A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://patents.google.com/patent/CN103617402B/en below:

CN103617402B - A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system

CN103617402B - A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system - Google PatentsA kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Download PDF Info
Publication number
CN103617402B
CN103617402B CN201310607114.8A CN201310607114A CN103617402B CN 103617402 B CN103617402 B CN 103617402B CN 201310607114 A CN201310607114 A CN 201310607114A CN 103617402 B CN103617402 B CN 103617402B
Authority
CN
China
Prior art keywords
electronic data
report
file
multimedia
multimedia electronic
Prior art date
2013-11-25
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201310607114.8A
Other languages
Chinese (zh)
Other versions
CN103617402A (en
Inventor
张建明
鲜文兵
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Ruian Technology Co Ltd
Original Assignee
Beijing Ruian Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
2013-11-25
Filing date
2013-11-25
Publication date
2016-03-30
2013-11-25 Application filed by Beijing Ruian Technology Co Ltd filed Critical Beijing Ruian Technology Co Ltd
2013-11-25 Priority to CN201310607114.8A priority Critical patent/CN103617402B/en
2014-03-05 Publication of CN103617402A publication Critical patent/CN103617402A/en
2016-03-30 Application granted granted Critical
2016-03-30 Publication of CN103617402B publication Critical patent/CN103617402B/en
Status Expired - Fee Related legal-status Critical Current
2033-11-25 Anticipated expiration legal-status Critical
Links Classifications Landscapes Abstract Translated from Chinese

本发明涉及一种多媒体电子数据取证报告及其生成、展示方法和系统,该系统包括,多媒体电子数据取证报告的采集装置;多媒体电子数据取证报告生成装置;认证展示装置,在取证报告生成时将压缩的数据文件采用压缩算法、校验方法、不可逆的加密算法以及对应的在取证报告展示时解密数据、自解压检验头文件,合并生成多媒体报告。本发明的方法和系统能够从整体上确保多媒体电子数据的完整性、防篡改和安全性。无论电子数据证据是文本还是视听材料,都能通过封闭的防篡改装置进行完整性技术防篡改,并加入电子证据展示认证机制,处理过程更安全、隐蔽。

The present invention relates to a multimedia electronic data forensics report and its generation and display method and system. The system includes: a collection device for multimedia electronic data forensics report; a device for generating multimedia electronic data forensics report; and an authentication and display device. Compressed data files adopt compression algorithm, verification method, irreversible encryption algorithm and corresponding decryption data when displaying forensics report, self-extraction inspection header file, and merge to generate multimedia report. The method and system of the invention can ensure the integrity, tamper-proof and security of multimedia electronic data as a whole. Regardless of whether the electronic data evidence is text or audio-visual materials, it can be tamper-proofed by integrity technology through a closed tamper-proof device, and an electronic evidence display authentication mechanism is added to make the processing process safer and more concealed.

Description Translated from Chinese 一种多媒体电子数据取证报告及其生成、展示方法和系统A multimedia electronic data forensics report and its generation and display method and system

技术领域technical field

本发明属电子数据证据领域,涉及多媒体电子数据证据的固定、传输、再现。The invention belongs to the field of electronic data evidence and relates to the fixing, transmission and reproduction of multimedia electronic data evidence.

背景技术Background technique

面对信息化、数字化的今天,电子数据证据的收集和固定行为要求基于电子证据的原始性原则,必须保证电子证据从产生到输出的完整性和有效性。传统的文本内容的电子证据,可通过打印,注明取证时间、取证人员、数据来源等,并加盖公章后,以书证的形式予以固定保存,防止电子证据固定过程的完整性遭到破坏;传统的具有视听资料,如包含音频、视频的证据,采用拍照和摄像的方法对证据加以固定。In the face of today's informatization and digitization, the collection and fixation of electronic data evidence requires the original principle of electronic evidence, and the integrity and validity of electronic evidence must be guaranteed from generation to output. Electronic evidence of traditional text content can be printed, indicating the time of evidence collection, evidence collection personnel, data source, etc., and stamped with the official seal, and then be fixed and preserved in the form of documentary evidence to prevent the integrity of the electronic evidence fixing process from being damaged; Traditionally, there are audio-visual materials, such as evidence including audio and video, and the methods of taking photos and videos are used to fix the evidence.

现有技术主要应用于数字签名技术,通过计算电子数据唯一的数字摘要值或校验码,保证电子数据证据的完整性,但在现有技术中都未涉及多媒体电子数据证据如何固定、传输和再现的完整解决方案。现有技术对电子证据形成存在薄弱地区如下:(1)多媒体电子数据证据如何固定,没有相应的信息化技术方案;(2)多媒体电子数据证据中,涉及大量的音、视频资料,如果按传统方法逐个进行签名,那么传输过程中可以将某文件及对应签名同时删除而不被发现,从而破坏证据的完整性;如果对涉及的音、视频资料整体打包签名,涉及的展示问题有没有规范的解决方案;(3)采用数字签名过程中未加入加密机制,可能存在恶意程序的侵入,破坏签名的有效性。The prior art is mainly applied to the digital signature technology, which ensures the integrity of the electronic data evidence by calculating the unique digital digest value or check code of the electronic data, but none of the prior art involves how the multimedia electronic data evidence is fixed, transmitted and A complete solution for reproduction. There are weak areas in the existing technology for the formation of electronic evidence as follows: (1) There is no corresponding information technology solution for how to fix multimedia electronic data evidence; (2) Multimedia electronic data evidence involves a large amount of audio and video materials. method to sign one by one, then a file and the corresponding signature can be deleted at the same time during the transmission process without being discovered, thereby destroying the integrity of the evidence; if the audio and video materials involved are packaged and signed as a whole, is there a standard for the display problem involved? Solution; (3) The encryption mechanism is not added in the process of digital signature, and there may be intrusion of malicious programs, which will destroy the validity of the signature.

