Secure printing method and system for sensitive data
Through data folding encryption and interfering data clustering technology, the possibility of sensitive data being leaked during printing in the prior art is solved, and the high security of sensitive data in transmission and printing is achieved.
Patent Information
- Application Number
- CN202510066158.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-01-16
AI Technical Summary
Existing secure printing technology cannot completely eliminate the possibility of sensitive data being leaked during printing.
The sensitive data is encrypted by data folding and encryption, and the data is secure during transmission through interfering with the data cluster and channel detection mechanism.
Effectively prevent sensitive data from being leaked during printing and transmission, ensuring the security and confidentiality of data.
Smart Images

Figure CN120045145A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of secure printing, and particularly relates to a method and system for secure printing of sensitive data. Background Art
[0002] Secure printing technology is an important means to ensure the security of sensitive data. Its core is to prevent the leakage or illegal access of sensitive data during the printing process through technical means such as encryption, watermarking, and data deletion. This technology is mainly applied in fields such as government, finance, and healthcare. By encrypting printing data, restricting access rights, deleting printing data, etc., the security and confidentiality of sensitive data are ensured. Most of the existing technologies adopt general encryption technologies. Although they can effectively reduce the risk of sensitive data leakage, they cannot completely eliminate the possibility of information leakage. The present invention proposes a new encryption method, encrypts the data through data folding, and sets interference data to ensure data security during the data printing process. Summary of the Invention
[0003] The purpose of the present invention is to provide a method and system for secure printing of sensitive data to solve the deficiencies in the background art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: A secure printing system for sensitive data, comprising: Permission authentication module: Classifies database files into sensitive files and ordinary files, classifies users accessing the database into ordinary users, secondary users, and primary users according to their permissions, and records user information, access operations, and access times when users access database files as access information; Information encryption module: Connected to the permission authentication module, when a user needs to perform a printing operation on a sensitive file, divides the sensitive file into a finite number of data clusters according to a preset data volume for encryption processing to generate encrypted data clusters, and simultaneously generates an equal amount of interference data clusters. Uses the sensitive data tag library to label the encrypted data clusters with random tags, uses the interference tag library to label the interference data clusters with interference tags, interleaves and numbers the encrypted data clusters and the interference data clusters, takes the random tags and the corresponding numbers as random tag information, takes the interference tags and the corresponding numbers as interference tag information, combines the encrypted data clusters and the interference data clusters into a file to be printed and transmits it using a dedicated channel, and packages the access information, random tag information, and interference tag information as audit information; Printing module: Connected to the information encryption module, it enables the private domain service network, obtains audit information and files to be printed, uses the sensitive data tag library to match the audit information to obtain encrypted data clusters and keys, decrypts at the printing end to obtain sensitive files, performs sensitive file printing operations, records the printing time and file information as printing information, and saves the printing information and audit information as log files in the private domain service network.
[0005] In a new embodiment, the permission authentication module includes: Classify database files into sensitive files and ordinary files, where sensitive files contain sensitive data, and classify access users into ordinary users, secondary users, and primary users; Ordinary users can only access ordinary files, secondary users can read all database files, and if they want to perform printing operations, they need a verification key provided by the primary user. Primary users can access all database files and can obtain a verification key updated regularly; When a user logs in to the database, face recognition and user information authentication are required and the user information is recorded. When accessing sensitive files, face recognition and user information authentication are required again and the user information is recorded. At the same time, the user's access operations and access times are recorded; Take the user information, access operations, and access times as access information, where the user information includes user images, identity information, phone numbers, and position information.
[0006] In a new embodiment, the information encryption module includes: When a user performs a printing operation on a sensitive file, divide the sensitive file into a finite number of data clusters according to a preset data volume for encryption processing to obtain encrypted data clusters, and at the same time generate an equal number of interference data clusters as the encrypted data clusters; Based on the sensitive data tag library, randomly tag the encrypted data clusters, and based on the interference tag database, tag the interference data clusters with interference tags; Interleave and combine the encrypted data clusters and interference data clusters and number them in sequence. The combination of the encrypted data clusters and interference data clusters is used as the file to be printed and transmitted using a dedicated transmission channel. Take the random tags and corresponding numbers as random tag information, take the interference tags and corresponding numbers as interference tag information, and take the access information, random tag information, and interference tag information as audit information.
