CN101364984B

Method for guarantee safety of electronic file

Abstract

The electronic ensuring consistency between datum of security's method, comprising an encryption technique and a process, comprising wherein the passive insulation technology of the base of active encryption; and pulling based on the outer a control to electronic document, dynamically managing a document a policy, wherein with the value of IT investment extend to the control security of the content management system, reduced with an customers, suppliers, the partners and party concerned information sharing costs.

Term

No projected expiry on record.

  1. Priority and filed
  2. Granted
  3. Today

2 claims: 2 independent, 0 dependent

  1. 1
    The electronic ensuring consistency between datum of security's method, comprising an encryption technique and decryption method, the is composed characterised, wherein the encryption process's from DC to:First;the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format;the encryption method for selecting need, the specific selecting comprises: 1st, Wherein the need to arm the server identification authentication 2, wherein lower part of the local MAC address confirm 3, wherein the lower user fingerprint remote authenticate 4, choices permits for maximum data failure value of the secondary 5, choices need end of the compulsory wire is 5 choices the first 3 items to the three to a rectangular wherein, the back two items thereof must the option, wherein the selecting completed, the encryption conclusion of;documentAlloy, and jurisdiction distribution to the encryption document, the specific option comprises: 1st, Wherein and capable of reads 2, choices for performing the copy and cutting operation 3, choices for performing offline operation 4, choices a detects the cross screen software and forbids 5, choices for recording encryption of the operation log and uploads in the choices 5 and 3rd are flowing line, the four choices is one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption end of the process;the total EFE title enterprise is 2-3cm ileencrytion is a enterprise fileCryptographic;systemThe process's a specific current: is, First time of a network environment for encrypting file, an automatic connection server and authentication, a judging for online operation or the wire-locking operation;And the online operation, which are authentication need to obtain unit licensor is connected to, a stores the user server and password of layer of secrecy management module end of the data in advance, or an is receiver MAC address authentication server or a fingerprint than a server verifying, a verifying is;the operation jurisdiction of which the distribution password correspondingly;and document correctly;And the output of the wire-locking operation, wherein the encryption need of the wire-locking operations in the ACK/NAK flowing, and using time limiting and a limit groove encrypted information in a layer of secrecy management module, which is needed by user layers password and address chip and apparatus, verification method is a client apparatus, the user layers password and address and chip confirm the three combination rope, and flowing are the same by authorization of data;and a on the legitimate operation to the document;and document correctly;The output by the user layers and password of MAC address chip and verification the wire-locking operation based on parts;first time is a data server of user server and password, a verifying through adhesive;and following apparatus or a receiver, tilted for verifying the failure may allocate resources for according to the encryption for setting the first time allowed maximum the data failure value of the secondary method for judging is continuously is connected to confirm or executing the e post;The file encryption module in communication compulsory, wherein when the user layers password apparatus and address and apparatus for identifying chip any one of determining or combination are the data value of the secondary super-junction allows the number of times;the illegal computer is reverse to the lower or the e deletes the local file. 1. 一种保证电子文件安全的方法,包括加密过程和解密过程,其特征在于,加密过程的具体流程是:首先,文档的初始涉密人员登陆加密服务器,上传需要加密的各类文档,验证完文档格式后,选择需要的加密方式,具体的选择有:1、是否需要加入服务器身份验证2、是否需要绑定本机MAC地址进行验证3、是否需要使用者指纹进行认证4、选择最大容许验证失败次数5、选择是否需要进行强制命令以上5项选择中前3项必须三者至少选其一,后两项为必选项,选择完成后对文档的加密结束;其次,对加密文档进行权限分配,具体的选项有:1、选择是否可以打开阅读2、选择是否可以进行拷贝、剪切操作3、选择是否可以进行离线操作4、选择是否侦测截屏软件并禁用5、选择是否记录加密文件的操作日志并上传以上5项选择中第3项为必选,其余四项选择是一种或一种以上,选择完成后加密服务器会提示用户对初始文件进行上传备份,上传结束后,服务器会自动输出封装好的EFE加密文件到使用者本地计算机,整个加密过程结束,EFE的全称是enterprise f ileencrytion 即企业级文件加密系统;解密过程的具体流程是:首先,对加密文件所使用的网络环境进行检测,自动连接服务器进行认证,判断为在线操作还是离线操作;如果为在线操作,那么所有的认证都需要得到服务器的许可方可通过,对预先存入密级管理模块的用户名、密码进行验证,或者进行授权MAC地址服务器验证或指纹的比对服务器验证,如果验证通过,则分配密码所对应的操作权限,正确使用文档;如果判断为离线操作,加密文件需要离线操作的情况下,必须在密级管理模块中嵌入使用时限、使用方式限制加密信息,则也是需要通过用户名密码、MAC地址、指纹验证,其验证方法是客户端验证,用户名密码、MAC地址和指纹验证三者任意组合,并且通过验证的授权必须相同时,才能对文件进行合法操作,正确使用文档;在判断为离线操作后进行的用户名密码、MAC地址、指纹验证时,首先进行的是用户名和密码的服务器验证,如果验证通过则进行后续验证或者直接获得授权,如果首次验证失败则可以根据加密时设定的最大容许验证失败次数来判断是继续返回验证或者执行强制操作;文件加密模块中内置了强制命令,则当用户名密码验证、MAC地址验证和指纹验证任意一种验证或任意组合验证次数超过容许次数后,非法计算机将被强制关机或者强制删除本地文件。
  2. 2
    According to the electronic ensuring consistency between datum of a method of claim from 1 to the is characterised of; the user layers password apparatus and address and apparatus for identifying chip combining is made of; and square is as follows:.1, Containing failure value of the secondary heat-radiating to confirm the number of the secondary maximum together, regardless of two parts and mode, each and mode apparatus and there is not greater than the stipulation value of times;.2, And mode assigns to a shape or assigns is clamped personally, wherein assigns to multiple individuals, A obtaining user server and intervals;the B obtaining authorization chip, which is of encrypted file flowing allocated with two pair of authorizations. Additionally the stipulation value of the secondary further associate with the first a square;.3, Selecting multiple people to methods and apparatus, capable of opening the time interval the maximum server selection, the other solution or multiple people flowing of the authorization with the data. 2.根据权利要求1所说的一种保证电子文件安全的方法,其特征在于,用户名密码验证、MAC地址验证和指纹验证任意组合使用,使用规则如下:.1、最大容许失败次数的设定为共同验证次数,无论以何种验证方式,每一验证方式的验证量都不应大于规定次数;.2、验证方式分配给一个人或分配给多个人,分配给多个人时,A获得用户名和密码,B 获得指纹授权,则加密文件的打开必须同时需要两种授权,而且规定次数也应遵循第一种规则;.3、选择多人分配验证,则在服务器中可以设定最大容许间隔时间,选择要求两人或多人必须同时开启授权通过验证。