发明内容Contents of the invention

本发明的目的之一是提供一种多媒体电子数据取证报告生成、展示方法,从整体上确保多媒体电子数据的完整性、防篡改和安全性。无论电子数据证据是文本还是视听材料,都能通过封闭的防篡改装置进行完整性技术防篡改,并加入电子证据展示认证机制,处理过程更安全、隐蔽。One of the objectives of the present invention is to provide a method for generating and displaying multimedia electronic data forensics reports, which can ensure the integrity, tamper-proof and security of multimedia electronic data as a whole. Regardless of whether the electronic data evidence is text or audio-visual materials, it can be tamper-proofed by integrity technology through a closed tamper-proof device, and an electronic evidence display authentication mechanism is added to make the processing process safer and more concealed.

一种多媒体电子数据取证报告生成方法,其步骤包括:A method for generating a multimedia electronic data forensics report, the steps comprising:

1)提取至少一种类型的电子数据并建立基于文件目录的初步电子取证报告;1) Extract at least one type of electronic data and create a preliminary electronic forensics report based on the file directory;

2)对所述初步电子文件取证报告进行压缩合并成单一的压缩文件并记录文件存储位置;2) Compress and merge the preliminary electronic document forensics report into a single compressed file and record the storage location of the file;

3)将随机生成字符串密钥作为所述压缩文件对称加密密钥;然后对所述压缩文件进行加密计算出文件摘要;3) Use a randomly generated string key as the symmetric encryption key for the compressed file; then encrypt the compressed file to calculate the file digest;

4)使用预置的非对称加密算法对所述文件摘要、文件存储位置以及文件对称加密密钥进行加密;加密完成后增加一引导程序,生成单一文件格式的多媒体电子数据取证报告。4) Use a preset asymmetric encryption algorithm to encrypt the file abstract, file storage location, and file symmetric encryption key; after the encryption is completed, add a boot program to generate a multimedia electronic data forensics report in a single file format.

优选地,所述基于文件目录的初步电子取证报告基于html超文本标识语言。Preferably, the preliminary electronic forensics report based on file directory is based on html hypertext markup language.

优选地,采用MD5或SHA1计算出文件摘要。Preferably, the file digest is calculated by using MD5 or SHA1.

优选地,根据所述文件摘要验证出没有被篡改的电子数据取证报告的方法为:Preferably, the method for verifying the electronic data forensics report that has not been tampered with according to the document summary is as follows:

比较计算得到的文件摘要与生成电子数据取证报告时产生的文件摘要是否相同,如果相同,则多媒体电子数据取证文件是完整而且未被篡改;如果不相同,则多媒体电子数据取证文件被篡改过,提示数据不完整,需要从原始数据源重新获得取证报告。Compare the calculated file abstract with the file abstract generated when the electronic data forensics report is generated. If they are the same, the multimedia electronic data forensics file is complete and has not been tampered with; if they are not the same, the multimedia electronic data forensics file has been tampered with. Indicates that the data is incomplete and the forensic report needs to be retrieved from the original data source.

优选地,在多媒体取证报告运行展示中,加入签名认证机制,显示认证签名单位,使多媒体报告在传输过程中更安全有效。Preferably, in the running display of the multimedia forensics report, a signature authentication mechanism is added to display the authentication signature unit, so that the transmission of the multimedia report is safer and more effective.

优选地,至少一种类型的电子数据包括:word文档,excel文档,短信,通话记录,照片,录音,录像。Preferably, at least one type of electronic data includes: word documents, excel documents, short messages, call records, photos, audio recordings, and video recordings.

更进一步,根据所述多媒体电子数据取证报告生成方法生成的一种多媒体电子数据取证报告的验证展示方法,其步骤包括:Furthermore, a method for verifying and displaying a multimedia electronic data forensics report generated according to the method for generating a multimedia electronic data forensics report, the steps of which include:

1)将所述多媒体电子数据取证报告传输到需要展示的计算机和/或移动终端设备启动引导程序解密出文件摘要、文件存储位置以及文件对称加密密钥;1) Transmit the multimedia electronic data forensics report to the computer and/or mobile terminal equipment to be displayed to start the boot program to decrypt the file summary, file storage location and file symmetric encryption key;

2)根据所述文件摘要验证出没有被篡改的电子数据取证报告,并根据所述对称加密密钥对该电子数据取证报告进行解密,将生成结果保存到临时文件目录对取证报告进行展示;2) Verify the electronic data forensics report that has not been tampered with according to the document summary, and decrypt the electronic data forensics report according to the symmetric encryption key, and save the generated result to the temporary file directory to display the forensics report;

3)所述报告引导程序自动删除临时文件,完成展示。3) The report guide program automatically deletes temporary files to complete the display.

优选地,所述多媒体电子数据取证报告在展示时,加入签名认证机制,显示认证签名单位。Preferably, when the multimedia electronic data forensics report is displayed, a signature authentication mechanism is added to display the authentication signature unit.

优选地,通过U盘拷贝、网络传送的方式将所述多媒体电子数据取证报告传输到需要展示的计算机和/或移动终端设备。Preferably, the multimedia electronic data forensics report is transmitted to the computer and/or mobile terminal equipment that needs to be displayed by means of USB disk copy and network transmission.