[0007] In a new embodiment, the steps of dividing the sensitive file into a finite number of data clusters according to a preset data volume for encryption processing to obtain encrypted data clusters and at the same time generating an equal number of interference data clusters as the encrypted data clusters are: Obtain the sensitive file, count the data volume of the sensitive file, and divide the sensitive file into a finite number of data clusters according to the preset data volume; Construct a data carrier with a finite number of data folds. The data carrier is a planar carrier capable of storing data. A spatial coordinate system of the planar carrier is constructed with the center point of the planar carrier as the origin, and the coordinate axes are x, y, and z respectively; Construct a folding rule, which includes the number of folds, folding direction, folding position, folding surface, and degree of folding; Among them, the number of folds is represented by a constant, the folding direction is based on the z-axis of the spatial coordinate system, the folding position is formed by connecting the vertex coordinates of the crease, the folding surface is composed of the vertex coordinates of the folded part, and the degree of folding is used to obtain the folding angle based on the folding surface. The angle is divided into six levels with a scale of 30 degrees and represented by the letters A, B, C, D, E, and F. The later the letter, the higher the degree of folding; Store a finite number of data clusters on a finite number of data carriers respectively, randomly fold the finite number of data carriers based on the folding rule to obtain encrypted data clusters, and record the folding rule as the key; Meanwhile, generate interference data clusters equal in quantity to the encrypted data clusters; Each interference data cluster contains ordinary data with a preset data volume, and the encryption method of the interference data clusters equal in quantity is the same as that of the encrypted data clusters.
[0008] In a new embodiment, the steps of interleaving and sequentially numbering the encrypted data clusters and the interference data clusters, and using a dedicated transmission channel to transmit the combined encrypted data clusters and interference data clusters as a file to be printed are as follows: Bind the key to the interference data clusters. The interference data clusters are connected to the corresponding encrypted data clusters through a data channel based on the key, and the encrypted data clusters and the interference data clusters are sequentially numbered according to the sensitive file data order to obtain the file to be printed; Among them, a channel detection mechanism and a data self-destruction mechanism are set on the data channel. The channel detection mechanism is used to detect the channel information of the dedicated transmission channel, and the data self-destruction mechanism is used to destroy the data when the triggering condition is met; The file to be printed is transmitted through a dedicated channel. When the channel detection mechanism detects a change in the channel information, the data self-destruction mechanism is triggered to complete the destruction of the encrypted data clusters.
[0009] In a new embodiment, the printing module includes: Enable the private domain service network and receive the file to be printed and audit information; Match the audit information using the sensitive data tag library. The printing end obtains the encrypted data clusters in the file to be printed and the keys on the interference data clusters, and decrypts and combines them in ascending order of the numbers of the encrypted data clusters using the corresponding keys to obtain the sensitive file; Perform the sensitive file printing operation, record the printing time and file information as printing information, and save the printing information and audit information as a log file in the private domain server.
[0010] In a new embodiment, the private domain service network includes: The private domain service network is only used for the printing operation of sensitive files, including a database end, a printing end, and a dedicated transmission channel connecting the database end and the printing end, and is only used for transmitting files to be printed; The database end transmits the file to be printed and audit information to the printing end through a dedicated transmission channel. After the printing operation is completed, the sensitive files are deleted and only the log files are retained.
[0011] The present invention also provides a secure printing method for sensitive data, including: Classify database files into sensitive files and ordinary files, classify users accessing the database according to permissions into ordinary users, secondary users, and primary users, and record user information, access operations, and access times when users access database files as access information; When a user needs to perform a printing operation on a sensitive file, divide the sensitive file into a finite number of data clusters according to a preset data volume for encryption processing to generate encrypted data clusters. At the same time, generate an equal number of interference data clusters as the encrypted data clusters. Use the sensitive data tag library to label the encrypted data clusters with random tags, use the interference tag library to label the interference data clusters with interference tags, stagger and number the encrypted data clusters and the interference data clusters, use the random tags and the corresponding numbers as random tag information, use the interference tags and the corresponding numbers as interference tag information, combine the encrypted data clusters and the interference data clusters into a file to be printed and transmit it using a dedicated channel, and package the access information, random tag information, and interference tag information as audit information; Activate the private domain service network, obtain the audit information and the file to be printed, use the sensitive data tag library to match the audit information to obtain the encrypted data clusters and keys, the printing end decrypts to obtain the sensitive file, performs the sensitive file printing operation, records the printing time and file information as printing information, and saves the printing information and the audit information as log files in the private domain service network.
