  • the shared file security management function provided by the method of this application can be directly integrated on the terminal, or It runs in the terminal in the form of a Software Development Kit (SKD).
  • the shared file security management method specifically includes the following steps. According to different requirements, the sequence of the steps in the flowchart can be changed, and some can be omitted.
  • the project team can use shared cloud desktops, shared disks, or shared servers to store a large number of confidential files.
  • Different secret level files have different secret levels, and the same secret level corresponds to multiple different secret level files.
  • the first confidentiality level corresponds to the first type of confidentiality file
  • the second confidentiality level corresponds to the second type of confidentiality file
  • the first confidentiality level is lower than the second security level.
  • the first-class classified documents are called first-class classified files, and the first-class classified files refer to some unimportant files, such as files directly downloaded online, procedural files, and files collected at exhibitions.
  • the second-class classified documents are called second-class classified documents, and the second-class classified documents refer to the core documents related to the project team and require strong confidentiality.
  • the terminal When the user performs the first operation on the first secret level file, the terminal receives the first operation instruction of the first secret level file, and then obtains the user's face image, and displays different password input interfaces according to the face image.
  • the first operation may be an opening operation.
  • the terminal first judges whether the face image is a face image in the white list, and when determining that the face image is a face image in the white list, it indicates that the user has the first operation on the first-secret file
  • the role permissions of the user can then recognize the face image, and display different password input interfaces according to the recognized face image.
  • the displaying the password input box corresponding to the face image includes:
  • a password input box corresponding to the second role authority is displayed.
  • the correspondence relationship between the password input interface and the role authority of the user who performs the first operation on the first-secret file can be preset. For example, when the user who performs the first operation on the first-secret file has the first role authority, there are 0 password input boxes on the displayed first password input interface, that is, the first-secret file can be directly opened without entering a password; When the user who performs the first operation on the first-secret file has the second role authority, there is a password input box on the second password input interface displayed.
  • the personnel with the first role authority may include: project team leaders and company senior leaders.
  • the personnel with the second role authority may include one or more of project team members and company intellectual property personnel.
  • the first role authority for example, a company leader
  • the first role authority for example, a company leader
  • he wants to view the first-secret file he can directly open the first-secret file without entering a password, which saves the leader’s time;
  • the first operation is set as the open operation to ensure that all users can only open the first-secret level files, and cannot delete or copy the first-secret level files.
  • a database can be established in advance, and the security level of all first-secret files and the passwords corresponding to the preset first-secret files are recorded in the database.
  • the database is also associated with the user's face image and user User ID, user’s position, user’s mailbox, etc.
  • the terminal After the user enters the password in the displayed password input box, the terminal matches the entered password with the password of the first-secret file preset in the database. When it is determined that the password matches the password corresponding to the preset first secret level file, the entered password is considered correct; when it is determined that the password does not match the password corresponding to the preset first secret level file, Think that the entered password is wrong.
  • the judging whether the password matches the password corresponding to the preset first secret level file includes:
  • the terminal determines that the entered password is correct; If user 1 enters password B in the password input box, the terminal determines that the entered password is wrong.
  • the passwords for opening the first secret level are different according to the user settings of different second role permissions, which further strengthens the security management of shared files.
  • the first security level file is opened for the user to perform the first operation on the first security level file.
  • a plurality of sub-files are stored in the first-secret level file. Some of the sub-files are encrypted files and some are non-encrypted files. The encrypted files are called second-secret level files.
  • the second-secret-level file also displays a preset encryption identification, which is used to remind users who do not have the authority to operate on the second-secret-level file, that is, the encryption
  • the logo is used to prompt that the second-secret level file is an encrypted file, and users without role permissions should not click or touch the second-secret level file.
  • S13 When it is determined that the password does not match the password corresponding to the preset first secret level file, S13 may be executed again, or the process may be directly ended.
  • a question dialog box when the user performs the second operation on the second-secret level file, and the terminal receives the second operation instruction of the second-secret level file, a question dialog box will pop up.
  • the second operation may be: open operation, modify operation, and copy operation.
  • the second-secret documents refer to some very important documents, such as project document codes, project test data, leadership decision documents, project plans and other documents.
  • the security level of the second security level file is higher than the security level of the first security level file. If you want to open the second secret level file, you must open the first secret level file first.
  • the question dialog box randomly popping up includes:
  • a question dialog box corresponding to the first target keyword is popped up, and a question corresponding to the first target keyword is displayed in the question dialog box.
  • a question corresponding to the second-secret level document is randomly generated according to the file content of the second-secret level document.
  • Different second-secret level documents correspond to different questions, and different questions correspond to different answers.
  • the user inputs the answer according to the question in the pop-up question dialog box, and then judges whether the answer matches the standard answer corresponding to the question preset in the database.
  • the judging whether the pending answer matches the preset standard answer of the question includes:
  • the matching degree is less than the matching degree threshold, it is determined that the pending answer does not match the standard answer.
  • the answer entered by the user in the question dialog box is called a pending answer.
  • a matching degree threshold can be set for each second-secret level file in advance.
  • the matching degree threshold is used to judge the degree of matching between the answer entered by the user in the question dialog box and the standard answer to the question. Critical value. For example, when the security level of the second-secret file is top secret, the corresponding matching threshold can be set to 100%; when the security level of the second-secret file is confidential, the corresponding matching threshold can be set to 90%; the second-secret file When the secret level of is secret, the corresponding matching degree threshold can be set to 80%. If the matching degree is greater than the matching degree threshold, it indicates that the answer to be tested is the standard answer or close to the standard answer, and the answer to be tested is determined to be the correct answer. If the matching degree is less than the matching degree threshold, it indicates that there is a large gap between the test answer and the standard answer, and it is determined that the test answer is not the correct answer.
  • the correctness of the tentative answer is determined. There is no need to strictly check the correctness of the answers input by the user against the standard answers, so that the user's memory can be liberated to a certain extent while ensuring the high security of the second-secret file.
  • the calculating the matching degree between the pending answer and the standard answer according to a preset matching degree calculation rule includes:
  • the ratio is used as the degree of matching between the pending answer and the standard answer.
  • the pending answer of the input answering question is "The project team members participating in the project include: the third keyword J, the third keyword K, the third keyword L, and the third keyword N"
  • the standard answer is "The project team members participating in the project include: the second keyword J, the second keyword K, the second keyword M, the second keyword N"
  • the identification of the same keywords is "J, K, N”
  • the first number of the same keyword is 3
  • the second number of the second keyword of the standard answer is 4
  • the number of the same keywords calculated by calculation is the key to the preset answer
  • the proportion of the total number of words is 75%
  • the matching degree between the answer to be tested and the standard answer is 75%.
  • the difficulty of setting the problem is also different according to the level of the second-secret level file. If the level of the second-secret level file is higher, the second level The issue of file setting is relatively difficult. If the security level of the second-secret file is lower, the issue of setting the second-secret file is relatively simple. Multiple questions will be set for each second-secret file. When the second operation on the second-secret file is detected, a question dialog box will pop up randomly. By randomly popping up question dialogs, the security of the second-secret file is further ensured. If the project corresponding to the second-secret file is not involved, or a person who does not know the project, the second-secret file cannot be opened.
  • the corresponding function can be performed on the second secret level file according to the second operation of the user.
  • the second operation is an open operation
  • the function of opening the second-secret file is executed.
  • the second operation is a copy operation
  • the function of copying the second-secret level file is executed.
  • the method further includes:
  • the question dialog box is displayed randomly again;
  • the face image is removed from the white list.
  • a question dialog box is randomly displayed for the first time. If the pending answer in the question dialog box does not match the standard answer, a question dialog box is randomly displayed for the second time.
  • the terminal sends the face image to the reviewer for review to determine whether the user corresponding to the face image has the operation authority to perform the second operation on the second-secret file.
  • the result of the review is that you do not have the operation authority to operate the second-secret file, the face image is moved from the white list to the black list. Because the second-secret level document has the secret level identification, it has been prompted that users who do not have the operation authority cannot perform the second operation on the second-secret level document.