本发明的另一目的在于提供一种多媒体电子数据取证报告,包括经过非对称加密的:文件摘要、文件存储位置、压缩文件对称加密密钥以及一引导程序;Another object of the present invention is to provide a multimedia electronic data forensics report, including asymmetrically encrypted: file summary, file storage location, compressed file symmetric encryption key and a boot program;

所述压缩文件对称加密密钥将随机生成字符串密钥获得;The compressed file symmetric encryption key will be obtained by randomly generating a string key;

所述文件摘要通过对所述压缩文件进行加密获得;The file digest is obtained by encrypting the compressed file;

所述引导程序用于在用户运行该多媒体电子数据取证报告后,对多媒体取证报告的完整性进行校验;The guide program is used to verify the integrity of the multimedia electronic data forensics report after the user runs the multimedia electronic data forensics report;

所述文件存储位置用于记录保存该多媒体电子数据取证报告时自动显示这个多媒体展示目录。The file storage location is used to automatically display the multimedia display directory when recording and saving the multimedia electronic data forensics report.

本发明的另一目的在于提供一种多媒体电子数据取证报告生成展示系统,从整体上解决多媒体电子数据证据的固定、传输和展示,具体技术方案如下:Another object of the present invention is to provide a multimedia electronic data forensics report generation and display system, which solves the fixing, transmission and display of multimedia electronic data evidence as a whole. The specific technical solutions are as follows:

本发明还提出一种多媒体电子数据取证报告生成、展示系统,包括:多媒体电子数据取证报告的采集装置;多媒体电子数据取证报告生成装置;认证展示装置;The present invention also proposes a system for generating and displaying a multimedia electronic data forensic report, comprising: a collection device for a multimedia electronic data forensic report; a device for generating a multimedia electronic data forensic report; an authentication display device;

所述多媒体电子数据取证报告的采集装置,用于从计算机和/或移动终端设备中采集至少一种类型的电子数据;The collection device of the multimedia electronic data forensics report is used to collect at least one type of electronic data from computers and/or mobile terminal equipment;

所述多媒体电子数据取证报告生成装置,用于根据提取得到的至少一种类型的电子数据并建立基于文件目录的初步电子取证报告;对所述初步电子文件取证报告进行压缩合并成单一的压缩文件并记录文件存储位置;将随机生成字符串密钥作为所述压缩文件对称加密密钥;然后对所述压缩文件进行加密计算出文件摘要;使用预置的非对称加密算法对所述文件摘要、文件存储位置以及文件对称加密密钥进行加密;加密完成后增加一引导程序,生成单一文件格式的多媒体电子数据取证报告;The multimedia electronic data forensics report generating device is used to create a preliminary electronic forensics report based on the file directory based on the extracted at least one type of electronic data; compress and merge the preliminary electronic file forensics report into a single compressed file And record the file storage location; randomly generate a character string key as the compressed file symmetric encryption key; then encrypt the compressed file to calculate the file abstract; use the preset asymmetric encryption algorithm to encrypt the file abstract, The file storage location and file symmetric encryption key are encrypted; after the encryption is completed, a boot program is added to generate a multimedia electronic data forensics report in a single file format;

所述认证展示装置,用于将所述多媒体电子数据取证报告传输到需要展示的计算机和/或移动终端设备启动引导程序解密出文件摘要、文件存储位置以及文件对称加密密钥;根据所述文件摘要验证出没有被篡改的电子数据取证报告,并根据所述对称加密密钥对该电子数据取证报告进行解密,将生成结果保存到临时文件目录对取证报告进行展示;所述报告引导程序自动删除临时文件,完成展示。The authentication display device is used to transmit the multimedia electronic data forensics report to the computer and/or mobile terminal equipment that needs to be displayed to start the boot program to decrypt the file abstract, file storage location and file symmetric encryption key; according to the file The summary verifies that the electronic data forensics report has not been tampered with, and decrypts the electronic data forensics report according to the symmetric encryption key, and saves the generated result to a temporary file directory to display the forensics report; the report guide program automatically deletes Temporary file, complete display.

本发明的有益效果:Beneficial effects of the present invention:

与现有技术相比,本发明对多媒体取证报告在传输过程中数据进行完整性保护。Compared with the prior art, the invention protects the integrity of the data in the transmission process of the multimedia forensics report.

1)通过压缩多媒体数据,计算文件校验值,生成加密数据、检验头文件,并对及生成的校验值加密处理,有效防止恶意用户更改校验值的目的。1) By compressing multimedia data, calculating file verification value, generating encrypted data, verifying header files, and encrypting the generated verification value, it can effectively prevent malicious users from changing the verification value.

2)将压缩的数据文件采用压缩算法、校验方法、不可逆的加密算法以及对应的解密数据、自解压检验头文件,合并生成多媒体报告。2) Combine compressed data files with compression algorithm, verification method, irreversible encryption algorithm, corresponding decrypted data, and self-extracting inspection header files to generate a multimedia report.

3)在多媒体取证报告运行展示中,加入签名认证机制,显示认证签名单位,使多媒体报告在传输过程中更安全有效。3) In the running display of the multimedia forensics report, a signature authentication mechanism is added to display the authentication signature unit, making the multimedia report more secure and effective during transmission.

附图说明Description of drawings

图1为本发明一实施例中实现运用多媒体电子数据取证报告的示意图;Fig. 1 is the schematic diagram that realizes using multimedia electronic data forensics report in one embodiment of the present invention;

图2为本发明一实施例中多媒体电子数据取证报告文件生成执行流程图Fig. 2 is the flow chart of generating and executing multimedia electronic data forensics report file in one embodiment of the present invention

图3为本发明一实施例中多媒体电子数据取证报告的认证展示流程图:Fig. 3 is the authentication demonstration flow chart of multimedia electronic data forensics report in one embodiment of the present invention:

图4为本发明一实施例中以某电子数据取证鉴定中心为例对某部手机进行勘查鉴定的流程示意图。Fig. 4 is a schematic flow diagram of an investigation and appraisal of a certain mobile phone by taking a certain electronic data forensics and appraisal center as an example in an embodiment of the present invention.