[0012] In the above technical solution, the technical effects and advantages provided by the present invention are: 1. By constructing a data folding encryption method, the present invention stores sensitive data on a flat carrier, and through multiple folding operations on the carrier, the encryption process of the sensitive data is completed. The new encryption method ensures that when the sensitive data is leaked during the printing process, the stealing party cannot perform an effective decryption method, ensuring the security of the sensitive data; 2. By constructing interference data clusters and setting a channel detection mechanism and a data destruction mechanism, the present invention ensures the problem of leakage of sensitive data during transmission. When the sensitive data is attacked and stolen by others during transmission and the transmission channel changes, the data destruction mechanism is triggered to destroy the sensitive data to prevent data leakage. Description of the Drawings
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments described in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0014] Figure 1 It is a system block diagram of the present invention; Figure 2 It is a method flow chart of the present invention. Detailed Embodiments
[0015] In order to make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, rather than all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0016] Embodiment 1. Please refer to Figure 1 As shown, a security printing system for sensitive data in this embodiment includes: Permission authentication module: Classify database files into sensitive files and ordinary files, classify users accessing the database into ordinary users, secondary users, and primary users according to their permissions, and record user information, access operations, and access times when users access database files as access information; Information encryption module: Connected to the permission authentication module. When a user needs to print a sensitive file, the sensitive file is divided into a finite number of data clusters according to a preset data volume for encryption processing to generate encrypted data clusters. At the same time, an equal amount of interference data clusters are generated. The encrypted data clusters are labeled with random labels using the sensitive data tag library, and the interference data clusters are labeled with interference labels using the interference tag library. The encrypted data clusters and interference data clusters are arranged alternately and numbered. The random labels and corresponding numbers are used as random label information, and the interference labels and corresponding numbers are used as interference label information. The encrypted data clusters and interference data clusters are combined into a file to be printed and transmitted using a dedicated channel. The access information, random label information, and interference label information are packaged as audit information; Printing module: Connected to the information encryption module, it enables the private domain service network, obtains audit information and files to be printed, matches the audit information using the sensitive data tag library to obtain encrypted data clusters and keys, decrypts at the printing end to obtain sensitive files, performs sensitive file printing operations, records the printing time and file information as printing information, and saves the printing information and audit information as log files in the private domain service network; Further explanation, secure printing technology is an important means to ensure the security of sensitive data. Its core is to prevent sensitive data from being leaked or illegally accessed during the printing process through technical means such as encryption, watermarking, and data deletion. Most existing technologies use general encryption technologies. Although they can effectively reduce the risk of sensitive data leakage, they cannot completely eliminate the possibility of information leakage. The present invention constructs a data folding encryption method to store sensitive data on a flat carrier. Through multiple folding operations on the carrier, the encryption process of sensitive data is completed. The new encryption method ensures that when sensitive data is leaked during the printing process, the thief cannot perform effective decryption methods, ensuring the security of sensitive data. At the same time, by constructing interference data clusters and setting up a channel detection mechanism and a data destruction mechanism, the problem of sensitive data leakage during transmission is ensured. When sensitive data is attacked and stolen by others during transmission and the transmission channel changes, the data destruction mechanism is triggered to destroy the sensitive data to prevent data leakage.
[0017] In one embodiment, the permission authentication module includes: Classify database files into sensitive files and ordinary files, where sensitive files contain sensitive data, and classify access users into ordinary users, secondary users, and primary users; Ordinary users can only access ordinary files. Secondary users can read all database files. If they want to perform printing operations, they need the verification key provided by the primary user. Primary users can access all database files and can obtain a verification key updated regularly; When a user logs in to the database, face recognition and user information authentication are required and the user information is recorded. When accessing sensitive files, face recognition and user information authentication are required again and the user information is recorded. At the same time, the user's access operations and access times are recorded; Take the user information, access operations, and access times as access information, where the user information includes user images, identity information, phone numbers, and position information; Further explanation, grading the access rights of users can effectively ensure the security of sensitive files. Database files are divided into sensitive files and ordinary files according to whether they contain sensitive data. At the same time, access users are divided into ordinary users, secondary users, and primary users. Different permissions are assigned to different users. Ordinary users can only access ordinary files. Secondary users can read sensitive files but cannot perform operations. If they want to perform further operations, they must obtain a verification key provided by the primary user. The primary user has the highest authority, can access and operate all files, and can obtain the verification key. The verification key is updated every day. All users need to undergo information authentication when accessing the database. The information authentication method consists of two parts: face recognition and information entry. Secondary authentication is also required when accessing sensitive files to effectively ensure the security of sensitive data.
