A multi-end authorized file management method, system and medium

The file management method using a multi-terminal authorization mechanism solves the problems of unclear user and file compatibility caused by hardware binding, and realizes flexible file management and efficient and secure transmission, which is suitable for surveying and mapping data processing scenarios.

CN122263148APending Publication Date: 2026-06-23SHENZHEN OLYM INFORMATION SECURITY TECHOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN OLYM INFORMATION SECURITY TECHOLOGY CO LTD
Filing Date
2026-03-09
Publication Date
2026-06-23

Smart Images

  • Figure CN122263148A_ABST
    Figure CN122263148A_ABST
Patent Text Reader

Abstract

The application provides a multi-end authorization file management method, system and medium, and relates to the field of file encryption, which comprises the following steps: a service end and at least one use end perform software authorization and / or hardware authorization at a manufacturer; the service end encrypts a file to obtain an encrypted file and sends the encrypted file to the at least one use end; the use end receiving the encrypted file decrypts the encrypted file in any authorization corresponding manner to obtain a decrypted file; and the use end receiving the encrypted file processes the decrypted file by using software corresponding to the decrypted software type. In this way, through the multi-end authorization mechanism, the service end can manage the file access rights of different use ends and ensure the security of the file in the transmission and storage process. Meanwhile, after receiving the encrypted file, the use end performs identity authentication through software authorization or hardware authorization, and can decrypt the file after the authentication, thereby improving the convenience of file management and effectively preventing file leakage and illegal access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of file encryption technology, and more specifically, to a file management method, system, and medium that can be authorized across multiple terminals. Background Technology

[0002] In the technical application scenarios of surveying and mapping data processing, the security and efficiency of data management are core requirements. Currently, the mainstream management mechanism widely adopted in the industry is the binding of authorization documents with hardware. However, this mechanism has many core pain points. Not only does the strong binding of authorization and hardware make it difficult to identify the actual user, making it difficult to accurately trace the responsible party in the event of data security issues, but it also severely restricts the flexibility of surveying and mapping production activities, making it impossible to add computer equipment for data processing in a timely manner according to project progress needs. At the same time, this mechanism also presents the challenge of adapting documents used by multiple units, further restricting the improvement of production efficiency and hindering the collaborative advancement of surveying and mapping production.

[0003] Existing solutions to address the aforementioned pain points have significant flaws and are cumbersome. Currently, there are two main approaches to handling the use of documents from multiple organizations: one is to avoid the inability to use documents from multiple organizations simultaneously, requiring frequent switching of authorizations to access data files from different organizations; the other is to negotiate with other authorized organizations to unify the authorization of all documents under one organization before use. These two solutions not only further exacerbate the limitations on the flexibility of production activities but also consume significant time due to cumbersome procedures, leading to a substantial decrease in surveying and mapping production efficiency. Furthermore, existing solutions fail to address the core issues of unclear user identification and inconvenience in adding or removing equipment, thus failing to fundamentally meet the actual needs of efficient and collaborative surveying and mapping production. Summary of the Invention

[0004] To address the above problems, this invention proposes a file management method, system, and medium with multi-terminal authorization. In a first aspect, embodiments of this invention provide a file management authorization method with multi-terminal authorization, the method comprising:

[0005] The server and at least one user terminal are granted software and / or hardware licenses by the manufacturer. The software license is granted by the manufacturer by issuing an authorization file to the server or user terminal offline, or by issuing a verification code to the server or user terminal online. The hardware license is granted by the manufacturer by issuing a USB flash drive key to the server or user terminal.

[0006] The server encrypts the file to obtain an encrypted file, and sends the encrypted file to at least one user terminal. The encrypted file includes decryption software type.

[0007] The receiving end decrypts the encrypted file using any authorized method to obtain the decrypted file;

[0008] The receiving end processes the encrypted file using the software corresponding to the decryption software type.

[0009] As one possible implementation, the server obtains software licensing from the vendor, including:

[0010] The server submits an authorization request to the manufacturer. The authorization request includes organization information and order information. The organization information includes the full name of the organization to which the server belongs, communication information, contact person and / or device code. The order information includes the number of authorizations, the validity period of the authorization and / or the type of authorization file.

[0011] Based on the authorization application, the manufacturer generates an authorization file containing the authorization policy and distributes it to the server offline. The authorization policy includes the authorization validity period, the total number of authorized clients, and / or the type of authorization file.

[0012] The server imports the license file to complete the software license.