图5为本发明一实施例中鉴定任务提出人可以将多媒体电子数据取证报告在通用的计算机上,进行浏览、展示示意图。Fig. 5 is a schematic diagram of an identification task proposer who can browse and display multimedia electronic data forensics reports on a general-purpose computer in an embodiment of the present invention.

具体实施方式detailed description

为了使本发明的目的、技术方案更加明确,以下通过具体实施例并配合附图,对本发明进行详细说明。In order to make the purpose and technical solution of the present invention clearer, the present invention will be described in detail below through specific embodiments and accompanying drawings.

在本发明的一实施例中多媒体电子数据取证报告的固定、传输和展示过程涉及到了一种多媒体电子数据取证报告生成展示系统,包括三部分:多媒体电子数据取证报告的采集装置;多媒体电子数据取证报告生成装置;认证展示装置;以下是对装置的详细说明:In one embodiment of the present invention, the process of fixing, transmitting and displaying the multimedia electronic data forensics report involves a system for generating and displaying the multimedia electronic data forensics report, which includes three parts: a collection device for the multimedia electronic data forensics report; a multimedia electronic data forensics report collection device; Report Generating Device; Certification Demonstration Device; The following is a detailed description of the device:

多媒体电子数据取证报告采集装置,用于从计算机、移动终端设备中采集文本、照片、音频、视频材料。在计算机和移动终端设备中,存在大量的电子数据,采集装置会根据多媒体电子数据报告使用者的要求,电子数据取证人员可以对读取的多媒体类型进行预设、选取。预设可选择哪哪一类型的电子数据作为电子数据证据,如word文档,excel文档,短信,通话记录,照片,录音,录像等。The multimedia electronic data forensics report collection device is used to collect text, photos, audio and video materials from computers and mobile terminal equipment. In computers and mobile terminal equipment, there is a large amount of electronic data, and the acquisition device will report the user's requirements according to the multimedia electronic data, and the electronic data forensics personnel can preset and select the type of multimedia to be read. Preset which type of electronic data can be selected as electronic data evidence, such as word documents, excel documents, text messages, call records, photos, audio recordings, video recordings, etc.

采集到多媒体数据后选取出特定的电子数据类型,作为电子数据证据,提供给用户。采集到的文本、照片、音频、视频等文件,一般可以在采集设备上直接进行浏览、分析。多媒体证据采集装置采集到的文本、照片、音频、视频文件,将作为输入传入多媒体电子数据取证报告生成装置。After the multimedia data is collected, a specific electronic data type is selected and provided to the user as electronic data evidence. The collected text, photos, audio, video and other files can generally be browsed and analyzed directly on the collection device. The text, photos, audio and video files collected by the multimedia evidence collection device will be sent to the multimedia electronic data evidence collection report generation device as input.

多媒体电子数据取证报告生成装置,用于将采集的文本、照片、音频、视频材料,经目录组织、压缩、摘要、加密后形成单个文件。The multimedia electronic data forensics report generation device is used to form a single file after the collected text, photos, audio and video materials are cataloged, compressed, summarized and encrypted.

本领域技术人员清楚地明了目录组织是指:从移动通信设备或者计算机中提取的电子数据,为了方便多媒体电子数据取证报告的使用者的分析理解,按照电子数据类型,如通信录、通话记录,照片等,以目录的形式逐级展示。Those skilled in the art clearly understand that directory organization refers to electronic data extracted from mobile communication devices or computers. In order to facilitate the analysis and understanding of users of multimedia electronic data forensics reports, according to the type of electronic data, such as address books and call records, Photos, etc., are displayed step by step in the form of a directory.

在本发明中通过压缩后,将多个多媒体电子文件合并成一个单一文件。After compression in the present invention, multiple multimedia electronic files are combined into a single file.

所述摘要的目的对文件的完整性进行校验,计算摘要后,对摘要进行加密。一旦文件被修改,就可以通过比较摘要,发现文件被修改。由于摘要加密采用非对称加密算法,因此无法伪造加密后的摘要。The purpose of the digest is to verify the integrity of the file, and after the digest is calculated, the digest is encrypted. Once the file is modified, it can be found that the file has been modified by comparing the summary. Since the digest encryption uses an asymmetric encryption algorithm, it is impossible to forge the encrypted digest.

所述加密是指:对摘要的加密采用的是非对称加密算法,对整个文件的加密采用的是对称加密算法。The encryption refers to: an asymmetric encryption algorithm is used for the encryption of the abstract, and a symmetric encryption algorithm is used for the encryption of the entire file.

所述多媒体电子数据取证报告的认证展示装置,用于在确认多媒体电子数据取证报告完整性和一致性之后,对多媒体电子数据取证报告进行展示。The certification display device for the multimedia electronic data forensics report is used for displaying the multimedia electronic data forensics report after confirming the integrity and consistency of the multimedia electronic data forensics report.

