Method for guarantee safety of electronic file
Abstract
The electronic ensuring consistency between datum of security's method, comprising an encryption technique and a process, comprising wherein the passive insulation technology of the base of active encryption; and pulling based on the outer a control to electronic document, dynamically managing a document a policy, wherein with the value of IT investment extend to the control security of the content management system, reduced with an customers, suppliers, the partners and party concerned information sharing costs.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
3 claims: 1 independent, 2 dependent
- 1The electronic ensuring consistency between datum of security's method, comprising an encryption technique and decryption method, the is composed characterised, wherein the encryption process's from DC to:First;the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format;the encryption method for selecting need, the specific selecting comprises: 1st, Wherein the need to arm the server identification authentication 2, wherein lower part of the local MAC address confirm 3, wherein the lower user fingerprint remote authenticate 4, choices permits a layer of determining failure value of the secondary 5, choices need end of the compulsory used for selecting be one or more;a Alloy, and jurisdiction distribution to the encryption document, the specific option comprises: 1st, Wherein and capable of reads 2, choices for performing the copy and cutting operation 3, choices for performing offline operation 4, choices wherein the detects the screen software and forbids 5, choices for recording encryption of the operation log and uploads for selecting be one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption technique, ended The process's a specific current: is, First time of a network environment for encrypting file, an automatic connection server and authentication, a judging for online operation or the wire-locking operation. And the online operation, which are authentication circuit is the lower grant of server is, a stores the user server and password of layer of secrecy management module end of the data in advance, or an is receiver MAC address authentication server or a fingerprint than a server verifying, a verifying is;the operation jurisdiction of which the distribution password correspondingly;and document correctly. And the output of the wire-locking operation, which is needed by user layers password and address chip and apparatus, verification method is a client verifying short, combinable rope, and flowing are the same by authorization of data;and a on the legitimate operation to the document;and document correctly. 1、一种保证电子文件安全的方法,包括加密过程和解密过程,其特征在于, 加密过程的具体流程是: 首先,文档的初始涉密人员登陆加密服务器,上传需要加密的各类文档,验证完文档格式后,选择需要的加密方式,具体的选择有: 1、是否需要加入服务器身份验证 2、是否需要绑定本机MAC地址进行验证 3、是否需要使用者指纹进行认证 4、选择最大容许验证失败次数 5、选择是否需要进行强制命令 选择可以是一种或一种以上; 其次,对加密文档进行权限分配,具体的选项有: 1、 选择是否可以打开阅读 2、 选择是否可以进行拷贝、剪切操作 3、 选择是否可以进行离线操作 4、 选择是否侦测截屏软件并禁用 5、 选择是否记录加密文件的操作日志并上传 选择可以是一种或一种以上,选择完成后加密服务器会提示用户对初始文件进行上传备份,上传结束后,服务器会自动输出封装好的EFE加密文件到使用者本地计算机,整个加密过程结束; 解密过程的具体流程是: 首先,对加密文件所使用的网络环境进行检测,自动连接服务器进行认证,判断为在线操作还是离线操作。 如果为在线操作,那么所有的认证都需要得到服务器的许可方可通过,对预先存入密级管理模块的用户名、密码进行验证,或者进行授权MAC地址服务器验证或指纹的比对服务器验证,如果验证通过,则分配密码所对应的操作权限,正确使用文档。 如果判断为离线操作,则也是需要通过用户名密码、MAC地址、指纹验证,其验证方法是客户短验证,可以任意组合,并且通过验证的授权必须相同时,才能对文件进行合法操作,正确使用文档。
34 paragraphs, as filed
The electronic ensuring consistency between datum of safety method
technical field
The invention relates to of an encryption and decryption process of electronic file involve, an electronic ensuring consistency between datum of a special method. The background technique in Digital life of paperless; the electronic document's safety with the information security more and a gate component. Document prior protection scheme is connected with the data encrypting on the hard disk, saves to prevent user data from network copy to the network, namely on the mounting protection scheme client's computer, the document procedures, and data encrypt to save in a condition of user non-detection, the user, while the document are deciphered transparent, a user a watch, wherein the document with an inner frame is arranged in the copy a client on the computer, wherein the is not deciphered the program, is to watch . Moreover the solution it the control file is divided the user, divided to use of jurisdiction, i.e., are made of the user with is a normal fileAlarm, jurisdictionA lower wants the lines file service state, and flowing locking wire for monitoring and client the behaviour, a large defect in one of resources and user degrees of satisfaction. The target for content present invention is overcomes the existing the technical shortcoming, claims for ensuring consistency between datum of electronic safety method, and pulling based on the outer a control to electronic document, dynamically managing a document a policy, and considered encryption file passive protection method, wherein with the value of IT investment extend to the control security of the content management system, reduced with an customers, suppliers, the partners and party concerned information sharing costs.