[0013] As one possible implementation, the user end includes PC clients and mobile clients, and the user end is licensed by the vendor, including:

[0014] The mobile client scans the manufacturer's registration QR code and enters an authorization request to send the authorization request to the manufacturer. The authorization request includes communication information, the full name of the affiliated unit and / or the contact person.

[0015] The manufacturer generates a verification code based on the authorization application and sends the verification code to the mobile client corresponding to the communication information;

[0016] The PC client or mobile client sends the verification code to the manufacturer to complete the software authorization.

[0017] As one possible implementation, the server and multiple user terminals are licensed hardware by the vendor, including:

[0018] The server submits an authorization request to the manufacturer. The authorization request includes organization information and order information. The organization information includes the full name of the organization to which the server belongs, communication information, contact person and / or device code. The order information includes the number of authorizations, the validity period of the authorization and / or the type of authorization file.

[0019] Based on the authorization application, the manufacturer burns the authorization information into the server-side USB flash drive key and delivers the server-side USB flash drive key and the number of user-side USB flash drive keys corresponding to the authorization application to the server.

[0020] The server inserts the server USB flash drive key to complete hardware authorization;

[0021] The server configures the authorization information corresponding to the user device code in the user's USB flash drive key, and delivers the user's USB flash drive key to the user corresponding to the device code;

[0022] The user inserts the USB flash drive key to complete hardware authorization.

[0023] As one possible implementation, the server sends the encrypted file to at least one user, including:

[0024] The server packages the encrypted file, the decryption software installation package, and / or uses the white paper, and distributes them to at least one user terminal offline.

[0025] Alternatively, the user's mobile client can scan the authorization QR code provided by the server, and the server will synchronize the encrypted file to the user's PC client.

[0026] As one possible implementation, the terminal receiving the encrypted file decrypts the encrypted file using any authorized method to obtain a decrypted file, including:

[0027] The mobile client corresponding to the user terminal that receives the encrypted file scans the device code and / or authorization QR code displayed on the PC client in order to send the device code and / or authorization QR code to the manufacturer;

[0028] The mobile client corresponding to the terminal that receives the encrypted file receives a Chinese character activation code.

[0029] Upon receiving the encrypted file, the user enters the Chinese activation code on the PC client to decrypt the encrypted file and obtain the decrypted file.

[0030] As one possible implementation, the method further includes:

[0031] The server performs a decryption operation on the encrypted file to obtain the plaintext file corresponding to the encrypted file.

[0032] Secondly, embodiments of the present invention provide a file management system with multi-terminal authorization, comprising: a vendor, a server, and at least one user terminal;

[0033] The manufacturer is used to grant software and / or hardware licenses to the server and at least one user terminal. The software license is granted by the manufacturer sending an authorization file to the server or user terminal offline, or by the manufacturer sending a verification code to the server or user terminal online. The hardware license is granted by the manufacturer sending a USB flash drive key to the server or user terminal.

[0034] The server is used to encrypt the file, obtain the encrypted file, and send the encrypted file to at least one user terminal. The encrypted file includes decryption software type.

[0035] The user terminal is used to decrypt the encrypted file using any authorized method to obtain a decrypted file; and to process the decrypted file using software corresponding to the decryption software type.

[0036] As one possible implementation, the user terminal includes mobile clients and PC clients;

[0037] The mobile client is used to scan the manufacturer's registration QR code, input an authorization request, and send the authorization request to the manufacturer. The authorization request includes communication information, the full name of the affiliated unit, and / or the contact person. It also sends a verification code to the manufacturer to complete the software authorization. Furthermore, it scans the device code and / or authorization QR code displayed on the PC client to send the device code and / or authorization QR code to the manufacturer. Finally, it receives a Chinese character activation code.

[0038] The PC client is used to send the verification code to the manufacturer to complete the software authorization; input the Chinese activation code to decrypt the encrypted file and obtain the decrypted file.

[0039] Thirdly, embodiments of the present invention provide a readable storage medium having executable instructions stored thereon, wherein the executable instructions, when executed by a processor, implement the method described in the first aspect.