在本发明的一实施例中一种多媒体电子数据取证报告生成展示方法,其步骤为:In an embodiment of the present invention, a method for generating and displaying a multimedia electronic data forensics report, the steps are:

第一步,用户从多媒体电子数据采集装置中选择特定的电子数据后,作为输入传送给多媒体电子数据取证报告生成装置。多媒体电子数据取证报告生成装置根据电子数据的内在关联关系,建立基于html标识语言的方便浏览的基于文件目录的电子数据取证报告。此步骤完成后,即形成初步的html取证报告,可以通过html的目录格式,方便的浏览各种取证信息。Html即“超文本”就是指页面内可以包含图片、链接,甚至音乐、程序等非文字元素。超文本标记语言的结构包括头部分(Head)、和主体部分(Body),其中头部(head)提供关于网页的信息,主体(body)部分提供网页的具体内容。In the first step, the user selects specific electronic data from the multimedia electronic data collection device, and sends it as an input to the multimedia electronic data forensic report generation device. The multimedia electronic data forensics report generation device creates an electronic data forensics report based on the file directory for easy browsing based on the html markup language according to the internal correlation of the electronic data. After this step is completed, a preliminary html forensic report will be formed, and various forensic information can be easily browsed through the html directory format. Html or "hypertext" means that the page can contain non-text elements such as pictures, links, and even music and programs. The structure of the hypertext markup language includes a head part (Head) and a body part (Body), wherein the head (head) provides information about the web page, and the body (body) part provides the specific content of the web page.

第二步,将基于文件目录格式的html取证报告进行压缩合并,形成一个单一的压缩文件(即将html的取证报告压缩合并为一个压缩文件),并记录html文件的文件存储位置(html文件作为多媒体电子数据取证报告的展示目录,需要记录这个文件的在压缩包中的相对位置,这样便于在展示对媒体取证报告时,自动显示这个多媒体目录。)。自动生成一个字符串密码,作为对压缩后文件的对称加密算法的密钥即输入,对生成的压缩文件进行加密。采用MD5或SHA1计算这个压缩文件的文件摘要得到校验值,采用的是标准的校验方法,即不可逆的hash值比较,在本发明中并不做具体的限制。将生成的文件摘要、对称加密密码(自动生产的字符串秘密)、html文件存储位置信息,使用预制的非对称加密算法进行加密。The second step is to compress and merge the html forensic report based on the file directory format to form a single compressed file (that is, compress and merge the html forensic report into a compressed file), and record the file storage location of the html file (the html file is used as a multimedia The display directory of the electronic data forensics report needs to record the relative position of this file in the compressed package, so that this multimedia directory can be automatically displayed when displaying the media forensics report.). Automatically generate a string password, which is input as the key of the symmetric encryption algorithm for the compressed file, and encrypt the generated compressed file. Adopting MD5 or SHA1 to calculate the file summary of this compressed file to obtain the verification value, what adopts is a standard verification method, that is, irreversible hash value comparison, which is not specifically limited in the present invention. The generated file summary, symmetric encryption password (automatically generated string secret), and html file storage location information are encrypted using a prefabricated asymmetric encryption algorithm.

第三步,将多媒体电子数据取证报告处理引导程序、压缩加密后的数据文件、加密后的文件摘要和对称加密密码、html文件存储位置信息进行统一处理,生成单一文件格式的多媒体取证报告。所述引导程序的作用是在双击运行多媒体取证报告后,对多媒体取证报告的完整性进行校验,如果多媒体取证报告没有被修改,它可以将基于html目录的多媒体取证报告解析出来,并打开html目录供用户浏览。The third step is to uniformly process the multimedia electronic data forensics report processing boot program, compressed and encrypted data files, encrypted file abstracts, symmetric encryption passwords, and html file storage location information to generate a multimedia forensics report in a single file format. The function of the boot program is to verify the integrity of the multimedia forensics report after double-clicking to run the multimedia forensics report. If the multimedia forensics report has not been modified, it can parse out the multimedia forensics report based on the html directory and open the html Directory for users to browse.

多媒体电子数据取证报告的认证展示装置,用于在确认多媒体电子数据取证报告完整性和一致性之后,对多媒体电子数据取证报告进行展示,展示方法如下:The certified display device for the multimedia electronic data forensics report is used to display the multimedia electronic data forensics report after confirming the integrity and consistency of the multimedia electronic data forensics report. The display method is as follows:

第一步,多媒体电子数据取证报告引导程序,解密出文件摘要非对称加密的密钥、对称加密密钥和html文件存储位置信息。In the first step, the multimedia electronic data forensics report guide program decrypts the asymmetric encryption key of the document abstract, the symmetric encryption key and the storage location information of the html file.

第二步,对压缩加密的多媒体数据文件,用与生产多媒体电子数据取证报告相同的算法计算文件摘要。比较计算得到的文件摘要与第一步得到的文件摘要,如果相同,则认为多媒体电子数据取证文件是完整而且未被篡改过的,进入第三步;如果不相同,说明多媒体电子数据取证文件是被篡改过的,提示数据不完整,需要从原始数据源获得取证报告后,退出处理过程。In the second step, for the compressed and encrypted multimedia data files, the file summary is calculated using the same algorithm as that used for producing multimedia electronic data forensics reports. Comparing the calculated file abstract with the file abstract obtained in the first step, if they are the same, it is considered that the multimedia electronic data forensics file is complete and has not been tampered with, and enter the third step; if not the same, it means that the multimedia electronic data forensics file is If it has been tampered with, it indicates that the data is incomplete, and it is necessary to obtain a forensic report from the original data source and exit the processing process.

第三步,使用第一步获得的对称加密密钥,对压缩加密后的多媒体电子数据文件进行解密(在展示时,使用步骤二中的密钥对加密后的压缩文件进行解密),生成一个单一的压缩文件。对这个压缩文件,使用压缩算法对应的解压算法进行解压,将生成结果保存到临时文件目录。In the third step, use the symmetric encryption key obtained in the first step to decrypt the compressed and encrypted multimedia electronic data file (during the display, use the key in step 2 to decrypt the encrypted compressed file), and generate a single compressed file. For this compressed file, use the decompression algorithm corresponding to the compression algorithm to decompress, and save the generated result to the temporary file directory.