[0018] In one embodiment, the information encryption module includes: When a user performs a printing operation on a sensitive file, the sensitive file is divided into a finite number of data clusters according to a preset data volume and encrypted to obtain encrypted data clusters. At the same time, an equal number of interference data clusters are generated; Based on the sensitive data tag library, random tags are assigned to the encrypted data clusters, and interference tags are assigned to the interference data clusters based on the interference tag database; The encrypted data clusters and the interference data clusters are interleaved and combined and numbered in sequence. The combination of the encrypted data clusters and the interference data clusters is used as the file to be printed and transmitted using a dedicated transmission channel. The random tags and the corresponding numbers are used as random tag information, the interference tags and the corresponding numbers are used as interference tag information, and the access information, random tag information, and interference tag information are used as audit information; Further explanation, when a user needs to perform a printing operation on a sensitive file, the data of the sensitive file is divided into a finite number of data clusters according to a preset quantity. Each data cluster is encrypted to obtain an encrypted data cluster. At the same time, imitating the encryption method of the encrypted data cluster, a preset quantity of random ordinary data is encrypted to obtain interference data clusters. Random tags and interference tags are assigned to the encrypted data clusters and the interference data clusters respectively. The encrypted data clusters and the interference data clusters are arranged and combined in an interleaved manner to obtain the file to be printed, and each type of data cluster is numbered in sequence. At the same time, the access information, random tag information, and interference tag information are recorded as audit information. The audit information is used for process traceback after the leakage of sensitive data to find the cause of the leakage.
[0019] In one embodiment, the step of dividing the sensitive file into a finite number of data clusters according to a preset data volume and encrypting to obtain encrypted data clusters, and at the same time generating an equal number of interference data clusters is: Obtain the sensitive file, count the data volume of the sensitive file, and divide the sensitive file into a finite number of data clusters according to the preset data volume; Construct a data carrier with a finite number of data folds. The data carrier is a planar carrier capable of storing data. A spatial coordinate system of the planar carrier is constructed with the center point of the planar carrier as the origin, and the coordinate axes are x, y, and z respectively; Construct a folding rule, which includes the number of folds, folding direction, folding position, folding surface, and degree of folding; Among them, the number of folds is represented by a constant. The folding direction is based on the z-axis of the spatial coordinate system. The folding position is formed by connecting the vertex coordinates of the creases. The folding surface is composed of the vertex coordinates of the folded part. The degree of folding is based on the folding surface to obtain the folding angle, and the angle is divided into six levels with 30 degrees as the scale, represented by the letters A, B, C, D, E, and F. The later the letter, the higher the degree of folding; Store a finite number of data clusters on a finite number of data carriers respectively. Randomly fold the finite number of data carriers based on the folding rule to obtain encrypted data clusters, and record the folding rule as the key; At the same time, generate interference data clusters equal in quantity to the encrypted data clusters; Each interference data cluster contains ordinary data of a preset data volume. The encryption method of the equal-quantity interference data clusters is the same as that of the encrypted data clusters; Furthermore, the data of the sensitive file is segmented according to the preset data volume. The preset data volume is selected according to the data volume of the sensitive file. For example, when the file data volume reaches 10,000, the preset data volume can be defined as 100. Construct a carrier for data folding. The carrier is a storage device. The data in the storage device is stored in a flat form and can realize data folding operations. Store the encrypted data clusters in the planar carrier, and perform folding processing on the planar carrier. The folding rule includes the number of folds, folding direction, folding position, folding surface, and degree of folding. The folding rule depends on the spatial coordinate system constructed for the planar carrier. The number of folds indicates how many times the carrier has been folded. The folding direction based on the z-axis of the spatial coordinate system can be represented as positive and negative. The folding position can be determined by connecting the vertices of the creases. For example, for a triangular folding surface, its crease is formed by connecting the two endpoints of the bottom line of the triangle on the x-y plane, and the folding surface is formed by connecting the three vertices of the triangle. The degree of folding is judged by the folding angle. Based on the folding surface, the folding angle is obtained. The larger the angle, the higher the degree of folding. And the degree of folding is expressed in the form of characters with 30 degrees as the scale and divided into A, B, C, D, E, and F. The folding rule generated during the process of folding the sensitive data is used as the key for subsequent decryption operations. At the same time, ordinary data is encrypted in the same way as interference data clusters.