  • the password entered by the user in the question dialog box twice is incorrect, it can be considered
  • the user does not comply with the company's system or the user may want to steal the second cipher level document, so the user is directly blocked, which further ensures the security of the first and second cipher level files.
  • the shared file security management method described in this application first determines whether the face image of the user who performs the first operation on the first-secret file is a face image in the whitelist, and then verifies that it corresponds to the person
  • the correctness of the password received in the password input box of the face graphic is to double ensure the security of the first-secret file in the shared disk; secondly, the second-secret file is in the first-secret file, and only the first-secret file is normally opened.
  • the second-secret level document can be displayed only when the second-secret level document is displayed, and the second-secret level document has a secret level mark, which indicates that personnel without operation authority can not perform the second operation on the second-secret level document; again, when the second-secret level document is detected In the second operation, a question dialog box is randomly displayed, and the security of the second-secret level file is ensured by verifying the matching degree between the tentative answer received in the randomly displayed question dialog box and the standard answer to the question.
  • Fig. 2 is a structural diagram of a shared file security management device provided in the second embodiment of the present application.
  • the shared file security management apparatus 20 may include multiple functional modules composed of program code segments.
  • the program code of each program segment in the shared file security management device 20 may be stored in the memory of the terminal and executed by at least one processor to execute (see FIG. 1 for details) for security management of shared files.
  • the shared file security management device 20 can be divided into multiple functional modules according to the functions it performs.
  • the functional modules may include: an acquisition module 201, a display module 202, a first judgment module 203, an opening module 204, an eject module 205, a second judgment module 206, an execution module 207, and a removal module 208.
  • the module referred to in this application refers to a series of computer-readable instruction segments that can be executed by at least one processor and can complete fixed functions, and are stored in a memory. In this embodiment, the functions of each module will be described in detail in subsequent embodiments.
  • the obtaining module 201 is configured to obtain the face image of the user who performed the first operation on the first security file when the first operation on the first security file is received.
  • the project team can use shared cloud desktops, shared disks, or shared servers to store a large number of confidential files.
  • Different secret level files have different secret levels, and the same secret level corresponds to multiple different secret level files.
  • the first confidentiality level corresponds to the first type of confidentiality file
  • the second confidentiality level corresponds to the second type of confidentiality file
  • the first confidentiality level is lower than the second confidentiality level.
  • the first-class classified documents are called first-class classified files, and the first-class classified files refer to some unimportant files, such as files directly downloaded online, procedural files, and files collected at exhibitions.
  • the second-class classified documents are called second-class classified documents, and the second-class classified documents refer to the core documents related to the project team and require strong confidentiality.
  • the terminal When the user performs the first operation on the first secret level file, the terminal receives the first operation instruction of the first secret level file, and then obtains the user's face image, and displays different password input interfaces according to the face image.
  • the first operation may be an opening operation.
  • the display module 202 is configured to display a password input box corresponding to the face image when the face image is recognized as a face image in the preset whitelist.
  • the terminal first judges whether the face image is a face image in the white list, and when determining that the face image is a face image in the white list, it indicates that the user has the first operation on the first-secret file
  • the role permissions of the user can then recognize the face image, and display different password input interfaces according to the recognized face image.
  • the display module 202 displaying the password input box corresponding to the face image includes:
  • a password input box corresponding to the second role authority is displayed.
  • the correspondence relationship between the password input interface and the role authority of the user who performs the first operation on the first-secret file can be preset. For example, when the user who performs the first operation on the first-secret file has the first role authority, there are 0 password input boxes on the displayed first password input interface, that is, the first-secret file can be directly opened without entering a password; When the user who performs the first operation on the first-secret file has the second role authority, there is a password input box on the second password input interface displayed.
  • the personnel with the first role authority may include: project team leaders and company senior leaders.
  • the personnel with the second role authority may include: one or more of the project team members and the company's intellectual property personnel.
  • the first role authority for example, a company leader
  • the first role authority for example, a company leader
  • he wants to view the first-secret file he can directly open the first-secret file without entering a password, which saves the leader’s time;
  • the first operation is set as the open operation to ensure that all users can only open the first-secret level files, and cannot delete or copy the first-secret level files.
  • the first determining module 203 is configured to determine whether the password matches the password corresponding to the preset first secret level file when it is detected that the password is received in the password input box.
  • a database can be established in advance, and the security level of all first-secret files and the passwords corresponding to the preset first-secret files are recorded in the database.
  • the database is also associated with the user's face image and user User ID, user’s position, user’s mailbox, etc.
  • the terminal After the user enters the password in the displayed password input box, the terminal matches the entered password with the password of the first-secret file preset in the database. When it is determined that the password matches the password corresponding to the preset first secret level file, the entered password is considered correct; when it is determined that the password does not match the password corresponding to the preset first secret level file, Think that the entered password is wrong.
  • the first judging module 203 judging whether the password matches the password corresponding to the preset first secret level file includes:
  • the terminal determines that the entered password is correct; If user 1 enters password B in the password input box, the terminal determines that the entered password is wrong.
  • the passwords for opening the first secret level are different according to the user settings of different second role permissions, which further strengthens the security management of shared files.
  • the opening module 204 is configured to open the first security level file when the first judgment module 203 determines that the password matches the password corresponding to the preset first security level file, and the first security level file includes The second-secret level file, where an encryption identifier is displayed on the second-secret level file.
  • the first security level file is opened for the user to perform the first operation on the first security level file.
  • a plurality of sub-files are stored in the first-secret level file. Some of the sub-files are encrypted files and some are non-encrypted files. The encrypted files are called second-secret level files.
  • the second-secret-level file also displays a preset encryption identification, which is used to remind users who do not have the authority to operate on the second-secret-level file, that is, the encryption
  • the logo is used to prompt that the second-secret level file is an encrypted file, and users without role permissions should not click or touch the second-secret level file.
  • the pop-up module 205 is configured to randomly pop up a question dialog box when receiving a second operation on the second-secret file.
  • a question dialog box when the user performs the second operation on the second-secret level file, and the terminal receives the second operation instruction of the second-secret level file, a question dialog box will pop up.
  • the second operation may be: open operation, modify operation, and copy operation.
  • the second-secret documents refer to some very important documents, such as project document codes, project test data, leadership decision documents, project plans and other documents.
  • the security level of the second security level file is higher than the security level of the first security level file. If you want to open the second secret level file, you must open the first secret level file first.
  • a question dialog box includes:
  • a question dialog box corresponding to the first target keyword is popped up, and a question corresponding to the first target keyword is displayed in the question dialog box.
  • a question corresponding to the second-secret level document is randomly generated according to the file content of the second-secret level document.
  • Different second-secret level documents correspond to different questions, and different questions correspond to different answers.
  • the second determining module 206 is configured to determine whether the pending answer matches the preset standard answer of the question when it is detected that the pending answer is received in the question dialog box.
  • the user inputs the answer according to the question in the pop-up question dialog box, and then judges whether the answer matches the standard answer corresponding to the question preset in the database.
  • the second judgment module 206 judging whether the pending answer matches a preset standard answer of the question includes:
  • the matching degree is less than the matching degree threshold, it is determined that the pending answer does not match the standard answer.
  • the answer entered by the user in the question dialog box is called a pending answer.
  • a matching degree threshold can be set for each second-secret level file in advance.
  • the matching degree threshold is used to judge the degree of matching between the answer entered by the user in the question dialog box and the standard answer to the question. Critical value. For example, when the security level of the second-secret file is top secret, the corresponding matching threshold can be set to 100%; when the security level of the second-secret file is confidential, the corresponding matching threshold can be set to 90%; the second-secret file When the secret level of is secret, the corresponding matching degree threshold can be set to 80%. If the matching degree is greater than the matching degree threshold, it indicates that the answer to be tested is the standard answer or close to the standard answer, and the answer to be tested is determined to be the correct answer. If the matching degree is less than the matching degree threshold, it indicates that there is a large gap between the test answer and the standard answer, and it is determined that the test answer is not the correct answer.
