Method for guarantee safety of electronic file
Abstract
The electronic ensuring consistency between datum of security's method, comprising an encryption technique and a process, comprising wherein the passive insulation technology of the base of active encryption; and pulling based on the outer a control to electronic document, dynamically managing a document a policy, wherein with the value of IT investment extend to the control security of the content management system, reduced with an customers, suppliers, the partners and party concerned information sharing costs.
Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
2 claims: 2 independent, 0 dependent
- 1The electronic ensuring consistency between datum of security's method, comprising an encryption technique and decryption method, the is composed characterised, wherein the encryption process's from DC to:First;the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format;the encryption method for selecting need, the specific selecting comprises: 1st, Wherein the need to arm the server identification authentication 2, wherein lower part of the local MAC address confirm 3, wherein the lower user fingerprint remote authenticate 4, choices permits for maximum data failure value of the secondary 5, choices need end of the compulsory wire is 5 choices the first 3 items to the three to a rectangular wherein, the back two items thereof must the option, wherein the selecting completed, the encryption conclusion of;documentAlloy, and jurisdiction distribution to the encryption document, the specific option comprises: 1st, Wherein and capable of reads 2, choices for performing the copy and cutting operation 3, choices for performing offline operation 4, choices a detects the cross screen software and forbids 5, choices for recording encryption of the operation log and uploads in the choices 5 and 3rd are flowing line, the four choices is one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption end of the process;the total EFE title enterprise is 2-3cm ileencrytion is a enterprise fileCryptographic;systemThe process's a specific current: is, First time of a network environment for encrypting file, an automatic connection server and authentication, a judging for online operation or the wire-locking operation;And the online operation, which are authentication need to obtain unit licensor is connected to, a stores the user server and password of layer of secrecy management module end of the data in advance, or an is receiver MAC address authentication server or a fingerprint than a server verifying, a verifying is;the operation jurisdiction of which the distribution password correspondingly;and document correctly;And the output of the wire-locking operation, wherein the encryption need of the wire-locking operations in the ACK/NAK flowing, and using time limiting and a limit groove encrypted information in a layer of secrecy management module, which is needed by user layers password and address chip and apparatus, verification method is a client apparatus, the user layers password and address and chip confirm the three combination rope, and flowing are the same by authorization of data;and a on the legitimate operation to the document;and document correctly;The output by the user layers and password of MAC address chip and verification the wire-locking operation based on parts;first time is a data server of user server and password, a verifying through adhesive;and following apparatus or a receiver, tilted for verifying the failure may allocate resources for according to the encryption for setting the first time allowed maximum the data failure value of the secondary method for judging is continuously is connected to confirm or executing the e post;The file encryption module in communication compulsory, wherein when the user layers password apparatus and address and apparatus for identifying chip any one of determining or combination are the data value of the secondary super-junction allows the number of times;the illegal computer is reverse to the lower or the e deletes the local file. 1. 