[0020] In one embodiment, the steps of interleaving and sequentially numbering the encrypted data clusters and the interference data clusters, and using a dedicated transmission channel to transmit the combined encrypted data clusters and interference data clusters as the file to be printed are as follows: Bind the key to the interference data cluster. The interference data cluster is connected to the corresponding encrypted data cluster through a data channel based on the key, and the encrypted data cluster and the interference data cluster are numbered in sequence according to the sensitive file data order to obtain the file to be printed; A channel detection mechanism and a data self-destruction mechanism are set on the data channel. The channel detection mechanism is used to detect the channel information of the dedicated transmission channel, and the data self-destruction mechanism is used to destroy the data when the trigger condition is met; The file to be printed is transmitted through a dedicated channel. When the channel detection mechanism detects a change in the channel information, the data self-destruction mechanism is triggered to complete the destruction of the encrypted data cluster; Further explanation: Bind the key to the interference data cluster, determine the encrypted data cluster through the key, connect the encrypted data cluster and the interference data cluster through a data channel, arrange and number the encrypted data cluster and the interference data cluster in an interleaved manner according to the data order of the sensitive file, set a channel detection mechanism and a data self-destruction mechanism on the data channel. The channel detection mechanism is used to detect the channel information of the transmission channel. The channel information includes the bandwidth, frequency range, signal-to-noise ratio, routing information, and IP address of the channel. When the channel detection mechanism detects a change in the channel information, the data self-destruction mechanism is triggered to destroy the encrypted data cluster to ensure the security of sensitive data.
[0021] In one embodiment, the printing module includes: Enable the private domain service network, and receive the file to be printed and audit information; Use the sensitive data tag library to match the audit information. The printing end obtains the encrypted data cluster in the file to be printed and the key on the interference data cluster, and decrypts the combination using the corresponding key in ascending order according to the number of the encrypted data cluster to obtain the sensitive file; Perform the sensitive file printing operation, record the printing time and file information as printing information, and save the printing information and audit information as a log file in the private domain service network; Further explanation: Based on the private domain service network, match the random tag information and interference tag information in the audit file through the sensitive data tag library, obtain the key, the encrypted data cluster and its number, arrange the encrypted data clusters in sequence according to the number and perform decryption operations using the key, and perform an anti-folding operation based on the key to achieve the decryption operation to obtain the sensitive file. During the printing process, record the printing information including the printing time and file information, and save the printing information and audit information as a log file in the private domain service network for information tracing after the leakage of sensitive data.
[0022] In one embodiment, the private domain service network includes: The private domain service network is only used for the printing operation of sensitive files, including the database side, the printing side, and a dedicated transmission channel connecting the database side and the printing side, and is only used to transmit the files to be printed; The database side transmits the files to be printed and audit information to the printing side through the dedicated transmission channel, and deletes the sensitive files after the printing operation, only retaining the log files; Furthermore, the setting of the private domain service network only includes the database side, the printing side, and the dedicated transmission channel connecting the two ends. The high independence of the private domain service network ensures the security of sensitive files during transmission and printing. After the printing operation is completed, the sensitive files will be deleted and only the log files will be retained, further ensuring the security of sensitive data. And the retention of log files can facilitate the viewing of the usage dynamics of sensitive files.