  • the correctness of the tentative answer is determined. There is no need to strictly check the correctness of the answers input by the user against the standard answers, so that the user's memory can be liberated to a certain extent on the premise of ensuring the high security of the second-secret file.
  • the calculating the matching degree between the pending answer and the standard answer according to a preset matching degree calculation rule includes:
  • the ratio is used as the degree of matching between the pending answer and the standard answer.
  • the pending answer of the input answering question is "The project team members participating in the project include: the third keyword J, the third keyword K, the third keyword L, and the third keyword N"
  • the standard answer is "The project team members participating in the project include: the second keyword J, the second keyword K, the second keyword M, the second keyword N"
  • the identification of the same keywords is "J, K, N”
  • the first number of the same keyword is 3
  • the second number of the second keyword of the standard answer is 4
  • the number of the same keywords calculated by calculation is the key to the preset answer
  • the proportion of the total number of words is 75%
  • the matching degree between the answer to be tested and the standard answer is 75%.
  • the difficulty of setting the problem is also different according to the level of the second-secret level file. If the level of the second-secret level file is higher, the second level The issue of file setting is relatively difficult. If the security level of the second-secret file is lower, the issue of setting the second-secret file is relatively simple. Multiple questions will be set for each second-secret file. When the second operation on the second-secret file is detected, a question dialog box will pop up randomly. By randomly popping up question dialogs, the security of the second-secret file is further ensured. If the project corresponding to the second-secret file is not involved, or a person who does not know the project, the second-secret file cannot be opened.
  • the second judgment module 206 is further configured to continue to run the second judgment module 206 when it is judged that the answer to be checked does not match the standard answer, or directly end the process.
  • the execution module 207 is configured to execute the second operation on the second secret level file when the second judgment module 206 determines that the answer to be verified matches the standard answer.
  • the corresponding function can be performed on the second secret level file according to the second operation of the user.
  • the second operation is an open operation
  • the function of opening the second-secret file is executed.
  • the second operation is a copy operation
  • the function of copying the second-secret level file is executed.
  • the shared file security management device 20 further includes:
  • the display module 202 is also used to randomly display the question dialog box again;
  • the second judgment module 206 is further configured to send the face image to the reviewer for review when it is determined that there is a mismatch between the pending answer in the question dialog box displayed again and the standard answer;
  • the removal module 208 is configured to remove the face image when the review result of the reviewer is that the person corresponding to the face image does not have the authority to operate the second-secret file In the white list.
  • a question dialog box is randomly displayed for the first time. If the pending answer in the question dialog box does not match the standard answer, a question dialog box is randomly displayed for the second time.
  • the terminal sends the face image to the reviewer for review to determine whether the user corresponding to the face image has the operation authority to perform the second operation on the second-secret file.
  • the result of the review is that you do not have the operation authority to operate the second-secret file, the face image is moved from the white list to the black list. Because the second-secret level document has the secret level identification, it has been prompted that users who do not have the operation authority cannot perform the second operation on the second-secret level document.
  • the password entered by the user in the question dialog box twice is incorrect, it can be considered
  • the user does not comply with the company's system or the user may want to steal the second cipher level document, so the user is directly blocked, which further ensures the security of the first and second cipher level files.
  • the shared file security management device of the present application first determines whether the face image of the user who performs the first operation on the first-secret level file is a face image in the whitelist, and then verifies that it corresponds to the person
  • the correctness of the password received in the password input box of the face graphic is to double ensure the security of the first-secret file in the shared disk; secondly, the second-secret file is in the first-secret file, and only the first-secret file is normally opened.
  • the second-secret level document can be displayed only when the second-secret level document is displayed, and the second-secret level document has a secret level mark, which indicates that personnel without operation authority can not perform the second operation on the second-secret level document; again, when the second-secret level document is detected In the second operation, a question dialog box is randomly displayed, and the security of the second-secret level file is ensured by verifying the matching degree between the tentative answer received in the randomly displayed question dialog box and the standard answer to the question.
  • the terminal 3 includes a memory 31, at least one processor 32, at least one communication bus 33, and a transceiver 34.
  • the structure of the terminal shown in FIG. 3 does not constitute a limitation of the embodiments of the present application. It may be a bus-type structure or a star structure. The terminal 3 may also include more More or less other hardware or software, or different component arrangements.
  • the terminal 3 includes a terminal that can automatically perform numerical calculation and/or information processing according to pre-set or stored instructions. Its hardware includes but is not limited to a microprocessor, an application specific integrated circuit, and Programming gate arrays, digital processors and embedded devices, etc.
  • the terminal 3 may also include client equipment.
  • the client equipment includes, but is not limited to, any electronic product that can interact with the client through a keyboard, a mouse, a remote control, a touch panel, or a voice control device, for example, a personal computer. Computers, tablets, smart phones, digital cameras, etc.
  • terminal 3 is only an example. If other existing or future electronic products can be adapted to this application, they should also be included in the protection scope of this application and included here by reference.
  • the memory 31 is used to store program codes and various data, such as the shared file security management device 20 installed in the terminal 3, and achieve high-speed and automatic completion during the operation of the terminal 3 Access to programs or data.
  • the memory 31 includes Read-Only Memory (ROM), Programmable Read-Only Memory (PROM), and Erasable Programmable Read-Only Memory (EPROM) , One-time Programmable Read-Only Memory (OTPROM), Electronically-Erasable Programmable Read-Only Memory (EEPROM), CD-ROM (Compact Disc Read- Only Memory, CD-ROM) or other optical disk storage, magnetic disk storage, tape storage, or any other non-volatile computer-readable medium that can be used to carry or store data.
  • ROM Read-Only Memory
  • PROM Programmable Read-Only Memory
  • EPROM Erasable Programmable Read-Only Memory
  • OTPROM One-time Programmable Read-Only Memory
  • EEPROM Electronically-Erasable Programmable Read-Only Memory
  • CD-ROM Compact Disc
  • the at least one processor 32 may be composed of integrated circuits, for example, may be composed of a single packaged integrated circuit, or may be composed of multiple integrated circuits with the same function or different functions, including one Or a combination of multiple central processing units (CPU), microprocessors, digital processing chips, graphics processors, and various control chips.
  • the at least one processor 32 is the control core (Control Unit) of the terminal 3, which uses various interfaces and lines to connect the various components of the entire terminal 3, and by running or executing programs or modules stored in the memory 31, And call the data stored in the memory 31 to perform various functions of the terminal 3 and process data, for example, perform the function of security management of shared files.
  • Control Unit Control Unit
  • the at least one communication bus 33 is configured to implement connection and communication between the memory 31 and the at least one processor 32 and the like.
  • the terminal 3 may also include a power source (such as a battery) for supplying power to various components.
  • the power source may be logically connected to the at least one processor 32 through a power management device, so as to realize management through the power management device. Functions such as charging, discharging, and power management.
  • the power supply may also include one or more DC or AC power supplies, recharging devices, power failure detection circuits, power converters or inverters, power supply status indicators and other arbitrary components.
  • the terminal 3 may also include various sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be repeated here.
  • the above-mentioned integrated unit implemented in the form of a software function module may be stored in a non-volatile computer-readable storage medium.
  • the above-mentioned software function module includes several instructions to enable a computer device (which may be a personal computer, a terminal, or a network device, etc.) or a processor to execute part of the method described in each embodiment of the present application.
  • the at least one processor 32 can execute the operating device of the terminal 3 and various installed applications (such as the shared file security management device 20), program codes, etc. , For example, the various modules mentioned above.
  • the memory 31 stores program codes, and the at least one processor 32 can call the program codes stored in the memory 31 to execute related functions.
  • the various modules described in FIG. 2 are program codes stored in the memory 31 and executed by the at least one processor 32, so as to realize the functions of the various modules to achieve the purpose of security management of shared files .
  • the memory 31 stores a plurality of instructions, and the plurality of instructions are executed by the at least one processor 32 to realize the security management of shared files.
  • the disclosed device and method may be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of the modules is only a logical function division, and there may be other division methods in actual implementation.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Health & Medical Sciences (AREA)
  • Automation & Control Theory (AREA)
  • Databases & Information Systems (AREA)
  • Storage Device Security (AREA)
  • Document Processing Apparatus (AREA)