[0040] The embodiments of the present invention provide a file management authorization method, system, and medium with multi-terminal authorization capability. The method includes: a server and at least one user terminal performing software and / or hardware authorization with a manufacturer, wherein the software authorization is performed by the manufacturer issuing an authorization file to the server or user terminal offline, or by the manufacturer issuing a verification code to the server or user terminal online; the hardware authorization is performed by the manufacturer issuing a USB flash drive key to the server or user terminal; the server encrypts the file to obtain an encrypted file, and sends the encrypted file to at least one user terminal, wherein the encrypted file includes a decryption software type; the user terminal receiving the encrypted file decrypts the encrypted file using any authorization-corresponding method to obtain a decrypted file; the user terminal receiving the encrypted file processes the decrypted file using software corresponding to the decryption software type.

[0041] In this way, through a multi-terminal authorization mechanism, the server can flexibly manage file access permissions for different users, ensuring file security during transmission and storage. Simultaneously, upon receiving an encrypted file, the user must authenticate themselves through valid software or hardware authorization before decrypting the file. This design not only improves the convenience of file management but also significantly enhances file security, effectively preventing the risks of file leakage and unauthorized access. Attached Figure Description

[0042] Figure 1 This is an exemplary system architecture diagram of an embodiment of the present invention that can be applied to a file management method with multi-terminal authorization;

[0043] Figure 2 This is a flowchart of a file management method with multi-terminal authorization provided in an embodiment of the present invention;

[0044] Figure 3 This is a schematic diagram of the structure of a computer suitable for implementing embodiments of the present disclosure. Detailed Implementation

[0045] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0046] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0047] Figure 1 An exemplary architecture 100 is shown, in which embodiments of the multi-terminal licensable file management method, system, and media of the present invention can be applied.

[0048] like Figure 1 As shown, architecture 100 may include vendor 101, server 102, and user 103. Vendor 101 can configure server USB key 104 and user USB key 105. Server 102 can configure server device, authorization file (.auth), and authorization QR code. User 103 refers to PC client unless otherwise specified, and it is accompanied by mobile client 106, which can be configured with log black box.

[0049] Network 107 is a medium for providing a communication link between vendor 101, server 102, and user 103. Vendor 101 can also provide an independent burning link (valid for 30 minutes, 60 minutes, or 24 hours) for USB flash drive key renewal.

[0050] Manufacturer 101, server 102, and user 103 are terminal devices or functional entities, on which various communication client applications, file encryption / decryption applications, authorization management applications, log analysis applications, etc., can be installed. Network 107 can include various connection types, such as wired and wireless communication links or fiber optic cables, etc.

[0051] The server-side USB key 104 and the user-side USB key 105 are USB keys (USBKEY, U-Key). The server-side USB key 104 is connected to the server 102, and the user-side USB key 105 is connected to the PC client device 111. The authorization file and authorization QR code are generated by the server 102 and used for activation authorization on the user 103. The mobile client 106 and the PC client device transmit the activation code through QR code scanning interaction.

[0052] Manufacturer 101, server 102, and user 103 can be either hardware or software. When they are hardware, they can be various electronic devices with data processing and communication functions, including but not limited to servers, desktop computers, laptops, smartphones, and smart terminals. When they are software, they can be installed in the aforementioned terminal devices and can be implemented as multiple software programs or software modules (such as authorization management modules, encryption / decryption modules, log analysis modules, etc.) or as a single software program or software module; no specific limitations are made here.

[0053] In some cases, the file authorization, encryption / decryption, and user-end methods provided by this invention can be executed independently by the vendor 101, the server 102, and the user 103.

[0054] In some cases, the method provided by this invention can be executed jointly by the aforementioned entities. For example, the step of "the server submitting an authorization request to the manufacturer" is executed by server 102, the step of "the manufacturer generating an authorization file or USB flash drive key and distributing it" is executed by manufacturer 101, and the step of "the user activating the PC client through the mobile client" is executed by the mobile client 106 of user 103 and the PC client device in cooperation. This invention does not limit this.

[0055] It should be understood that Figure 1 The vendor 101, server 102, user 103, their sub-roles, and the number of various devices are merely illustrative. Depending on implementation needs, any number of these entities and devices can be included.

[0056] See below. Figure 2 , Figure 2 A flowchart 200 of a multi-terminal authorized file management method provided in an embodiment of the present invention is shown, including:

[0057] Step 201: The server and at least one user end obtain software and / or hardware licenses from the vendor.

[0058] The manufacturer is the core of the authorization management, responsible for generating authorization files, managing UKey keys, and building a key distribution and verification system.

[0059] Server-side: The entity that generates the original file and performs encryption operations. It needs to configure the server-side device and the corresponding device code, and use the file distribution server version software. The authorization process requires submitting an application to the manufacturer and completing activation and binding.