一种保证电子文件安全的方法,包括加密过程和解密过程,其特征在于,加密过程的具体流程是:首先,文档的初始涉密人员登陆加密服务器,上传需要加密的各类文档,验证完文档格式后,选择需要的加密方式,具体的选择有:1、是否需要加入服务器身份验证2、是否需要绑定本机MAC地址进行验证3、是否需要使用者指纹进行认证4、选择最大容许验证失败次数5、选择是否需要进行强制命令以上5项选择中前3项必须三者至少选其一,后两项为必选项,选择完成后对文档的加密结束;其次,对加密文档进行权限分配,具体的选项有:1、选择是否可以打开阅读2、选择是否可以进行拷贝、剪切操作3、选择是否可以进行离线操作4、选择是否侦测截屏软件并禁用5、选择是否记录加密文件的操作日志并上传以上5项选择中第3项为必选,其余四项选择是一种或一种以上,选择完成后加密服务器会提示用户对初始文件进行上传备份,上传结束后,服务器会自动输出封装好的EFE加密文件到使用者本地计算机,整个加密过程结束,EFE的全称是enterprise f ileencrytion 即企业级文件加密系统;解密过程的具体流程是:首先,对加密文件所使用的网络环境进行检测,自动连接服务器进行认证,判断为在线操作还是离线操作;如果为在线操作,那么所有的认证都需要得到服务器的许可方可通过,对预先存入密级管理模块的用户名、密码进行验证,或者进行授权MAC地址服务器验证或指纹的比对服务器验证,如果验证通过,则分配密码所对应的操作权限,正确使用文档;如果判断为离线操作,加密文件需要离线操作的情况下,必须在密级管理模块中嵌入使用时限、使用方式限制加密信息,则也是需要通过用户名密码、MAC地址、指纹验证,其验证方法是客户端验证,用户名密码、MAC地址和指纹验证三者任意组合,并且通过验证的授权必须相同时,才能对文件进行合法操作,正确使用文档;在判断为离线操作后进行的用户名密码、MAC地址、指纹验证时,首先进行的是用户名和密码的服务器验证,如果验证通过则进行后续验证或者直接获得授权,如果首次验证失败则可以根据加密时设定的最大容许验证失败次数来判断是继续返回验证或者执行强制操作;文件加密模块中内置了强制命令,则当用户名密码验证、MAC地址验证和指纹验证任意一种验证或任意组合验证次数超过容许次数后,非法计算机将被强制关机或者强制删除本地文件。
- 2According to the electronic ensuring consistency between datum of a method of claim from 1 to the is characterised of; the user layers password apparatus and address and apparatus for identifying chip combining is made of; and square is as follows:.1, Containing failure value of the secondary heat-radiating to confirm the number of the secondary maximum together, regardless of two parts and mode, each and mode apparatus and there is not greater than the stipulation value of times;.2, And mode assigns to a shape or assigns is clamped personally, wherein assigns to multiple individuals, A obtaining user server and intervals;the B obtaining authorization chip, which is of encrypted file flowing allocated with two pair of authorizations. Additionally the stipulation value of the secondary further associate with the first a square;.3, Selecting multiple people to methods and apparatus, capable of opening the time interval the maximum server selection, the other solution or multiple people flowing of the authorization with the data. 2.根据权利要求1所说的一种保证电子文件安全的方法,其特征在于,用户名密码验证、MAC地址验证和指纹验证任意组合使用,使用规则如下:.1、最大容许失败次数的设定为共同验证次数,无论以何种验证方式,每一验证方式的验证量都不应大于规定次数;.2、验证方式分配给一个人或分配给多个人,分配给多个人时,A获得用户名和密码,B 获得指纹授权,则加密文件的打开必须同时需要两种授权,而且规定次数也应遵循第一种规则;.3、选择多人分配验证,则在服务器中可以设定最大容许间隔时间,选择要求两人或多人必须同时开启授权通过验证。
Independent claims2
73 paragraphs, as filed
The electronic ensuring consistency between datum of safety method
technical field
[0001] The invention relates to of an encryption and decryption process of electronic file involve, an electronic ensuring consistency between datum of a special method.
background technology
[0002] The Digital life of paperless; the electronic document's safety with the information security more and a gate component. Document prior protection scheme is connected with the data encrypting on the hard disk, saves to prevent user data from network copy to the network, namely on the mounting protection scheme client's computer, the document procedures, and data encrypt to save in a condition of user non-detection, the user, while the document are deciphered transparent, a user a watch, wherein the document with an inner frame is arranged in the copy a client on the computer, wherein the is not deciphered the program, is to watch . Moreover the solution it the control file is divided the user, divided to use of jurisdiction, i.e., are made of the user with is a normal fileAlarm, jurisdictionA lower wants the lines file service state, and flowing locking wire for monitoring and client the behaviour, a large defect in one of resources and user degrees of satisfaction.
invention content
[0003] Target of this invention is overcomes the existing the technical shortcoming, claims for ensuring consistency between datum of electronic safety method, and pulling based on the outer a control to electronic document, dynamically managing a document a policy, and considered encryption file passive protection method, wherein with the value of IT investment extend to the control security of the content management system, reduced with an customers, suppliers, the partners and party concerned information sharing costs.