Abstract

一种共享文件安全管理方法,包括:获取对第一密级文件进行第一操作的用户的人脸图像;当人脸图像为预设白名单中的人脸图像时显示密码输入框,判断密码输入框中的密码与预设的第一密级文件对应的密码匹配时,打开第一密级文件,第一密级文件中包括第二密级文件,当接收到对第二密级文件的第二操作时,随机弹出问题对话框;判断问题对话框中的待验答案与问题的标准答案匹配时,对第二密级文件执行第二操作。还提供一种共享文件安全管理装置、终端及非易失性计算机可读存储介质。所述方法通过判断用户的人脸图像保证共享盘中的第一密级文件的安全性,同时若对第一密级文件中的第二密级文件进行操作时,随机显示问题对话框来确保第二密级文件的安全性。

Description

共享文件安全管理方法、装置、终端及可读存储介质
本申请要求于2019年06月19日提交中国专利局,申请号为201910533846.4发明名称为“共享文件安全管理方法、装置、终端及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及云桌面办公技术领域,具体涉及一种共享文件安全管理方法、装置、终端及可读存储介质。
背景技术
随着通信技术的迅速发展,信息数据的传递越来越方便快捷,人们获取信息的路径和范围越来越广泛。信息安全性变得更加严峻。特别是项目组内部信息的安全性,如有同事请假不在,项目信息需要紧急处理,密码便会告知他人,由他人帮忙进行处理,那么此时就会存在项目信息安全隐患问题。特别是项目核心的技术文件,如果泄密,就会给公司带来巨大的风险,甚至造成巨大的经济损失。
虽可以通过对重要文件进行加密的方式来确保文件的安全性,但密码容易被泄露。尤其是对协同办公的情况下,无法保证共享文件的安全。
因此,如何在共享办公的环境下,保证密级等级高的文件的安全成为亟待解决的技术问题。
发明内容
鉴于以上内容,有必要提出一种共享文件安全管理方法、装置、终端及可读存储介质,通过判断用户的人脸图像保证共享盘中的第一密级文件的安全性,同时若对第一密级文件中的第二密级文件进行操作时,随机显示问题对话框来确保第二密级文件的安全性。
本申请的第一方面提供一种共享文件安全管理方法,应用于终端中,所述方法包括:
接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对 应的密码是否匹配;
当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
当确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
本申请的第二方面提供一种共享文件安全管理装置,所述装置包括:
获取模块,用于接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
显示模块,用于当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
第一判断模块,用于当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配;
打开模块,用于当所述第一判断模块确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
弹出模块,用于接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
第二判断模块,用于当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
执行模块,用于当所述第二判断模块确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
本申请的第三方面提供一种终端,所述终端包括处理器,所述处理器用于执行存储器中存储的至少一个计算机可读指令时实现所述共享文件安全管理方法。
本申请的第四方面提供一种非易失性计算机可读存储介质,所述非易失性计算机可读存储介质上存储有至少一个计算机可读指令,所述计算机可读指令被处理器执行时实现所述共享文件安全管理方法。
综上所述,本申请所述的共享文件安全管理方法、装置、终端及可读存储介质,首先通 过判断对第一密级文件进行第一操作的用户的人脸图像是否为白名单中的人脸图像,再通过验证对应所述人脸图形的密码输入框中接收到的密码的正确性,来双重确保共享盘中的第一密级文件的安全性;其次,第二密级文件是在第一密级文件中,只有正常打开了第一密级文件,才能显示出第二密级文件,且第二密级文件上具有密级标识,标识无操作权限的人员不可对第二密级文件进行第二操作;再次,当侦测到对第二密级文件的第二操作时,随机显示问题对话框,通过验证所述随机显示问题对话框中接收到待验答案与问题的标准答案之间的匹配度来确保第二密级文件的安全性。
附图说明
图1是本申请实施例一提供的共享文件安全管理方法的流程图。
图2是本申请实施例二提供的共享文件安全管理装置的结构图。
图3是本申请实施例三提供的终端的结构示意图。
如下具体实施方式将结合上述附图进一步说明本申请。
具体实施方式
为了能够更清楚地理解本申请的上述目的、特征和优点,下面结合附图和具体实施例对本申请进行详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
实施例一
图1是本申请实施例一提供的共享文件安全管理方法的流程图。
在本实施例中,所述共享文件安全管理方法可以应用于终端中,对于需要进行共享文件安全管理的终端,可以直接在终端上集成本申请的方法所提供的共享文件安全管理的功能,或者以软件开发工具包(Software Development Kit,SKD)的形式运行在终端中。
如图1所示,所述共享文件安全管理方法具体包括以下步骤,根据不同的需求,该流程图中步骤的顺序可以改变,某些可以省略。
S11:接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像。
本实施例中,项目组可以使用共享云桌面、共享磁盘或者共享服务器存储大量的密级文件。不同的密级文件的密级等级不同,同一密级等级对应多个不同的密级文件。以两类密级等级为例进行说明,第一密级等级对应第一类密级文件,第二密级等级对应第二类密级文件,第一密级等级低于第二密级等级。
所述第一类密级文件称之为第一密级文件,第一密级文件是指一些不重要的文件,如网上直接下载的文件、程序性文件、展会上搜集的文件等。
所述第二类密级文件称之为第二密级文件,第二密级文件是指与项目组相关的核心文件,需要较强的保密性。
当用户预对第一密级文件进行第一操作时,终端接收到第一密级文件的第一操作指令,则获取用户的人脸图像,根据人脸图像显示不同的密码输入界面。
所述第一操作可以为打开操作。
S12:当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框。
本实施例中,终端先判断人脸图像是否为白名单中的人脸图像,在确定所述人脸图像为白名单中的人脸图像时,表明用户拥有对第一密级文件进行第一操作的角色权限,从而再对人脸图像进行识别,根据识别到的人脸图像显示不同的密码输入界面。
优选的,所述显示对应所述人脸图像的密码输入框包括:
识别所述人脸图像中的用户对应的角色权限;
当所述角色权限为第一角色权限时,直接对所述第一密级文件进行所述第一操作;
当所述角色权限为第二角色权限时,显示对应所述第二角色权限的密码输入框。
可以预先设置密码输入界面与对第一密级文件进行第一操作的用户的角色权限之间的对应关系。例如,当对第一密级文件进行第一操作的用户具有第一角色权限时,显示的第一密码输入界面上有0个密码输入框,即不需要输入密码即可直接打开第一密级文件;当对第一密级文件进行第一操作的用户具有第二角色权限时,显示的第二密码输入界面上有1个密码输入框。
所述拥有第一角色权限的人员可以包括:项目组领导、公司高层领导。
所述拥有第二角色权限的人员可以包括:项目组成员、公司知识产权人员中的一个或者多个。
本实施例中,对拥有第一角色权限的用户,例如,公司领导,想要查看第一密级文件的时候,可以不用输入密码,直接打开第一密级文件,节省了领导的时间;对拥有第二角色权限的用户,设置密码输入框,保证了文件的安全性。同时设置第一操作为打开操作,确保所有用户只能打开第一密级文件,而无法对第一密级文件进行删除或者复制。
S13:当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配。
本实施例中,可以预先建立一个数据库,数据库中记录了所有第一密级文件的密级等级 及预设的第一密级文件对应的密码,同时所述数据库中还关联了用户的人脸图像、用户的工号、用户的职位、用户的邮箱等。
当用户在所显示的密码输入框中输入了密码后,终端将所输入的密码与数据库中的预设的第一密级文件的密码进行匹配。当确定所述密码与预设的所述第一密级文件对应的密码匹配时,认为所输入的密码正确;当确定所述密码与预设的所述第一密级文件对应的密码不匹配时,认为所输入的密码错误。
优选的,所述判断所述密码与预设的所述第一密级文件对应的密码是否匹配包括:
获取与所述人脸图像对应的所述第一密级文件的目标密码,不同的人脸图形对应所述第一密级文件的目标密码不同;
判断所述密码与所述目标密码是否匹配。
示例性的,假设数据库中记录的预设的对应所述第一密级文件的密码为A,人脸图像对应的用户1,在密码输入框中输入密码A,则终端确定所输入的密码正确;如果用户1在密码输入框中输入密码B,则终端确定所输入的密码错误。
本实施例中,根据不同的第二角色权限的用户设置打开第一密级的密码不同,进一步加强了共享文件的安全的管理。
S14:当确定所述密码与所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识。
本实施例中,当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开第一密级文件,供用户对所述第一密级文件进行第一操作。
本实施例中,所述第一密级文件中存放有多个子文件,所述子文件有些是加密文件,有些是非加密文件,将加密文件称之为第二密级文件。
第二密级文件上还显示有预先设置的加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作,即所述加密标识用以提示该第二密级文件是加密文件,无角色权限的用户不要点击或者触摸第二密级文件。
当确定所述密码与预设的所述第一密级文件对应的密码不匹配时,可以重新执行S13,也可以直接结束流程。
S15:接收到对所述第二密级文件的第二操作时,随机弹出问题对话框。
本实施例中,当用户预对第二密级文件进行第二操作时,终端接收到第二密级文件的第二操作指令,则弹出问题对话框。所述第二操作可以为:打开操作、修改操作、复制操作。
所述第二密级文件是指一些非常重要的文件,例如,项目文件代码、项目试验数据、领导决策文件、项目计划书等文件。所述第二密级文件的密级等级高于第一密级文件的密级等 级。要想打开第二密级文件必须先打开第一密级等级文件。
优选的,所述接收到对所述第二密级文件的第二操作时,随机弹出问题对话框包括:
提取所述第二密级文件的文件内容中的多个第一关键词;
根据每个所述第一关键词首次出现的位置顺序确定所述每个第一关键词的编号;
采用随机数生成算法生成一个随机数;
根据所述随机数与编号之间的对应关系筛选出对应所述随机数的第一目标关键词;
弹出与所述第一目标关键词对应的问题对话框,所述问题对话框中显示有与所述第一目标关键词对应的问题。