[0060] User terminals, including PC client terminals and mini-program terminals, need to obtain authorization (software authorization) through PC client devices or mobile clients, or complete activation through UKey hardware (hardware authorization). Step 201 establishes the basic permission system for subsequent file encryption, distribution, and use, clarifying the authorization scope and usage qualifications of each role.

[0061] Authorization is divided into software authorization and hardware authorization. Software authorization involves the manufacturer issuing an authorization file to the server or user offline, or issuing a verification code online. Hardware authorization involves the manufacturer issuing a USB key to the server or user. Software authorization has two modes: offline file and mini-program. Hardware authorization has one mode: UKey, covering needs such as standalone operation, hardware binding, and online management.

[0062] Method 1: Offline file authorization (single machine within the same organization)

[0063] Step 201-1-1: The server submits an authorization application to the manufacturer (including organization information: full name of the server's organization, contact information, contact person and / or device code; order information: authorization order number, authorization quantity, authorization validity period and / or authorization file type).

[0064] Step 201-1-2: Based on the authorization application, the vendor generates an authorization file (.auth) containing the authorization policy (authorization validity period, total number of authorized clients and / or authorization file type), and distributes it to the server offline.

[0065] Step 201-1-3: Import the license file on the server to complete the software license.

[0066] In this case, if expansion is needed (the server submits the unit name + device code + new quantity, and the manufacturer generates a new license file for import) or offline license renewal (the server submits a renewal application including renewal information, and the manufacturer generates a renewal file after manual verification).

[0067] Method 2: UKey Authorization (Standalone / Hardware Binding)

[0068] Step 201-2-1: The server submits an authorization request to the manufacturer (same as above, including company information and order information).

[0069] Step 201-2-2: Based on the authorization application, the manufacturer burns the authorization information into the server-side USB flash drive key and delivers the server-side USB flash drive key and the number of user-side USB flash drive keys corresponding to the authorization application to the server.

[0070] Step 201-2-3: Insert the server USB key into the server to complete hardware authorization.

[0071] Step 201-2-4: The server configures the authorization information corresponding to the user device code in the user USB flash drive key, and delivers the user USB flash drive key to the user corresponding to the device code.

[0072] Step 201-2-5: Insert the USB flash drive key into the user terminal to complete hardware authorization.

[0073] In this case, to increase the number of authorizations, submit a new authorization request and repeat steps 201-2-1 to 201-2-4. To renew the UKey, the server submits an application, the manufacturer generates a new authorization file and a temporary burning link for 30 minutes / 60 minutes / 24 hours, the server connects to the internet, inserts the server-side USB flash drive key, and then re-delivers the USB flash drive key to the user.

[0074] Method 3: Mini Program Unit Management Authorization (Online Verification)

[0075] Step 201-3-1: The mobile client scans the manufacturer's registration QR code and enters the authorization application to send the authorization application to the manufacturer. The authorization application includes communication information, the full name of the affiliated unit and / or the contact person.

[0076] Communication information includes contact details and accounts for various communication software (such as WeChat, QQ, etc.), and verification codes can be SMS verification codes, voice verification codes, etc.

[0077] Step 201-3-2: The manufacturer generates a verification code based on the authorization application and sends the verification code to the mobile client corresponding to the communication information;

[0078] Step 201-3-3: The PC client or mobile client sends the verification code to the manufacturer to complete the software authorization.

[0079] As one possible implementation, if a company name change is required (the user submits the original / new company name + contact information, verifies via SMS, and updates the verification code), and if relevant personnel use different mobile clients, then a change of registered personnel is required (the new user registers via the mini-program, the mini-program checks for company name conflicts and prompts for the original registration information (de-identified), the new user initiates a change request, the original user receives the "change request" in the mini-program, processes the request, performs a second SMS verification, and agrees to the change).

[0080] Step 202: The server encrypts the file to obtain an encrypted file, and sends the encrypted file to at least one user terminal.

[0081] After activation, the file encryption process begins. The server supports encrypting individual files or entire folders. Encrypted files are automatically marked with a unique encryption icon for easy identification. All encrypted files are stored in a designated directory, and the system synchronously records detailed encryption logs, including file name, size, encryption time, associated user organization, and other key information for server-side traceability and management. The server also has the right to view the unified storage directory for encrypted files and can change the storage path as needed. After a change, files in the original directory will be automatically migrated to the new path, ensuring flexible file management. If a new user organization needs to be added, the server can associate the new user organization information with the encrypted files, package the relevant materials, and send them offline.