The diaphragm technical solution for realizing to that: The protection policy of the electronic file is comprising an active protection sheath and two parts passively, the protective device is a dependence encryption server the operation grading limiting to realize the document layer of secrecy module of electronic file, the passive protection is the compulsions the dependence sheet and instruction completing a pre-formed. The method comprises the encryption technique and decryption method for realizing, specifically as follows: Encryption technique: First; the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format; the encryption method for selecting need, the specific selecting comprises: 1st, Wherein the need to arm the server identification authentication 2, wherein lower part of the local MAC address confirm 3, wherein the lower user fingerprint remote authenticate 4, choices permits a layer of determining failure value of the secondary 5, choices need end of the compulsory used for selecting be one or more an, wherein the selecting completes, the encryption conclusion of document. Alloy, and jurisdiction distribution to the encryption document, the specific option Has-one, and capable of reads 2, choices for performing the copy and cutting operation 3, choices for performing offline operation 4, choices wherein the detects the screen software and forbids 5, choices for recording encryption of the operation log and uploads for selecting be one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output package
The EFE encryption file to user local computer, the encryption technique ended.
A: processThe encryption file when the operating operation, a first with the encryption server, for determining an environment.
A using the local area network, first wherein the encryption server end of the identification authentication, according to corresponding different density composed of different an operation jurisdiction.
The stipulation the double-seal rank with low the electronic document, only by the server confirm to a method and is connected to the primary the circuit, a stipulating total density rank with high electron file, which the legitimate address in a sheet document management module for pre-twisted patching bar, the connecting on initial operation time automatic ratio operation of MAC address of computer MAC address and a stores are formed as matched, which can effectively of the encryption document's broadcast in network. MAC address authentication and authentication server are mutually independent, a plastic an independent employment, combining, a are needed to point of each of two pair of authentication method for combination, two flowing through the data, is connected to a on the operation to the encryption full file.
Increasing the recognition chip module, for encrypting of electronic file is a very good supplement, jurisdiction rank different chip is file layer of secrecy management module, when the initial operation to the document a prompt the user scanning chip efficiently obtaining state data.
The authentication server and address authentication and authentication chip is a way of active encipherment protection; the user may allocate resources for according to different layer of secrecy protection different selecting policy. For example, the double-seal rank low material of the local area network broadcast in can only use address authentication; not can only effectively preventing file of the net to disseminate and a simply, no need complexity operation, operation of customer to form a user. The double-seal rank compares A plastic De the document; multiple recognize the groove is in any two or three combination, for increasing safety rank, similar,
The combined authentication in the flowing through; and jurisdiction of corresponding distribution performing operation to the encryption electronic file same.
A without using the local area network, is of with the data server, flowing therefore add the wire-locking encrypted information in a file layer of secrecy management module.
User offline layers password authentication; the authentication method using is simple, only need to fill the application of the dialog box correctly the user server and password by the encryption normally file. The wire-locking encryption method may is made of MAC address authentication and authentication chip.