[0004] The diaphragm technical solution for realizing to that:
[0005] The protection policy of the electronic file is comprising an active protection sheath and two parts passively, the protective device is a dependence encryption server the operation grading limiting to realize the document layer of secrecy module of electronic file, the passive protection is the compulsions the dependence sheet and instruction completing a pre-formed. The method comprises the encryption technique and decryption method for realizing, specifically as follows:
[0006] Encryption technique: First; the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format; the encryption method for selecting need, the specific selecting comprises:
[0007] 1st, Wherein the need to arm the server identification authentication
[0008] 2nd, Wherein lower part of the local address end of the data
[0009] 3rd, Wherein the lower user chip end of the authentication
[0010] 4th; And the containing authentication failure value of the secondary maximum
[0011] 5th, Wherein selecting lower end of the compulsory device
[0012] The is 5 choices the first 3 items flowing the three to wherein, the back two items must be one moment the option, wherein the selecting completes, the encryption conclusion of; document
[0013] Alloy, and jurisdiction distribution to the encryption document, the specific option comprises:
[0014] 1st, Wherein selecting of the reading
[0015] 2nd, Wherein and performing copy and cutting operation
[0016] 3rd, Wherein and performing the wire-locking operation
[0017] 4th, Wherein selecting detects the cross screen software and is forbid
[0018] 5th, Wherein and an encryption of the operation log and uploads
[0019] The is 5 choices the 3rd) is flowing line, the four choices is one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption end of the process; the total EFE title is enterprise file encrytion is a enterprise encryption file system.
[0020] A: processThe encryption file when the operating operation, a first with the encryption server, for determining an environment.
[0021] A using the local area network, first wherein the encryption server end of the identification authentication, according to corresponding different density composed of different an operation jurisdiction.
[0022] The stipulation the double-seal rank with low the electronic document, only by the server confirm to a method and is connected to the primary the circuit, a stipulating total density rank with high electron file, which MA°C the address in a sheet document management module in advance legitimately, a bearing is initial operation time automatic ratio operation of MAC address of computer MAC address and a stores are formed as matched, which can effectively of the encryption document's broadcast in network. MAC address authentication and authentication server are mutually independent, a plastic an independent employment, combining, a are needed to point of each of two pair of authentication method for combination, two flowing through the data, is connected to a on the operation to the encryption full file.
[0023] Increasing the recognition chip module, for encrypting of electronic file is a very good supplement, jurisdiction rank different chip is file layer of secrecy management module, when the initial operation to the document a prompt the user scanning chip efficiently obtaining state data.
[0024] The authentication server and address authentication and authentication chip is a way of active encipherment protection; the user may allocate resources for according to different layer of secrecy protection different selecting policy. For example, the double-seal rank low material of the local area network broadcast in can only use address authentication; not can only effectively preventing file of the net to disseminate and a simply, no need complexity operation, operation of customer to form a user. The double-seal rank compares A plastic De the document; multiple recognize the groove is in any two or three combination, for increasing safety rank, similar, a combined authentication along the flowing through; and jurisdiction of corresponding distribution performing operation to the encryption electronic file same.
[0025] A without using the local area network, is of with the data server, flowing therefore add the wire-locking encrypted information in a file layer of secrecy management module.
[0026] User offline layers password authentication; the authentication method using is simple, only need to fill the application of the dialog box correctly the user server and password by the encryption normally file. The wire-locking encryption method may is made of MAC address authentication and authentication chip.