第四步,多媒体电子数据取证报告引导程序调用展示计算机上的浏览器,以html文件存储位置信息作为输入,按照预设的多媒体电子数据目录,对取证信息进行展示。In the fourth step, the guide program of the multimedia electronic data forensics report invokes the browser on the display computer, takes the storage location information of the html file as input, and displays the forensic information according to the preset multimedia electronic data directory.

第五步,对多媒体电子数据取证报告展示完成,关闭对应的浏览器后,多媒体电子数据取证报告引导程序自动删除程序生成的临时文件。In the fifth step, the display of the multimedia electronic data forensics report is completed, and after closing the corresponding browser, the multimedia electronic data forensics report guide program automatically deletes the temporary files generated by the program.

上述展示方式还包括签名机制,是对多媒体电子数据取证报告采集人的身份认证。The above display method also includes a signature mechanism, which is the identity authentication of the collector of the multimedia electronic data forensics report.

图1为本发明一实施例中实现运用多媒体电子数据取证报告的示意图。电子数据取证员进行多媒体数据采集,采集完后形成多媒体电子数据取证报告。根据该多媒体电子数据取证报告,多媒体电子报告使用者可以直接用其进行展示用户。FIG. 1 is a schematic diagram of realizing the use of multimedia electronic data for forensic reporting in an embodiment of the present invention. The electronic data forensics officer collects multimedia data, and forms a multimedia electronic data forensics report after the collection is completed. According to the multimedia electronic data forensics report, the user of the multimedia electronic report can directly use it to display the user.

图2为本发明一实施例中多媒体电子数据取证报告文件生成执行流程图。流程如下:Fig. 2 is a flow chart of generating and executing multimedia electronic data forensics report files in an embodiment of the present invention. The process is as follows:

1)将多媒体数据采集获得的多媒体电子数据或者选取用于生成多媒体电子数据取证报告的源数据;1) Collect the multimedia electronic data obtained by multimedia data collection or select the source data used to generate the multimedia electronic data forensics report;

2)根据获得的数据生成基于文件目录的html的多媒体电子数据报告;2) According to the obtained data, generate an html multimedia electronic data report based on the file directory;

3)压缩成单一文件格式;3) Compressed into a single file format;

4)加密、计算文件摘要;4) Encryption and calculation of file digests;

5)使用非对称加密算法对文件摘要、文件加密密码、html存在路径信息进行加密;5) Use an asymmetric encryption algorithm to encrypt file abstracts, file encryption passwords, and html existence path information;

6)生成多媒体电子数据报告。6) Generate multimedia electronic data reports.

图3为本发明一实施例中多媒体电子数据取证报告的认证展示流程图。流程如下:Fig. 3 is a flow chart of authentication presentation of a multimedia electronic data forensics report in an embodiment of the present invention. The process is as follows:

1)多媒体电子数据取证报告被以U盘拷贝、网络传送等方式,发送到需要进行电子数据取证结果展示的计算机;1) The multimedia electronic data forensics report is sent to the computer that needs to display the electronic data forensics results by means of U disk copy, network transmission, etc.;

2)双击多媒体电子数据取证报告文件;2) Double-click the multimedia electronic data forensics report file;

3)多媒体电子数据取证报告引导程序还原出文件摘要,加密密码,html存储路劲等信息;3) The multimedia electronic data forensics report guide program restores the file summary, encrypted password, html storage path and other information;

4)计算文件摘要,并与存储的文件摘要进行比较,若摘要不相同,则提示多媒体数据取证报告可能被篡改,结束打开;若摘要相同,则将多媒体电子数据取证文件解密、解压到临时路径;4) Calculate the file summary and compare it with the stored file summary. If the summary is not the same, it will prompt that the multimedia data forensics report may have been tampered with and end the opening; if the summary is the same, the multimedia electronic data forensics file will be decrypted and decompressed to a temporary path. ;

5)使用系统自带的浏览器对html进行展示,实现对多媒体电子数据的展示;5) Use the browser that comes with the system to display html to realize the display of multimedia electronic data;

6)完成对多媒体取证报告的浏览后关闭浏览器,自动删除生成的临时路径和文件。6) Close the browser after browsing the multimedia forensics report, and automatically delete the generated temporary paths and files.

如图4所示是某电子数据取证鉴定中心为例对某部手机进行勘查鉴定的流程示意图。当某电子数据取证鉴定中心接受一项任务,鉴定中心指派鉴定员对该手机进行鉴定,该鉴定员对这部手机进行取证鉴定后,利用多媒体电子数据取证报告生成技术,生成可以脱离取证鉴定设备的多媒体电子数据取证报告。该多媒体电子数据取证报告被以文件的形式拷贝或者通过网络发送给鉴定任务提出人。在多媒体电子数据取证报告生成装置中进行如下的操作:As shown in Figure 4, it is a schematic diagram of the flow chart of an electronic data forensics identification center for an example of a certain mobile phone investigation and identification. When an electronic data forensics appraisal center accepts a task, the appraisal center assigns an appraiser to appraise the mobile phone. After the appraiser conducts the forensic appraisal of the mobile phone, he uses the multimedia electronic data forensics report generation technology to generate a device that can be separated from the forensic appraisal. Multimedia Electronic Data Forensics Report. The multimedia electronic data forensics report is copied in the form of a file or sent to the identification task proposer through the network. Perform the following operations in the multimedia electronic data forensics report generation device:

1)生成基于文件路径的html报告;1) Generate an html report based on the file path;

2)将生成的文件摘要、对称加密密码、html文件存储位置信息,使用预制的非对称加密算法进行加密;2) Encrypt the generated file summary, symmetric encryption password, and html file storage location information using a prefabricated asymmetric encryption algorithm;

3)将多媒体电子数据取证报告引导程序、压缩文件以及相关信息处理生成多媒体电子取证报告。3) Process the multimedia electronic data forensics report guide program, compressed files and related information to generate a multimedia electronic forensics report.