本实施例中,根据第二密级文件的文件内容随机产生对应所述第二密级文件的问题,不同的第二密级文件对应不同的问题,不同的问题对应不同的答案。
S16:当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配。
用户根据弹出的问题对话框中的问题输入答案,然后判断所述答案与数据库中预先设置的对应所述问题的标准答案是否匹配。
优选的,所述判断所述待验答案与预设的所述问题的标准答案是否匹配包括:
根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度;
获取所述第二密级文件对应的预设匹配度阈值;
判断所述匹配度是否大于所述匹配度阈值;
当所述匹配度大于或者等于所述匹配度阈值时,确定所述待验答案与所述标准答案匹配;
当所述匹配度小于所述匹配度阈值时,确定所述待验答案与所述标准答案不匹配。
用户在问题对话框中输入的答案称之为待验答案。
本实施例中,可以预先为每一个第二密级文件对应设置一个匹配度阈值,所述匹配度阈值,用以评判用户在问题对话框中输入的答案与问题的标准答案之间的匹配度的临界值。例如,第二密级文件的密级等级为绝密时,对应的匹配度阈值可以设置为100%;第二密级文件的密级等级为机密时,对应的匹配度阈值可以设置为90%;第二密级文件的密级等级为秘密时,对应的匹配度阈值可以设置为80%。若匹配度大于匹配度阈值,则表明待验答案为标准答案或者接近标准答案,即可确定待验答案为正确答案。若匹配度小于匹配度阈值,则表明待验答案与标准答案差距较大,确定待验答案不为正确答案。
通过设置匹配度阈值,再判断待验答案与标准答案之间的匹配度与匹配度阈值之间的大小关系,来确定待验答案的正确性与否。而无需严格对照标准答案来校验用户输入的答案的正确性,从而可以在确保第二密级文件高安全性的前提下,可以一定程度上的解放用户的记 忆力。
优选的,所述根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度包括:
提取所述待验答案中的预设第二关键词;
提取所述标准答案中的预设第三关键词;
统计所述预设第二关键词中与所述第三关键词相同的关键词的第一个数;
计算所述第一个数占所述预设第三关键词的第二个数的比例;
将所述比例作为所述待验答案与所述标准答案之间的匹配度。
示例性的,若所输入的回答问题的待验答案为“参加项目的项目组成员包括:第三关键词J、第三关键词K、第三关键词L、第三关键词N”,预设的标准答案为“参加项目的项目组成员包括:第二关键词J、第二关键词K、第二关键词M、第二关键词N”,识别出具有相同的关键词为“J、K、N”,相同的关键词的第一个数为3,标准答案的第二关键词的第二个数为4,计算所统计的相同的关键词个数占所预设的答案中关键词总个数的比例为75%,则待验答案与所述标准答案之间的匹配度为75%。
由于问题是按照第二密级文件的文件内容进行设置的,根据第二密级文件的密级等级,设置的问题的难易程度也不同,如果第二密级文件的密级等级较高,对该第二密级文件设置的问题相对较难,如果第二密级文件的密级等级较低,对该第二密级文件设置的问题相对较简单。对每个第二密级文件会设置多个问题,当侦测到对第二密级文件的第二操作时,随机弹出问题对话框。通过随机弹出问题对话框,进一步的保证了第二密级文件的安全性,如果没有参与第二密级文件对应的项目,或者对所述项目不了解的人员,是无法打开第二密级文件的。
S17:当判断所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
本实施例中,在判断所述待验答案与数据库中预设的所述问题的标准答案匹配时,可以按照用户的所述第二操作来对所述第二密级文件执行相应的功能。比如,第二操作是打开操作时,执行打开第二密级文件的功能。又如,第二操作是复制操作时,执行复制第二密级文件的功能。
当判断所述待验答案与所述标准答案不匹配时,可以继续执行S16,也可以直接结束流程。
进一步的,在判断所述待验答案与所述标准答案不匹配之后,所述方法还包括:
再次随机显示问题对话框;
当判断再次显示的问题对话框中的待验答案与标准答案之间不匹配时,将所述人脸图像发送给审核者进行审核;
当接收到所述审核者的审核结果为所述人脸图像对应的人员不具有对所述第二密级文件进行操作权限的人员时,将所述人脸图像移除所述白名单中。
本实施例中,第一次随机显示一个问题对话框,若问题对话框中的待验答案与标准答案不匹配时,再第二次随机显示一个问题对话框,若问题对话框中的待验答案与标准答案仍不匹配时,终端将人脸图像发送给审核者进行审核,以判断人脸图像对应的用户是否具有对第二密级文件进行第二操作的操作权限。当审核的结果为不具有操作第二密级文件的操作权限时,将人脸图像从白名单中移至黑名单中。因为第二密级文件上具有密级标识,已经提示过不具有操作权限的用户不可以对第二密级文件进行第二操作,倘若该用户两次在问题对话框中输入的密码均不对时,可以认为该用户不遵守公司制度或者该用户可能想窃取第二密级文,故将该用户直接拉黑,进一步确保了第一密级文件和第二密级文件的安全性。
综上所述,本申请所述共享文件安全管理方法,首先通过判断对第一密级文件进行第一操作的用户的人脸图像是否为白名单中的人脸图像,再通过验证对应所述人脸图形的密码输入框中接收到的密码的正确性,来双重确保共享盘中的第一密级文件的安全性;其次,第二密级文件是在第一密级文件中,只有正常打开了第一密级文件,才能显示出第二密级文件,且第二密级文件上具有密级标识,标识无操作权限的人员不可对第二密级文件进行第二操作;再次,当侦测到对第二密级文件的第二操作时,随机显示问题对话框,通过验证所述随机显示问题对话框中接收到待验答案与问题的标准答案之间的匹配度来确保第二密级文件的安全性。
实施例二
图2是本申请实施例二提供的共享文件安全管理装置的结构图。
在一些实施例中,所述共享文件安全管理装置20可以包括多个由程序代码段所组成的功能模块。所述共享文件安全管理装置20中的各个程序段的程序代码可以存储于终端的存储器中,并由至少一个处理器所执行,以执行(详见图1描述)对共享文件进行安全管理。
本实施例中,所述共享文件安全管理装置20根据其所执行的功能,可以被划分为多个功能模块。所述功能模块可以包括:获取模块201、显示模块202、第一判断模块203、打开模块204、弹出模块205、第二判断模块206、执行模块207及移除模块208。本申请所称的模块是指一种能够被至少一个处理器所执行并且能够完成固定功能的一系列计算机可读指令段,其存储在存储器中。在本实施例中,关于各模块的功能将在后续的实施例中详述。
获取模块201,用于接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像。
本实施例中,项目组可以使用共享云桌面、共享磁盘或者共享服务器存储大量的密级文件。不同的密级文件的密级等级不同,同一密级等级对应多个不同的密级文件。以两类密级等级为例进行说明,第一密级等级对应第一类密级文件,第二密级等级对应第二类密级文件,第一密级等级低于第二密级等级。
所述第一类密级文件称之为第一密级文件,第一密级文件是指一些不重要的文件,如网上直接下载的文件、程序性文件、展会上搜集的文件等。
所述第二类密级文件称之为第二密级文件,第二密级文件是指与项目组相关的核心文件,需要较强的保密性。
当用户预对第一密级文件进行第一操作时,终端接收到第一密级文件的第一操作指令,则获取用户的人脸图像,根据人脸图像显示不同的密码输入界面。
所述第一操作可以为打开操作。
显示模块202,用于当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框。
本实施例中,终端先判断人脸图像是否为白名单中的人脸图像,在确定所述人脸图像为白名单中的人脸图像时,表明用户拥有对第一密级文件进行第一操作的角色权限,从而再对人脸图像进行识别,根据识别到的人脸图像显示不同的密码输入界面。
优选的,所述显示模块202显示对应所述人脸图像的密码输入框包括:
识别所述人脸图像中的用户对应的角色权限;
当所述角色权限为第一角色权限时,直接对所述第一密级文件进行所述第一操作;
当所述角色权限为第二角色权限时,显示对应所述第二角色权限的密码输入框。
可以预先设置密码输入界面与对第一密级文件进行第一操作的用户的角色权限之间的对应关系。例如,当对第一密级文件进行第一操作的用户具有第一角色权限时,显示的第一密码输入界面上有0个密码输入框,即不需要输入密码即可直接打开第一密级文件;当对第一密级文件进行第一操作的用户具有第二角色权限时,显示的第二密码输入界面上有1个密码输入框。
所述拥有第一角色权限的人员可以包括:项目组领导、公司高层领导。
所述拥有第二角色权限的人员可以包括:项目组成员中、公司知识产权人员中的一个或者多个。
本实施例中,对拥有第一角色权限的用户,例如,公司领导,想要查看第一密级文件的 时候,可以不用输入密码,直接打开第一密级文件,节省了领导的时间;对拥有第二角色权限的用户,设置密码输入框,保证了文件的安全性。同时设置第一操作为打开操作,确保所有用户只能打开第一密级文件,而无法对第一密级文件进行删除或者复制。
第一判断模块203,用于当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配。
本实施例中,可以预先建立一个数据库,数据库中记录了所有第一密级文件的密级等级及预设的第一密级文件对应的密码,同时所述数据库中还关联了用户的人脸图像、用户的工号、用户的职位、用户的邮箱等。
当用户在所显示的密码输入框中输入了密码后,终端将所输入的密码与数据库中的预设的第一密级文件的密码进行匹配。当确定所述密码与预设的所述第一密级文件对应的密码匹配时,认为所输入的密码正确;当确定所述密码与预设的所述第一密级文件对应的密码不匹配时,认为所输入的密码错误。
优选的,所述第一判断模块203判断所述密码与预设的所述第一密级文件对应的密码是否匹配包括:
获取与所述人脸图像对应的所述第一密级文件的目标密码,不同的人脸图形对应所述第一密级文件的目标密码不同;
判断所述密码与所述目标密码是否匹配。
示例性的,假设数据库中记录的预设的对应所述第一密级文件的密码为A,人脸图像对应的用户1,在密码输入框中输入密码A,则终端确定所输入的密码正确;如果用户1在密码输入框中输入密码B,则终端确定所输入的密码错误。
本实施例中,根据不同的第二角色权限的用户设置打开第一密级的密码不同,进一步加强了共享文件的安全的管理。
打开模块204,用于当所述第一判断模块203确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识。
本实施例中,当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开第一密级文件,供用户对所述第一密级文件进行第一操作。
本实施例中,所述第一密级文件中存放有多个子文件,所述子文件有些是加密文件,有些是非加密文件,将加密文件称之为第二密级文件。
第二密级文件上还显示有预先设置的加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作,即所述加密标识用以提 示该第二密级文件是加密文件,无角色权限的用户不要点击或者触摸第二密级文件。
弹出模块205,用于接收到对所述第二密级文件的第二操作时,随机弹出问题对话框。
本实施例中,当用户预对第二密级文件进行第二操作时,终端接收到第二密级文件的第二操作指令,则弹出问题对话框。所述第二操作可以为:打开操作、修改操作、复制操作。