[0027] The wire-locking operation with a risk connected to the online operation, transmitting the material, the third party and other situations, a protection of encrypted file is a gate, therefore with the encryption of need to the wire-locking operations in the ACK/NAK flowing, and using time limiting and using method for limiting the encrypted information in a layer of secrecy management module.
[0028] Completion using time limiting is a dependence automatic computer clock completing, is smaller than or super-junction the scheduled time in a condition, and a authentication to communicate, is of end of the operation to the invention assorted.
[0029] Use limit groove is a dependence transfer function of realizing forbid to the encryption file copy, and mobile, the operation of non-local hard disk.
[0030] Belonging to the active encryption method of each authentication manner of encrypted file, wherein the encryption machine of the illegal method is arranged, the lower passive protection policy to assure the encryption document's lower part of a specific violent work state.
[0031] When the first authentication failure using encryption file, protecting policy is started passively, according to the level of secrecy different file, allowed of the value of times of authentication failure is defined in. Usually the ACK/NAK, considers misoperation, wherein the encryption server to think is 3 times of the authentication is a legitimate. The second time authentication Zhu White at the same time, the local computer in the is connected with the encryption server, a computer address, the back user, time, the encryption filename for authenticating failure equal detailed information is capable with a server and the auditing backup, so that the number of inquiring to the operation illegal the future.
[0032] Super-junction layer of secrecy permits for failure value of the secondary operation, wherein the encryption server according thinks is a dangerous operation, according to online or the wire-locking, and difference of encrypted rank, wherein a pluggable compulsory device.
[0033] The e encryption file uploaded server is a passive protection measurement, and achieves other; the encryption document with a safety backup to exist, a uploading the encryption file, the following compulsory storing energy safety operating.
[0034] The trigger by a layer of secrecy management module; when the authentication failure value of the secondary achieves the control state, executing the e to the lower or - crush the local on the local computer of the operation of an file.
[0035] The invention claims an aims at the conversion the file and encryption and insulated, conducts the rights management to electronic tool using the document layer of secrecy management module. The main function of this invention is the passive insulation technology of the base of active encryption, the front side of the capable of the conducting rights management, a forbid to the encryption file to each operations for file, wherein effectively avoiding with the two broadcast and embezzlement of; fileAnd the back is suitable for density rank with the base, the passive insulation technology with a violent protection method for encrypting file is a illegal operation, therefore the uploaded backup function of encrypted server is one gate.
[0036] Function of this invention can is separately, only for sending encrypting function is connected to at needed the double-seal rank lower seat. Additionally the is cost, lowAnd the double-seal rank high base; the inserting passive insulation technology for increasing the protection to the file.
brief description fo the drawings
[0037] Digital 1 is the encryption current position of the invention.
[0038] Digital 2) is a current position of the invention.
Performing is specifically
[0039] A to the invention is the further detail the light of the auxiliary figure's content.
[0040] See the digital 1, wherein a encryption process's from DC to:
[0041] First; the document initial density provide the data encrypting server, the document of the uploaded need to encrypt, a confirming the file format; the encryption method for selecting need, the specific selecting comprises:
[0042] 1st, Wherein the need to arm the server identification authentication
[0043] 2nd, Wherein lower part of the local address end of the data
[0044] 3rd, Wherein the lower user chip end of the authentication
[0045] 4th; And the containing authentication failure value of the secondary maximum
[0046] 5th, Wherein selecting lower end of the compulsory device
[0047] The is 5 choices the first 3 items flowing the three to wherein, the back two items must be one moment the option, wherein the selecting completes, the encryption conclusion of; document
[0048] Alloy, and jurisdiction distribution to the encryption document, the specific option comprises:
[0049] 1st, Wherein selecting of the reading
[0050] 2nd, Wherein and performing copy and cutting operation
[0051] 3rd, Wherein and performing the wire-locking operation
[0052] 4th, Wherein selecting detects the cross screen software and is forbid
[0053] 5th, Wherein and an encryption of the operation log and uploads
[0054] The is 5 choices the 3rd) is flowing line, the four choices is one or more an, wherein the selecting completes, wherein the encryption server and promoting the user end of the uploaded backup to an initial file, wherein the uploaded with ended, the server with the output sealing the rod EFE encryption file to a user local computer, the whole encryption end of the process; the total EFE title is enterprise file encrytion is a enterprise encryption file system.