图5所示是定任务提出人,可以将多媒体电子数据取证报告在通用的计算机上的浏览、展示示意图。通过多媒体电子数据取证报告中应用的非对称加密技术,能够确保电子数据的完整性和一致性。具体流程如下:Fig. 5 is a schematic diagram showing a task proposer who can browse and display multimedia electronic data forensics reports on a general-purpose computer. Through the asymmetric encryption technology applied in the multimedia electronic data forensics report, the integrity and consistency of electronic data can be ensured. The specific process is as follows:

1)鉴定任务提出人,获得多媒体电子数据取证报告文件;1) Identify the task proposer and obtain the multimedia electronic data forensics report;

2)在多媒体电子数据取证报告展示认证装置中,多媒体电子数据取证报告引导程序对取证报告进行分析;2) In the multimedia electronic data forensics report display authentication device, the multimedia electronic data forensics report guide program analyzes the forensics report;

3)确定取证报告的完整性和一致性;3) determine the completeness and consistency of the forensic report;

4)解压到临时文件夹;4) Unzip to a temporary folder;

5)对多媒体取证报告进行浏览和展示;5) Browse and display the multimedia forensics report;

6)展示完成后,删除临时文件。6) After the display is complete, delete the temporary file.

Claims (11)

1. a multimedia electronic data forensic report generation method, its step comprises:

1) the preliminary electron evidence obtaining that the electronic data extracting at least one type is also set up based on file directory is reported;

2) described preliminary electron file evidence obtaining report is compressed be merged into single compressed file and log file memory location;

3) using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document;

4) preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout.

2. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, the described evidence obtaining of the preliminary electron based on file directory report is based on html Hypertext Markup Language.

3. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, adopts MD5 or SHA1 to calculate document.

4. multimedia electronic data forensic report generation method according to claim 1, it is characterized in that, run in displaying in multimedia evidence obtaining report, add signature authentication mechanism, display authentication signature unit, makes multimedia reports safer and more effective in transmitting procedure.

5. multimedia electronic data forensic report generation method according to claim 1, is characterized in that, the electronic data of at least one type comprises: word document, excel document, note, message registration, photo, recording, video recording.

6. the multimedia electronic data forensic report that multimedia electronic data forensic report generation method according to claim 1 generates verifies methods of exhibiting, and its step comprises:

1) computing machine and/or the mobile terminal device Bootloader that described multimedia electronic data forensic report are transferred to needs displaying decrypt document, file storage location and file symmetric cryptographic key;

2) verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown;

3) described report boot deletes temporary file automatically, completes displaying.

7. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, is characterized in that, the method verifying the electronic data evidence obtaining report be not tampered according to described document is:

Whether the document that the document relatively calculated produces when reporting with generation electronic data evidence obtaining is identical, if identical, then multimedia electronic data forensic file is complete and is not tampered; If not identical, then multimedia electronic data forensic file was tampered, and reminder-data is imperfect, needed to regain evidence obtaining report from raw data source.

8. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, it is characterized in that, described multimedia electronic data forensic report, when showing, adds signature authentication mechanism, display authentication signature unit.

9. multimedia electronic data forensic report checking methods of exhibiting according to claim 6, it is characterized in that, copied by USB flash disk and/or network transmit mode described multimedia electronic data forensic report is transferred to need show computing machine and/or mobile terminal device.

10. a multimedia electronic data forensic report, is characterized in that, comprises through asymmetric encryption: document, file storage location, compressed file symmetric cryptographic key and a boot;

Described compressed file symmetric cryptographic key is obtained by stochastic generation character string;

Described document is by being encrypted acquisition to described compressed file;

Described boot is used for after user runs this multimedia electronic data forensic report, verifies the integrality of multimedia evidence obtaining report;

Automatically this multimedia show catalogue is shown when described file storage location is for recording and preserving this multimedia electronic data forensic report.

11. 1 kinds of multimedia electronic data forensic report generate, display systems, it is characterized in that, comprising: the harvester of multimedia electronic data forensic report; Multimedia electronic data forensic report generating apparatus; Certification exhibiting device;

The harvester of described multimedia electronic data forensic report, for gathering the electronic data of at least one type from computing machine and/or mobile terminal device;

Described multimedia electronic data forensic report generating apparatus, for also setting up the preliminary electron evidence obtaining report based on file directory according to the electronic data extracting at least one type obtained; Described preliminary electron file evidence obtaining report is compressed and is merged into single compressed file and log file memory location; Using stochastic generation character string key as described compressed file symmetric cryptographic key; Then described compressed file is encrypted and calculates document; Preset rivest, shamir, adelman is used to be encrypted described document, file storage location and file symmetric cryptographic key; Encrypt rear increase by boot, generate the multimedia electronic data forensic report of single file layout;

Described certification exhibiting device, decrypts document, file storage location and file symmetric cryptographic key for the computing machine and/or mobile terminal device Bootloader described multimedia electronic data forensic report being transferred to needs displaying; Verify the electronic data evidence obtaining report be not tampered according to described document, and according to described symmetric cryptographic key, the report of this electronic data evidence obtaining is decrypted, generation result is saved in temporary file directory and evidence obtaining report is shown; Described report boot deletes temporary file automatically, completes displaying.