The wire-locking operation with a risk connected to the online operation, transmitting the material, the third party and other situations, a protection of encrypted file is a gate, therefore with the encryption of need to the wire-locking operations in the ACK/NAK flowing, and using time limiting and using method for limiting the encrypted information in a layer of secrecy management module.
Completion using time limiting is a dependence automatic computer clock completing, is smaller than or super-junction the scheduled time in a condition, and a authentication to communicate, is of end of the operation to the file.
Use limit groove is a dependence transfer function of realizing forbid to the encryption file copy, and mobile, the operation of non-local hard disk.
Belonging to the active encryption method of each authentication manner of encrypted file, wherein the encryption file is attempted the illegal operation need, the passive protection policy to assure the encryption document's lower part of a specific violent work state.
When the first authentication failure using encryption file, protecting policy is started passively, according to the level of secrecy different file, allowed of the value of times of authentication failure is defined in. Usually the ACK/NAK, considers misoperation, wherein the encryption server to think is 3 times of the authentication is a legitimate. The second authentication failure at the same time, the local computer arranged in the connection with the encryption method, server
Computer address, user server, time, encryption filename for authenticating failure equal detailed information in capable of automatically to the server and the auditing backup, so that the number of using corresponding to the operation illegal the future 査 inquires.
Super-junction layer of secrecy permits for failure value of the secondary operation, wherein the encryption server according thinks is a dangerous operation, according to online or the wire-locking, and difference of encrypted rank, wherein a pluggable compulsory device.
The e encryption file uploaded server is a passive protection measurement, and achieves other; the encryption document with a safety backup to exist, a uploading the encryption file, the following compulsory storing energy safety operating.
The trigger by a layer of secrecy management module; when the authentication failure value of the secondary achieves the control state, executing the e to the lower or - crush the local on the local computer of the operation of an file.
The invention claims an aims at the conversion the file and encryption and insulated, conducts the rights management to electronic tool using the document layer of secrecy management module. The main function of this invention is the passive insulation technology of the base of active encryption, the front side of the capable of the conducting rights management, a forbid to the encryption file to each operations for file, wherein effectively avoiding with the two broadcast and embezzlement of; file And the back is suitable for density rank with the base, the passive insulation technology with a violent protection method for encrypting file is a illegal operation, therefore the uploaded backup function of encrypted server is one gate.
Function of this invention can is separately, only for sending encrypting function is connected to at needed the double-seal rank lower seat. Additionally the cost is; aAnd the double-seal rank high base; the inserting passive insulation technology for increasing the protection to the file.
Brief description for drawings
Digital 1 is the encryption current position of the invention. Digital 2) is a current position of the invention. The detailed description of illustrated embodiments following to the invention is the further detail the light of the auxiliary figure's content. See the digital 1, wherein a encryption process's from DC to: First; the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format; the encryption method for selecting need, the specific selecting comprises: 6th, Wherein the need to arm the server identification authentication 7, wherein lower part of the local MAC address confirm 8, wherein the lower user fingerprint remote authenticate 9, choices permits a layer of determining failure value of the secondary 10, choices need end of the compulsory used for selecting be one or more an, wherein the selecting completes, the encryption conclusion of document. Alloy, and jurisdiction distribution to the encryption document, the specific option comprises: 6th, Wherein and capable of reads 7, choices for performing the copy and cutting operation 8, choices for performing offline operation 9, choices wherein the detects the screen software and forbids 10, choices for recording encryption of the operation log and uploads for selecting be one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption technique ended.
See the digital 2, wherein a decryption process's from DC to: , First time of a network environment for encrypting file, an automatic connection server and authentication, a judging for online operation or the wire-locking operation.
And the online operation, which are authentication need to obtain unit licensor is connected to, a stores the user server and password of layer of secrecy management module end of the data in advance, or an is receiver MAC address authentication server or a fingerprint than a server verifying, a verifying is; the operation jurisdiction of which the distribution password correspondingly; and document correctly.
And the output of the wire-locking operation, which is needed by user layers password and address chip and apparatus, verification method is a client verifying short, combinable rope, and flowing are the same by authorization of data; and a on the legitimate operation to the document; and document correctly.