所述第二密级文件是指一些非常重要的文件,例如,项目文件代码、项目试验数据、领导决策文件、项目计划书等文件。所述第二密级文件的密级等级高于第一密级文件的密级等级。要想打开第二密级文件必须先打开第一密级等级文件。
优选的,所述弹出模块205接收到对所述第二密级文件的第二操作时,随机弹出问题对话框包括:
提取所述第二密级文件的文件内容中的多个第一关键词;
根据所述多个第一关键词出现的位置确定所述多个第一关键词的编号;
采用随机数生成算法生成一个随机数;
根据所述随机数与编号之间的对应关系筛选出对应所述随机数的第一目标关键词;
弹出与所述第一目标关键词对应的问题对话框,所述问题对话框中显示有与所述第一目标关键词对应的问题。
本实施例中,根据第二密级文件的文件内容随机产生对应所述第二密级文件的问题,不同的第二密级文件对应不同的问题,不同的问题对应不同的答案。
第二判断模块206,用于当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配。
用户根据弹出的问题对话框中的问题输入答案,然后判断所述答案与数据库中预先设置的对应所述问题的标准答案是否匹配。
优选的,所述第二判断模块206判断所述待验答案与预设的所述问题的标准答案是否匹配包括:
根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度;
获取所述第二密级文件对应的预设匹配度阈值;
判断所述匹配度是否大于所述匹配度阈值;
当所述匹配度大于或者等于所述匹配度阈值时,确定所述待验答案与所述标准答案匹配;
当所述匹配度小于所述匹配度阈值时,确定所述待验答案与所述标准答案不匹配。
用户在问题对话框中输入的答案称之为待验答案。
本实施例中,可以预先为每一个第二密级文件对应设置一个匹配度阈值,所述匹配度阈值,用以评判用户在问题对话框中输入的答案与问题的标准答案之间的匹配度的临界值。例 如,第二密级文件的密级等级为绝密时,对应的匹配度阈值可以设置为100%;第二密级文件的密级等级为机密时,对应的匹配度阈值可以设置为90%;第二密级文件的密级等级为秘密时,对应的匹配度阈值可以设置为80%。若匹配度大于匹配度阈值,则表明待验答案为标准答案或者接近标准答案,即可确定待验答案为正确答案。若匹配度小于匹配度阈值,则表明待验答案与标准答案差距较大,确定待验答案不为正确答案。
通过设置匹配度阈值,再判断待验答案与标准答案之间的匹配度与匹配度阈值之间的大小关系,来确定待验答案的正确性与否。而无需严格对照标准答案来校验用户输入的答案的正确性,从而可以在确保第二密级文件高安全性的前提下,可以一定程度上的解放用户的记忆力。
优选的,所述根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度包括:
提取所述待验答案中的预设第二关键词;
提取所述标准答案中的预设第三关键词;
统计所述预设第二关键词中与所述第三关键词相同的关键词的第一个数;
计算所述第一个数占所述预设第三关键词的第二个数的比例;
将所述比例作为所述待验答案与所述标准答案之间的匹配度。
示例性的,若所输入的回答问题的待验答案为“参加项目的项目组成员包括:第三关键词J、第三关键词K、第三关键词L、第三关键词N”,预设的标准答案为“参加项目的项目组成员包括:第二关键词J、第二关键词K、第二关键词M、第二关键词N”,识别出具有相同的关键词为“J、K、N”,相同的关键词的第一个数为3,标准答案的第二关键词的第二个数为4,计算所统计的相同的关键词个数占所预设的答案中关键词总个数的比例为75%,则待验答案与所述标准答案之间的匹配度为75%。
由于问题是按照第二密级文件的文件内容进行设置的,根据第二密级文件的密级等级,设置的问题的难易程度也不同,如果第二密级文件的密级等级较高,对该第二密级文件设置的问题相对较难,如果第二密级文件的密级等级较低,对该第二密级文件设置的问题相对较简单。对每个第二密级文件会设置多个问题,当侦测到对第二密级文件的第二操作时,随机弹出问题对话框。通过随机弹出问题对话框,进一步的保证了第二密级文件的安全性,如果没有参与第二密级文件对应的项目,或者对所述项目不了解的人员,是无法打开第二密级文件的。
所述第二判断模块206,还用于当判断所述待验答案与所述标准答案不匹配时,可以继续运行所述第二判断模块206,也可以直接结束流程。
执行模块207,用于当所述第二判断模块206确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
本实施例中,在判断所述待验答案与数据库中预设的所述问题的标准答案匹配时,可以按照用户的所述第二操作来对所述第二密级文件执行相应的功能。比如,第二操作是打开操作时,执行打开第二密级文件的功能。又如,第二操作是复制操作时,执行复制第二密级文件的功能。
进一步的,在所述第二判断模块206判断所述待验答案与所述标准答案不匹配之后,所述共享文件安全管理装置20还包括:
所述显示模块202,还用于再次随机显示问题对话框;
所述第二判断模块206,还用于当判断再次显示的问题对话框中的待验答案与标准答案之间不匹配时,将所述人脸图像发送给审核者进行审核;
移除模块208,用于当接收到所述审核者的审核结果为所述人脸图像对应的人员不具有对所述第二密级文件进行操作权限的人员时,将所述人脸图像移除所述白名单中。
本实施例中,第一次随机显示一个问题对话框,若问题对话框中的待验答案与标准答案不匹配时,再第二次随机显示一个问题对话框,若问题对话框中的待验答案与标准答案仍不匹配时,终端将人脸图像发送给审核者进行审核,以判断人脸图像对应的用户是否具有对第二密级文件进行第二操作的操作权限。当审核的结果为不具有操作第二密级文件的操作权限时,将人脸图像从白名单中移至黑名单中。因为第二密级文件上具有密级标识,已经提示过不具有操作权限的用户不可以对第二密级文件进行第二操作,倘若该用户两次在问题对话框中输入的密码均不对时,可以认为该用户不遵守公司制度或者该用户可能想窃取第二密级文,故将该用户直接拉黑,进一步确保了第一密级文件和第二密级文件的安全性。
综上所述,本申请所述共享文件安全管理装置,首先通过判断对第一密级文件进行第一操作的用户的人脸图像是否为白名单中的人脸图像,再通过验证对应所述人脸图形的密码输入框中接收到的密码的正确性,来双重确保共享盘中的第一密级文件的安全性;其次,第二密级文件是在第一密级文件中,只有正常打开了第一密级文件,才能显示出第二密级文件,且第二密级文件上具有密级标识,标识无操作权限的人员不可对第二密级文件进行第二操作;再次,当侦测到对第二密级文件的第二操作时,随机显示问题对话框,通过验证所述随机显示问题对话框中接收到待验答案与问题的标准答案之间的匹配度来确保第二密级文件的安全性。
实施例三
参阅图3所示,为本申请实施例三提供的终端的结构示意图。在本申请较佳实施例中,所述终端3包括存储器31、至少一个处理器32、至少一条通信总线33及收发器34。
本领域技术人员应该了解,图3示出的终端的结构并不构成本申请实施例的限定,既可以是总线型结构,也可以是星形结构,所述终端3还可以包括比图示更多或更少的其他硬件或者软件,或者不同的部件布置。
在一些实施例中,所述终端3包括一种能够按照事先设定或存储的指令,自动进行数值计算和/或信息处理的终端,其硬件包括但不限于微处理器、专用集成电路、可编程门阵列、数字处理器及嵌入式设备等。所述终端3还可包括客户设备,所述客户设备包括但不限于任何一种可与客户通过键盘、鼠标、遥控器、触摸板或声控设备等方式进行人机交互的电子产品,例如,个人计算机、平板电脑、智能手机、数码相机等。
需要说明的是,所述终端3仅为举例,其他现有的或今后可能出现的电子产品如可适应于本申请,也应包含在本申请的保护范围以内,并以引用方式包含于此。
在一些实施例中,所述存储器31用于存储程序代码和各种数据,例如安装在所述终端3中的共享文件安全管理装置20,并在终端3的运行过程中实现高速、自动地完成程序或数据的存取。所述存储器31包括只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable Read-Only Memory,PROM)、可擦除可编程只读存储器(Erasable Programmable Read-Only Memory,EPROM)、一次可编程只读存储器(One-time Programmable Read-Only Memory,OTPROM)、电子擦除式可复写只读存储器(Electrically-Erasable Programmable Read-Only Memory,EEPROM)、只读光盘(Compact Disc Read-Only Memory,CD-ROM)或其他光盘存储器、磁盘存储器、磁带存储器、或者能够用于携带或存储数据的非易失性计算机可读的任何其他介质。
在一些实施例中,所述至少一个处理器32可以由集成电路组成,例如可以由单个封装的集成电路所组成,也可以是由多个相同功能或不同功能封装的集成电路所组成,包括一个或者多个中央处理器(Central Processing unit,CPU)、微处理器、数字处理芯片、图形处理器及各种控制芯片的组合等。所述至少一个处理器32是所述终端3的控制核心(Control Unit),利用各种接口和线路连接整个终端3的各个部件,通过运行或执行存储在所述存储器31内的程序或者模块,以及调用存储在所述存储器31内的数据,以执行终端3的各种功能和处理数据,例如执行共享文件安全管理的功能。
在一些实施例中,所述至少一条通信总线33被设置为实现所述存储器31以及所述至少一个处理器32等之间的连接通信。
尽管未示出,所述终端3还可以包括给各个部件供电的电源(比如电池),优选的,电 源可以通过电源管理装置与所述至少一个处理器32逻辑相连,从而通过电源管理装置实现管理充电、放电、以及功耗管理等功能。电源还可以包括一个或一个以上的直流或交流电源、再充电装置、电源故障检测电路、电源转换器或者逆变器、电源状态指示器等任意组件。所述终端3还可以包括多种传感器、蓝牙模块、Wi-Fi模块等,在此不再赘述。
应该了解,所述实施例仅为说明之用,在专利申请范围上并不受此结构的限制。
上述以软件功能模块的形式实现的集成的单元,可以存储在一个非易失性计算机可读存储介质中。上述软件功能模块包括若干指令用以使得一台计算机设备(可以是个人计算机,终端,或者网络设备等)或处理器(processor)执行本申请各个实施例所述方法的部分。
在进一步的实施例中,结合图2,所述至少一个处理器32可执行所述终端3的操作装置以及安装的各类应用程序(如所述的共享文件安全管理装置20)、程序代码等,例如,上述的各个模块。
所述存储器31中存储有程序代码,且所述至少一个处理器32可调用所述存储器31中存储的程序代码以执行相关的功能。例如,图2中所述的各个模块是存储在所述存储器31中的程序代码,并由所述至少一个处理器32所执行,从而实现所述各个模块的功能以达到共享文件安全管理的目的。
在本申请的一个实施例中,所述存储器31存储多个指令,所述多个指令被所述至少一个处理器32所执行以实现共享文件安全的管理。
具体地,所述至少一个处理器32对上述指令的具体实现方法可参考图1对应实施例中相关步骤的描述,在此不赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
最后应说明的是,以上实施例仅用以说明本申请的技术方案而非限制,尽管参照较佳实施例对本申请进行了详细说明,本领域的普通技术人员应当理解,可以对本申请的技术方案进行修改或等同替换,而不脱离本申请技术方案的精神和范围。