[0023] A secure printing method for sensitive data includes: Classify the database files into sensitive files and ordinary files, classify the users accessing the database according to their permissions into ordinary users, secondary users, and primary users, and record the user information, access operations, and access times when the users access the database files as access information; When a user needs to print a sensitive file, divide the sensitive file into a finite number of data clusters according to a preset data volume for encryption processing to generate encrypted data clusters. At the same time, generate an equal number of interference data clusters as the encrypted data clusters. Use the sensitive data tag library to label the encrypted data clusters with random tags, use the interference tag library to label the interference data clusters with interference tags, interleave and number the encrypted data clusters and the interference data clusters, use the random tags and the corresponding numbers as random tag information, use the interference tags and the corresponding numbers as interference tag information, combine the encrypted data clusters and the interference data clusters into the file to be printed and transmit it using the dedicated channel, and package the access information, random tag information, and interference tag information as audit information; Activate the private domain service network, obtain the audit information and the file to be printed, use the sensitive data tag library to match the audit information to obtain the encrypted data clusters and the keys, the printing side decrypts to obtain the sensitive file, performs the sensitive file printing operation, records the printing time and file information as printing information, and saves the printing information and the audit information as log files in the private domain service network.
[0024] As mentioned above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art in the technical field disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.
Claims
1. A secure printing system for sensitive data, characterized in that: Permission authentication module: classifies database files into sensitive files and common files, classifies users who access the database into common users, secondary users, and primary users according to their permissions, and records user information, access operations, and access time when users access database files as access information; Information encryption module: connected to the authority authentication module. When a user needs to print a sensitive file, the sensitive file is divided into a limited number of data clusters according to a preset data volume, and encrypted to generate an encrypted data cluster. At the same time, an interference data cluster equal to the encrypted data cluster is generated. The encrypted data cluster is marked with a random label using the sensitive data label library, and the interference data cluster is marked with an interference label using the interference label library. The encrypted data cluster and the interference data cluster are alternately arranged and numbered. The random label and the corresponding number are used as random label information, and the interference label and the corresponding number are used as interference label information. The encrypted data cluster and the interference data cluster are combined into a file to be printed and transmitted using a dedicated channel. The access information, random label information, and interference label information are packaged as audit information. Printing module: connects to the information encryption module, opens the private domain service network, obtains audit information and files to be printed, uses the sensitive data tag library to match the audit information to obtain encrypted data clusters and keys, decrypts the sensitive files on the printing end, performs sensitive file printing operations, records the printing time and file information as printing information, and saves the printing information and audit information as log files in the private domain service network.
2. A secure printing system for sensitive data according to claim 1, characterized in that: The authority authentication module includes: Database files are classified into sensitive files and ordinary files, where sensitive files contain sensitive data, and access users are classified into ordinary users, secondary users, and primary users; Ordinary users can only access ordinary files, while secondary users can read all database files. To print, primary users need to provide a verification key. Primary users can access all database files and obtain a regularly updated verification key. When users log into the database, they need to perform face recognition and user information authentication and record the user information. When accessing sensitive files, they need to perform face recognition and user information authentication again and record the user information. At the same time, the user's access operation and access time are recorded; The user information, access operation and access time are taken as access information, wherein the user information includes user image, identity information, phone number and position information.
3. A secure printing system for sensitive data according to claim 1, characterized in that: The information encryption module comprises: When a user prints a sensitive document, the sensitive document is divided into a limited number of data clusters according to a preset data volume, and encrypted to obtain an encrypted data cluster, and at the same time, an interference data cluster equal in number to the encrypted data cluster is generated; Randomly label the encrypted data clusters based on the sensitive data label library, and label the interference data clusters based on the interference label database; The encrypted data clusters and the interference data clusters are interlaced and numbered in sequence. The encrypted data clusters and the interference data clusters are combined as files to be printed and transmitted using a dedicated transmission channel. The random labels and corresponding numbers are used as random label information, the interference labels and corresponding numbers are used as interference label information, and the access information, random label information and interference label information are used as audit information.