[0055] See the digital 2, wherein a decryption process's from DC to:
[0056] , First time of a network environment for encrypting file, an automatic connection server and authentication, a judging for online operation or the wire-locking operation.
[0057] And the online operation, which are authentication need to obtain unit licensor is connected to, a stores the user server and password of layer of secrecy management module end of the data in advance, or an is receiver MAC address authentication server or a fingerprint than a server verifying, a verifying is; the operation jurisdiction of which the distribution password correspondingly; and document correctly.
[0058] And the output of the wire-locking operation, which is needed by user layers password and address chip and apparatus, verification method is a client apparatus, the user layers password and address and chip confirm the three combination rope, and flowing are the same by authorization of data; and a on the legitimate operation to the document; and document correctly.
[0059] Are processed into the initial data first time is a data server of user password layers, a verifying through adhesive; and following apparatus or a receiver, tilted for verifying the failure may allocate resources for according to the encryption for setting the first time allowed maximum the data failure value of the secondary method for judging is continuously is connected to confirm or executing the e part, in usually condition, server default allowed maximum the failure value of times is 3; secondary are of through the data, filled with illegal operation computer address and work time and log uploaded servers of the insulated; Alloy and e operation to the document, wherein the type of the e units according to encryption corner of lead.
[0060] Usually the condition; the authentication of encrypted file does not only recommend for single authentication method, wherein the through the user server and chip is confirmed wherein it further comprises the following apparatus for ensuring consistency between datum of the document the safety, a second MAC address authentication or a fingerprint authentication, wherein authentication's current same on authenticated of the first time, relied on the encryption initial lead.
[0061] Combining is on the back of the cover of household password apparatus and address and apparatus for identifying chip are; and square is as follows:
[0062] 1st, Containing failure value of the secondary heat-radiating to confirm the number of the secondary maximum together, regardless of two parts and mode, each and mode apparatus and there is not greater than the stipulation value of times;
[0063] 2nd, Verification method of methods to a are separately, ration multiple personally, a: of
[0064] A obtaining user server and intervals; the B obtaining authorization chip, which is of encrypted file flowing the simultaneous two pair of authorizations. Additionally the stipulation value of the secondary further associate with the first a square;
[0065] 3rd, And selecting multiple people to methods and apparatus, capable of opening the time interval the maximum server, and other solution or multiple people flowing of the authorization single wires with the data.
[0066] And a file encryption module in communication compulsory, wherein when the user layers password apparatus and address and apparatus for identifying chip any one of determining or combination are the data value of the secondary super-junction allows the number of times; the illegal computer is reverse to the lower or the e deletes the local file. A density rank very high material, and maintain the document are stolen, can avoid the illegal user connecting a code breaking by the method of exhaustion, the document is not only opened, wherein a pluggable non-reversible smashing operation, document's safety distribution problem that effectively solves the network.
7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| TWI614633B | Cited by | Taiwan Province of China | Examiner |
| CN104850801A | Cited by | China | Search report |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200810150624 | China | A | |
| CN20081150624 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| CN101364984A | China | A | |
| CN101364984BThis record | China | B |
Numbers
- Publication
- 101364984
- Publication, DOCDB
- 101364984
- Publication, EPODOC
- CN101364984B
- Application
- 101506246
- Application, DOCDB
- 200810150624
- Application, EPODOC
- CN20081150624
Titles2
- English
- Method for guarantee safety of electronic file
- Chinese
- 一种保证电子文件安全的方法
Classification
- IPC, 4
- H04L29 06
- G06F21 32
- H04L9 32
- G06F21 00