Claims (20)

  1. 一种共享文件安全管理方法,应用于终端中,其特征在于,所述方法包括:
    接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
    当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
    当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配;
    当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
    接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
    当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
    当确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
  2. 如权利要求1所述的方法,其特征在于,所述当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框包括:
    识别所述人脸图像中的用户对应的角色权限;
    当所述角色权限为第一角色权限时,直接对所述第一密级文件进行所述第一操作;
    当所述角色权限为第二角色权限时,显示对应所述第二角色权限的密码输入框。
  3. 如权利要求1所述的方法,其特征在于,所述判断所述密码与预设的所述第一密级文件对应的密码是否匹配包括:
    获取与所述人脸图像对应的所述第一密级文件的目标密码,不同的人脸图形对应所述第一密级文件的目标密码不同;
    判断所述密码与所述目标密码是否匹配。
  4. 如权利要求1所述的方法,其特征在于,所述接收到对所述第二密级文件的第二操作时,随机弹出问题对话框包括:
    提取所述第二密级文件的文件内容中的多个第一关键词;
    根据每个所述第一关键词首次出现的位置顺序确定所述每个第一关键词的编号;
    采用随机数生成算法生成一个随机数;
    根据所述随机数与编号之间的对应关系筛选出对应所述随机数的第一目标关键词;
    弹出与所述第一目标关键词对应的问题对话框,所述问题对话框中显示有与所述第一目标关键词对应的问题。
  5. 如权利要求1所述的方法,其特征在于,所述判断所述待验答案与所述问题的标准答案是否匹配包括:
    根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度;
    获取所述第二密级文件对应的预设匹配度阈值;
    判断所述匹配度是否大于所述匹配度阈值;
    当所述匹配度大于或者等于所述匹配度阈值时,确定所述待验答案与所述标准答案匹配;
    当所述匹配度小于所述匹配度阈值时,确定所述待验答案与所述标准答案不匹配。
  6. 如权利要求5所述的方法,其特征在于,所述根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度包括:
    提取所述待验答案中的预设第二关键词;
    提取所述标准答案中的预设第三关键词;
    统计所述预设第二关键词中与所述第三关键词相同的关键词的第一个数;
    计算所述第一个数占所述预设第三关键词的第二个数的比例;
    将所述比例作为所述待验答案与所述标准答案之间的匹配度。
  7. 如权利要求1所述的方法,其特征在于,在判断所述待验答案与所述标准答案不匹配之后,所述方法还包括:
    再次随机显示问题对话框;
    当判断再次显示的问题对话框中的待验答案与标准答案之间不匹配时,将所述人脸图像发送给审核者进行审核;
    当接收到所述审核者的审核结果为所述人脸图像对应的人员不具有对所述第二密级文件进行操作权限的人员时,将所述人脸图像移除所述白名单中。
  8. 一种共享文件安全管理装置,运行于终端中,其特征在于,所述装置包括:
    获取模块,用于接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
    显示模块,用于当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
    第一判断模块,用于当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配;
    打开模块,用于当所述第一判断模块确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
    弹出模块,用于接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
    第二判断模块,用于当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
    执行模块,用于当所述第二判断模块确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
  9. 一种终端,其特征在于,所述终端包括处理器,所述处理器用于执行存储器中存储的至少一个计算机可读指令时实现以下步骤:
    接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
    当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
    当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配;
    当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
    接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
    当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
    当确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
  10. 如权利要求9所述的终端,其特征在于,所述处理器执行所述至少一个计算机可读指令以实现所述显示对应所述人脸图像的密码输入框时,包括:
    识别所述人脸图像中的用户对应的角色权限;
    当所述角色权限为第一角色权限时,直接对所述第一密级文件进行所述第一操作;
    当所述角色权限为第二角色权限时,显示对应所述第二角色权限的密码输入框。
  11. 如权利要求9所述的终端,其特征在于,所述处理器执行所述至少一个计算机可读 指令以实现所述判断所述密码与预设的所述第一密级文件对应的密码是否匹配时,包括:
    获取与所述人脸图像对应的所述第一密级文件的目标密码,不同的人脸图形对应所述第一密级文件的目标密码不同;
    判断所述密码与所述目标密码是否匹配。
  12. 如权利要求9所述的终端,其特征在于,所述处理器执行所述至少一个计算机可读指令以实现随机弹出问题对话框时,包括:
    提取所述第二密级文件的文件内容中的多个第一关键词;
    根据每个所述第一关键词首次出现的位置顺序确定所述每个第一关键词的编号;
    采用随机数生成算法生成一个随机数;
    根据所述随机数与编号之间的对应关系筛选出对应所述随机数的第一目标关键词;
    弹出与所述第一目标关键词对应的问题对话框,所述问题对话框中显示有与所述第一目标关键词对应的问题。
  13. 如权利要求9至12中任意一项所述的终端,其特征在于,所述处理器执行所述至少一个计算机可读指令以实现所述判断所述待验答案与所述问题的标准答案是否匹配时,包括:
    根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度;
    获取所述第二密级文件对应的预设匹配度阈值;
    判断所述匹配度是否大于所述匹配度阈值;
    当所述匹配度大于或者等于所述匹配度阈值时,确定所述待验答案与所述标准答案匹配;
    当所述匹配度小于所述匹配度阈值时,确定所述待验答案与所述标准答案不匹配。
  14. 如权利要求13所述的终端,其特征在于,所述处理器执行所述至少一个计算机可读指令以实现所述根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度时,包括:
    提取所述待验答案中的预设第二关键词;
    提取所述标准答案中的预设第三关键词;
    统计所述预设第二关键词中与所述第三关键词相同的关键词的第一个数;
    计算所述第一个数占所述预设第三关键词的第二个数的比例;
    将所述比例作为所述待验答案与所述标准答案之间的匹配度。
  15. 如权利要求9所述的终端,其特征在于,在判断所述待验答案与所述标准答案不匹配之后,所述处理器执行所述至少一个计算机可读指令还用以实现以下步骤:
    再次随机显示问题对话框;
    当判断再次显示的问题对话框中的待验答案与标准答案之间不匹配时,将所述人脸图像 发送给审核者进行审核;
    当接收到所述审核者的审核结果为所述人脸图像对应的人员不具有对所述第二密级文件进行操作权限的人员时,将所述人脸图像移除所述白名单中。
  16. 一种非易失性计算机可读存储介质,所述非易失性计算机可读存储介质上存储有至少一个计算机可读指令,其特征在于,所述计算机可读指令被处理器执行以实现以下步骤:
    接收到对第一密级文件的第一操作时,获取对所述第一密级文件进行所述第一操作的用户的人脸图像;
    当识别所述人脸图像为预设白名单中的人脸图像时显示对应所述人脸图像的密码输入框;
    当侦测到所述密码输入框中接收到密码时,判断所述密码与预设的所述第一密级文件对应的密码是否匹配;
    当确定所述密码与预设的所述第一密级文件对应的密码匹配时,打开所述第一密级文件,所述第一密级文件中包括第二密级文件,所述第二密级文件上显示有加密标识,所述加密标识用于提示不具有对所述第二密级文件进行操作权限的用户不能对所述第二密级文件进行操作;
    接收到对所述第二密级文件的第二操作时,随机弹出问题对话框;
    当侦测到所述问题对话框中接收到待验答案时,判断所述待验答案与预设的所述问题的标准答案是否匹配;
    当确定所述待验答案与所述标准答案匹配时,对所述第二密级文件执行所述第二操作。
  17. 如权利要求16所述的非易失性计算机可读存储介质,其特征在于,所述至少一个计算机可读指令被所述处理器执行以实现显示对应所述人脸图像的密码输入框时,包括:
    识别所述人脸图像中的用户对应的角色权限;
    当所述角色权限为第一角色权限时,直接对所述第一密级文件进行所述第一操作;
    当所述角色权限为第二角色权限时,显示对应所述第二角色权限的密码输入框。
  18. 如权利要求16所述的非易失性计算机可读存储介质,其特征在于,所述至少一个计算机可读指令被所述处理器执行以实现所述判断所述密码与预设的所述第一密级文件对应的密码是否匹配时,包括:
    获取与所述人脸图像对应的所述第一密级文件的目标密码,不同的人脸图形对应所述第一密级文件的目标密码不同;
    判断所述密码与所述目标密码是否匹配。
  19. 如权利要求16所述的非易失性计算机可读存储介质,其特征在于,所述至少一个计 算机可读指令被所述处理器执行以实现随机弹出问题对话框时,包括:
    提取所述第二密级文件的文件内容中的多个第一关键词;
    根据每个所述第一关键词首次出现的位置顺序确定所述每个第一关键词的编号;
    采用随机数生成算法生成一个随机数;
    根据所述随机数与编号之间的对应关系筛选出对应所述随机数的第一目标关键词;
    弹出与所述第一目标关键词对应的问题对话框,所述问题对话框中显示有与所述第一目标关键词对应的问题。
  20. 如权利要求16至19中任意一项所述的非易失性计算机可读存储介质,其特征在于,所述至少一个计算机可读指令被所述处理器执行以实现所述判断所述待验答案与所述问题的标准答案是否匹配时,包括:
    根据预设匹配度计算规则计算所述待验答案与所述标准答案之间的匹配度;
    获取所述第二密级文件对应的预设匹配度阈值;
    判断所述匹配度是否大于所述匹配度阈值;
    当所述匹配度大于或者等于所述匹配度阈值时,确定所述待验答案与所述标准答案匹配;
    当所述匹配度小于所述匹配度阈值时,确定所述待验答案与所述标准答案不匹配。
PCT/CN2019/118599 2019-06-19 2019-11-14 共享文件安全管理方法、装置、终端及可读存储介质 Ceased WO2020253068A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910533846.4A CN110414246B (zh) 2019-06-19 2019-06-19 共享文件安全管理方法、装置、终端及存储介质
CN201910533846.4 2019-06-19