CN201310607114.8A 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Expired - Fee Related CN103617402B (en) Priority Applications (1) Application Number Priority Date Filing Date Title CN201310607114.8A CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Applications Claiming Priority (1) Application Number Priority Date Filing Date Title CN201310607114.8A CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Publications (2) Family ID=50168105 Family Applications (1) Application Number Title Priority Date Filing Date CN201310607114.8A Expired - Fee Related CN103617402B (en) 2013-11-25 2013-11-25 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system Country Status (1) Families Citing this family (8) * Cited by examiner, † Cited by third party Publication number Priority date Publication date Assignee Title CN105049581B (en) * 2015-03-31 2018-05-29 杭州猿人数据科技有限公司 Telephonograph evidence processing system and processing method CN105139322B (en) * 2015-07-02 2019-01-25 盘石软件(上海)有限公司 A kind of distributed electronic data evidence obtaining system and method CN105354773B (en) * 2015-10-28 2020-05-12 重庆邮电大学 System for evidence preservation and verification on traffic accident scene CN105635257A (en) * 2015-12-24 2016-06-01 福建天泉教育科技有限公司 Method and system for automatically detecting data update CN106850793A (en) * 2017-01-23 2017-06-13 重庆邮电大学 A kind of method that remote trusted towards Android phone is collected evidence CN107871063A (en) * 2017-11-16 2018-04-03 王磊 Anti-tamper video and audio recording digital signature method, device and storage medium CN114065139A (en) * 2020-08-04 2022-02-18 成都鼎桥通信技术有限公司 Multimedia file tamper-proof method and device CN118227699B (en) * 2024-03-18 2025-03-04 江苏鼎跃腾网络科技有限公司 Electronic data forensics combat training integrated equipment system Citations (4) * Cited by examiner, † Cited by third party Publication number Priority date Publication date Assignee Title CN1928842A (en) * 2005-09-07 2007-03-14 创惟科技股份有限公司 High-Secret Non-sequential Hidden Block Memory Confidential Data Protection Method for Massive Data Storage Devices CN102325139A (en) * 2011-09-14 2012-01-18 福建伊时代信息科技股份有限公司 Electronic document processing method, processing system and verification system CN102724044A (en) * 2012-07-04 2012-10-10 东方金盾科技有限公司 Electronic evidence verification and preservation method CN103400083A (en) * 2013-07-08 2013-11-20 福建伊时代信息科技股份有限公司 Method, device and system for protecting electronic evidence Patent Citations (4) * Cited by examiner, † Cited by third party Publication number Priority date Publication date Assignee Title CN1928842A (en) * 2005-09-07 2007-03-14 创惟科技股份有限公司 High-Secret Non-sequential Hidden Block Memory Confidential Data Protection Method for Massive Data Storage Devices CN102325139A (en) * 2011-09-14 2012-01-18 福建伊时代信息科技股份有限公司 Electronic document processing method, processing system and verification system CN102724044A (en) * 2012-07-04 2012-10-10 东方金盾科技有限公司 Electronic evidence verification and preservation method CN103400083A (en) * 2013-07-08 2013-11-20 福建伊时代信息科技股份有限公司 Method, device and system for protecting electronic evidence Also Published As Similar Documents Publication Publication Date Title CN103617402B (en) 2016-03-30 A kind of multimedia electronic data forensic report and generation, methods of exhibiting and system CN110798315B (en) 2021-04-13 Data processing method and device based on block chain and terminal WO2022052630A1 (en) 2022-03-17 Method and apparatus for processing multimedia information, and electronic device and storage medium US8856532B2 (en) 2014-10-07 Digital signatures of composite resource documents CN101017544B (en) 2010-12-01 Authentication method of integrated seal signature with digital certificate of electronic seal Chen et al. 2020 Study and implementation on the application of blockchain in electronic evidence generation US11394538B2 (en) 2022-07-19 System and method for verifying the no-later-than date-of-existence, data integrity, identity of the recorder, and timestamp of the recording for digital content US20040039932A1 (en) 2004-02-26 Apparatus, system and method for securing digital documents in a digital appliance CN107124281B (en) 2020-02-28 Data security method and related system TW201814566A (en) 2018-04-16 Apparatus, system, and method of preventing forgery or falsification of electronic document based on content US11449584B1 (en) 2022-09-20 Generating authenticable digital content CN110958319A (en) 2020-04-03 Method and device for managing infringement and evidence-based block chain CN111143869A (en) 2020-05-12 Application package processing method, device, electronic device and storage medium CN115952560B (en) 2024-02-06 Method, system, equipment and medium for verifying authenticity of electronic archive file based on original handwriting signature US11770260B1 (en) 2023-09-26 Determining authenticity of digital content CN106557707B (en) 2020-03-24 Method and system for processing document data CN113315745A (en) 2021-08-27 Data processing method, device, equipment and medium CN107888591B (en) 2020-02-14 Method and system for electronic data preservation CN112583772B (en) 2022-07-15 Data acquisition and storage platform CN108900472B (en) 2021-11-30 Information transmission method and device CN112954403B (en) 2023-02-17 Video encryption method, device, equipment and storage medium CN111724155A (en) 2020-09-29 Electronic contract management method and device CN115834035A (en) 2023-03-21 Multimedia data storage method, computer equipment and storage device KR20200069034A (en) 2020-06-16 Method for preventing falsification data from being stored in network and system performing the method CN101951365B (en) 2014-03-26 Network information counterfeiting issuing system, counterfeiting receiving system, and counterfeiting system and method Legal Events Date Code Title Description 2014-03-05 PB01 Publication 2014-03-05 PB01 Publication 2014-04-02 C10 Entry into substantive examination 2014-04-02 SE01 Entry into force of request for substantive examination 2016-03-30 C14 Grant of patent or utility model 2016-03-30 GR01 Patent grant 2024-11-22 CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20160330

2024-11-22 CF01 Termination of patent right due to non-payment of annual fee

RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4