4. A secure printing system for sensitive data according to claim 3, characterized in that: The steps of dividing the sensitive file into a limited number of data clusters according to a preset data amount, performing encryption processing to obtain encrypted data clusters, and generating interference data clusters equal in number to the encrypted data clusters are: Acquire sensitive files, count the data volume of sensitive files, and divide sensitive files into a limited number of data clusters according to the preset data volume; Construct a data carrier with a finite number of data folds, the data carrier is a plane carrier capable of storing data, and construct a spatial coordinate system of the plane carrier with the center point of the plane carrier, and the coordinate axes are x, y, and z respectively; Construct folding rules, which include folding times, folding directions, folding positions, folding surfaces and folding degrees; The number of folds is represented by a constant, the folding direction is based on the z-axis of the spatial coordinate system, the folding position is connected based on the vertex coordinates of the crease, the folding surface is composed of the vertex coordinates of the folded part, the folding degree is based on the folding surface to obtain the folding angle, and the angle is divided into six levels with 30 degrees as a scale, represented by letters A, B, C, D, E, and F. The later the letter, the higher the folding degree; A finite number of data clusters are stored on a finite number of data carriers respectively, and the finite number of data carriers are randomly folded based on a folding rule to obtain an encrypted data cluster, and the folding rule is recorded as a key; Simultaneously generate interference data clusters equal to the encrypted data clusters; The interference data clusters all contain a preset amount of common data, and the encryption method of the equal amount of interference data clusters is the same as the encryption method of the encrypted data clusters.
5. A secure printing system for sensitive data according to claim 3, characterized in that: The steps of interleaving and sequentially numbering the encrypted data clusters and the interference data clusters, and using the encrypted data clusters and the interference data clusters as the file to be printed and transmitting them through a dedicated transmission channel are as follows: The key is bound to the interference data cluster, the interference data cluster is connected to the corresponding encrypted data cluster through a data channel based on the key, and the encrypted data cluster and the interference data cluster are numbered in sequence according to the sensitive file data to obtain the file to be printed; A channel detection mechanism and a data self-destruction mechanism are set on the data channel. The channel detection mechanism is used to detect the channel information of the dedicated transmission channel. The data self-destruction mechanism is used to destroy the data when a trigger condition is formed. The file to be printed is transmitted through a dedicated channel. When the channel detection mechanism finds that the channel information has changed, the data self-destruction mechanism is triggered to complete the destruction of the encrypted data cluster.
6. A secure printing system for sensitive data according to claim 1, characterized in that: The printing module comprises: Open the private domain service network to receive documents to be printed and audit information; The audit information is matched using the sensitive data tag library. The printing end obtains the encrypted data clusters and the keys on the interference data clusters in the file to be printed, and uses the corresponding keys to perform combined decryption in ascending order according to the numbers of the encrypted data clusters to obtain the sensitive files. Perform sensitive document printing operations, and record the printing time and file information as printing information. The printing information and audit information are saved as log files in the private domain server.
7. A secure printing system for sensitive data according to claim 1, characterized in that: The private domain service network includes: The private domain service network is only used for printing operations of sensitive documents, including the database end and the printing end, and the dedicated transmission channel connecting the database end and the printing end, which is only used for transmitting documents to be printed; The database end transmits the files to be printed and audit information to the printing end through a dedicated transmission channel. After the printing operation is completed, sensitive files are deleted and only log files are retained.
8. A method for securely printing sensitive data, used to implement a system for securely printing sensitive data according to any one of claims 1 to 7, characterized in that: Classify database files into sensitive files and common files, classify users who access the database into common users, secondary users and primary users according to their permissions, and record user information, access operations and access time when users access database files as access information; When a user needs to print a sensitive file, the sensitive file is divided into a limited number of data clusters according to a preset data volume, and encrypted data clusters are generated. At the same time, interference data clusters equal to the encrypted data clusters are generated, and random labels are added to the encrypted data clusters using a sensitive data label library, and interference labels are added to the interference data clusters using an interference label library. The encrypted data clusters and the interference data clusters are alternately arranged and numbered, and the random labels and corresponding numbers are used as random label information, and the interference labels and corresponding numbers are used as interference label information. The encrypted data clusters and the interference data clusters are combined into a file to be printed and transmitted using a dedicated channel, and the access information, random label information, and interference label information are packaged as audit information; Open the private domain service network, obtain audit information and files to be printed, use the sensitive data tag library to match the audit information to obtain encrypted data clusters and keys, decrypt on the printing end to obtain sensitive files, perform sensitive file printing operations, record printing time and file information as printing information, and save the printing information and audit information as log files in the private domain service network.
Citation Information
Patent Citations
Network secure printing system and printing method
CN101795271A
A rectangular image three-dimensional encryption method
CN109922224A
Printing control method and system for ensuring secure transmission of data
CN114826789A
Data transmission management method
CN117852001A
Network data secure transmission method based on trusted platform
CN118573473A
Cited By
Data processing method, system and device, equipment, storage medium and product
CN121508804A