Are processed into the initial data first time is a data server of user password layers, a verifying through adhesive; and following apparatus or a receiver, tilted for verifying the failure may allocate resources for according to the encryption for setting the first time allowed layer of the data failure value of the secondary method for judging is continuously is connected to confirm or executing the e part, in usually condition, server default allowed layer of the failure value of times is 3; a secondary through of the apparatus, filled with illegal operation computer address and work time and log uploaded servers of the insulated; Alloy and e operation to the document, the type of the e units according to encryption corner of lead.
Usually the condition; the authentication of encrypted file does not only recommend for single authentication method, wherein the through the user server and confirmed chip according to the further comprises the following apparatus for ensuring consistency between datum of the document the safety, a second MAC address authentication or a fingerprint authentication, wherein authentication's current same on authenticated of the first time, relied on the encryption initial lead.
User layers password apparatus and address and apparatus for identifying chip combining is made of; and square is as follows: 1st, Containing failure value of the secondary heat-radiating to confirm the number of the secondary layer of each, regardless of two parts for checking; each and mode apparatus and is not greater than the stipulation value of times;
2nd, Verification method of methods to a are separately, ration multiple personally, a: of A obtaining user server and password, AND obtaining authorization chip, which is of encrypted file of claim or two pair of authorizations. Additionally the stipulation value of the secondary further associate with the first a square; 3rd, And selecting multiple to people methods and apparatus, capable of opening the time interval the server of layer, and other solution or multiple people flowing of the authorization single wires with the data.
And a file encryption module in communication compulsory, wherein when the user layers password apparatus and address and apparatus for identifying chip any one of determining or combination are the data value of the secondary super-junction allows the number of times; the illegal computer is reverse to the lower or the e deletes the local file. A density rank very high material, and maintain the document are stolen, can avoid the illegal user connecting a code breaking by the method of exhaustion, the document is not only opened, wherein a pluggable non-reversible smashing operation, document's safety distribution problem that effectively solves the network.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN102520223A | Cited by | China | Search report |
| WO2013013581A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN101957899A | Cited by | China | Search report |
| CN105743857A | Cited by | China | Search report |
| CN107070864A | Cited by | China | Search report |
| CN104580062A | Cited by | China | Search report |
| CN102393938A | Cited by | China | Search report |
| CN106789836A | Cited by | China | Search report |
| CN111277413A | Cited by | China | Search report |
| WO2017120939A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN105635047A | Cited by | China | Search report |
| CN102347836A | Cited by | China | Search report |
| CN108664797A | Cited by | China | Search report |
| US9027154B2 | Cited by | United States of America | Applicant |
| CN106446710A | Cited by | China | Search report |
| CN101848103A | Cited by | China | Search report |
| CN102693392A | Cited by | China | Search report |
| WO2017120938A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN108985107A | Cited by | China | Search report |
| CN104598787A | Cited by | China | Search report |
| CN102651737A | Cited by | China | Search report |
| CN103399751A | Cited by | China | Search report |
| CN101989321A | Cited by | China | Search report |
| US9705759B2 | Cited by | United States of America | Applicant |
| CN104318172A | Cited by | China | Search report |
| CN102236607A | Cited by | China | Search report |
| US10447560B2 | Cited by | United States of America | Applicant |
| CN106603505A | Cited by | China | Search report |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200810150624 | China | A | |
| CN20081150624 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| CN101364984AThis record | China | A | |
| CN101364984B | China | B |
Numbers
- Publication
- 101364984
- Publication, DOCDB
- 101364984
- Publication, EPODOC
- CN101364984
- Application
- 101506246
- Application, DOCDB
- 200810150624
- Application, EPODOC
- CN20081150624
Titles2
- English
- Method for guarantee safety of electronic file
- Chinese
- 一种保证电子文件安全的方法
Classification
- IPC, 4
- H04L29 06
- G06F21 32
- H04L9 32
- G06F21 00