Publications (1)

Publication Number Publication Date
WO2020253068A1 true WO2020253068A1 (zh) 2020-12-24

Family

ID=68359366

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/118599 Ceased WO2020253068A1 (zh) 2019-06-19 2019-11-14 共享文件安全管理方法、装置、终端及可读存储介质

Country Status (2)

Country Link
CN (1) CN110414246B (zh)
WO (1) WO2020253068A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113747270A (zh) * 2021-09-06 2021-12-03 蓝鲸智云智能科技南京有限公司 一种云数据中心物联管控系统

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110414246B (zh) * 2019-06-19 2023-05-30 平安科技(深圳)有限公司 共享文件安全管理方法、装置、终端及存储介质
CN110865975A (zh) * 2019-11-13 2020-03-06 中国科学院电子学研究所 一种管理文档的方法、装置、电子设备和存储介质
CN113342753B (zh) * 2021-06-25 2023-04-14 长江存储科技有限责任公司 文件安全管理方法、装置、设备及计算机可读存储介质
CN113934700A (zh) * 2021-10-19 2022-01-14 成都统信软件技术有限公司 共享文件夹访问控制方法、访问方法及访问控制系统
CN115314664A (zh) * 2022-08-05 2022-11-08 中国银行股份有限公司 一种数据展示方法、装置、设备及存储介质

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160110543A1 (en) * 2014-10-21 2016-04-21 Electronics And Telecommunications Research Institute Apparatus and method for detecting malicious application based on visualization similarity
CN105631272A (zh) * 2016-02-02 2016-06-01 云南大学 一种多重保险的身份认证方法
CN105827409A (zh) * 2016-02-29 2016-08-03 宇龙计算机通信科技(深圳)有限公司 一种身份验证的方法及装置
CN106549920A (zh) * 2015-09-21 2017-03-29 华为终端(东莞)有限公司 登录信息输入方法、登录信息保存方法及相关装置
CN107734197A (zh) * 2017-11-30 2018-02-23 河南浩德科技有限公司 屏幕解锁方法、装置、移动终端及计算机存储介质
CN109344588A (zh) * 2018-09-03 2019-02-15 平安科技(深圳)有限公司 安全认证方法及终端设备
CN110414246A (zh) * 2019-06-19 2019-11-05 平安科技(深圳)有限公司 共享文件安全管理方法、装置、终端及存储介质

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102567679A (zh) * 2010-12-24 2012-07-11 上海晨兴希姆通电子科技有限公司 字迹保密锁装置及其应用方法
CN102930225A (zh) * 2012-10-25 2013-02-13 中国航天科工集团第二研究院七〇六所 基于密级标识的电子文档访问控制方法
CN104346388B (zh) * 2013-07-31 2018-03-09 株式会社理光 云端服务器以及图像存储检索系统
US9888383B2 (en) * 2016-05-02 2018-02-06 International Business Machines Corporation Authentication using dynamic verbal questions based on social and geospatial history
CN106778222B (zh) * 2016-12-20 2020-06-02 北京小米移动软件有限公司 解锁方法及装置
CN107133303A (zh) * 2017-04-28 2017-09-05 百度在线网络技术(北京)有限公司 用于输出信息的方法和装置
CN107220558A (zh) * 2017-05-24 2017-09-29 郑州云海信息技术有限公司 一种权限管理的方法、装置及系统
CN108170792B (zh) * 2017-12-27 2021-12-28 北京百度网讯科技有限公司 基于人工智能的问答引导方法、装置和计算机设备
CN109063152A (zh) * 2018-08-08 2018-12-21 鲸数科技(北京)有限公司 智能问答方法、装置及智能终端
CN109254957A (zh) * 2018-09-21 2019-01-22 安徽和信科技发展有限责任公司 一种基于大数据的档案管理系统
CN109492085B (zh) * 2018-11-15 2024-05-14 平安科技(深圳)有限公司 基于数据处理的答案确定方法、装置、终端及存储介质

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160110543A1 (en) * 2014-10-21 2016-04-21 Electronics And Telecommunications Research Institute Apparatus and method for detecting malicious application based on visualization similarity
CN106549920A (zh) * 2015-09-21 2017-03-29 华为终端(东莞)有限公司 登录信息输入方法、登录信息保存方法及相关装置
CN105631272A (zh) * 2016-02-02 2016-06-01 云南大学 一种多重保险的身份认证方法
CN105827409A (zh) * 2016-02-29 2016-08-03 宇龙计算机通信科技(深圳)有限公司 一种身份验证的方法及装置
CN107734197A (zh) * 2017-11-30 2018-02-23 河南浩德科技有限公司 屏幕解锁方法、装置、移动终端及计算机存储介质
CN109344588A (zh) * 2018-09-03 2019-02-15 平安科技(深圳)有限公司 安全认证方法及终端设备
CN110414246A (zh) * 2019-06-19 2019-11-05 平安科技(深圳)有限公司 共享文件安全管理方法、装置、终端及存储介质

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113747270A (zh) * 2021-09-06 2021-12-03 蓝鲸智云智能科技南京有限公司 一种云数据中心物联管控系统
CN113747270B (zh) * 2021-09-06 2024-01-02 蓝鲸智云智能科技南京有限公司 一种云数据中心物联管控系统

Also Published As

Publication number Publication date
CN110414246A (zh) 2019-11-05
CN110414246B (zh) 2023-05-30

Similar Documents

Publication Publication Date Title
WO2020253068A1 (zh) 共享文件安全管理方法、装置、终端及可读存储介质
AI Artificial intelligence risk management framework: Generative artificial intelligence profile
US12348559B2 (en) Account classification using a trained model and sign-in data
US12022000B2 (en) Method for information processing in digital asset certificate inheritance transfer, and related device
US8127365B1 (en) Origination-based content protection for computer systems
CN104881606B (zh) 基于形式化建模的软件安全需求获取方法
CN110489994B (zh) 核电站的文件权限管理方法、装置及终端设备
US12282719B1 (en) Building and simulating execution of managed artificial intelligence pipelines
US10402549B1 (en) Systems and methods for creating validated identities for dependent users
US20210111870A1 (en) Authorizing and validating removable storage for use with critical infrastrcture computing systems
CN117332391A (zh) 计及权限分级管控的配电网数据资产安全访问方法及系统
CN112328975A (zh) 一种产品软件授权管理方法、终端设备及介质
WO2013081185A1 (ja) セキュリティ検証装置及びセキュリティ検証方法
CN112825093B (zh) 安全基线检查方法、主机、服务器、电子设备及存储介质
US20250217509A1 (en) Enhanced dynamic security with partial data access to preserve anonymity
CN120354453A (zh) 一种文档加密方法、系统、程序产品及存储介质
US11088923B2 (en) Multi-stage authorization
Vasudevan et al. Mapping the metaverse minefield: a TIPS framework for security-conscious business adoption
CN113656376B (zh) 一种数据处理方法、装置及计算机设备
CN109889342A (zh) 接口测试鉴权方法、装置、电子设备及存储介质
CN109525554B (zh) 金融数据通信方法、装置、介质及电子设备
CN114531295A (zh) 一种用户行为审计系统、方法、设备及存储介质
CN114143025A (zh) 云平台安全策略管理系统
CN114091112A (zh) 应用权限管控方法、装置和电子设备
US20260099594A1 (en) Automated application security onboarding

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19933895

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19933895

Country of ref document: EP

Kind code of ref document: A1