[0082] There are two main forms of distribution for encrypted files: offline distribution and distribution via mini-programs.

[0083] During offline distribution, the server packages the encrypted file, decryption software installation package, and / or the white paper, and distributes them offline to at least one user. The server can choose to package the "encrypted file + authorization QR code" separately, or it can package the "PC client + authorization code + white paper" together and send them directly to the user via offline methods such as mail.

[0084] Distribution via mini-programs is more convenient. Users simply need to open the corresponding mini-program, scan the authorization QR code provided by the server (supports photo recognition of previously saved QR codes), and the system will verify whether the user's registered organization matches the authorization information. Once the match is successful, the authorization import is completed, and the encrypted file is synchronized to the user's PC client. In scenarios involving multiple server authorizations, users can scan the authorization QR codes of each server sequentially to manage multiple authorizations simultaneously.

[0085] As the source of file encryption, the server ensures the compliance and security of the encryption operation through software or hardware activation, preventing management chaos caused by unauthorized devices encrypting files at will. The file encryption process utilizes features such as dedicated tagging, unified storage, and logging to achieve full traceability of encrypted files, facilitating server-side control over file usage. Diverse secure distribution methods not only meet the file transfer needs of different scenarios but also ensure that encrypted files can only be accessed by authorized users through verification credentials such as authorization QR codes. The overall operation process forms a closed-loop management system of "activation-encryption-distribution," blocking the risk of file leakage at the source, ensuring the security and controllability of encrypted files during transmission, and laying the foundation for compliant decryption by users later.

[0086] Step 203: The user receiving the encrypted file decrypts the encrypted file using any authorized method to obtain the decrypted file.

[0087] Decryption is the process by which the user, provided that authorization conditions are met (such as activation code verification, UKey verification, and the authorization being within its validity period), converts an encrypted file into a usable state. Decryption, on the other hand, is an operation initiated by the server to restore the encrypted file to its plaintext state; only the server has the authority to perform this operation. The plaintext state is the file's presentation after decryption; the file is no longer encrypted and can be directly viewed and edited, unlike the restricted access mode of the encrypted state.

[0088] Furthermore, if the user prints an encrypted file in a different format, the new format file will be encrypted. Copying the contents of an encrypted file to an unencrypted file will save the unencrypted file as encrypted. Opening both encrypted and unencrypted files simultaneously will not change their encryption status.

[0089] If the encrypted file fails to be opened, the PC client will prompt that the software is not authorized or will automatically repair itself, and record the operation log.

[0090] The decryption process involves two methods:

[0091] Method 1: Ukey decryption

[0092] The user inserts the USB key sent by the user terminal to send the encrypted file, and then opens the encrypted file to decrypt it directly.

[0093] Method 2: Software Decryption

[0094] First, the decryption operation is initiated by the user. The mobile client corresponding to the user who received the encrypted file scans the device code and / or authorization QR code displayed on the PC client to send the device code and / or authorization QR code to the manufacturer. The mobile client then receives a Chinese activation code. Finally, the user inputs the Chinese activation code on the PC client to decrypt the encrypted file, obtaining the decrypted file. Based on authorization verification and within the authorization validity period, this process is divided into two scenarios: short-term trial and long-term pure software license.

[0095] In short-term trial scenarios, the user first downloads the short-term trial server from the manufacturer. This server defaults to a 1-month trial license for one client. After encrypting the file, the server sends a compressed package containing the client, the encrypted file, and the authorization QR code to the user. After installing the PC client, the user's interface displays the device code and the mini-program code. The user must first complete registration and import the authorization QR code via the mobile client (the authorization QR code is a credential generated by the server containing file authorization information; the user can scan it with the mobile client to complete the authorization import, which is a prerequisite for obtaining the activation code). The user then scans the PC client's device code with the mobile client to obtain a 17-character activation code (the activation code is a key credential used to verify the user's authorization qualification; it is either a 17-character activation code (short-term trial scenario) or a 13-character activation code (long-term pure software license scenario). After entering the activation code, the client can be activated and the encrypted file can be opened normally.

[0096] In long-term pure software licensing scenarios, the user scans the authorization QR code provided by the server via a mobile client (in multi-server scenarios, the QR codes of each server need to be scanned sequentially), selects the imported license file, and generates a 13-character activation code. Then, the user enters the activation code on the PC client, and the system verifies the license validity period. If it passes, the user completes the binding and activation with the local machine. If the license is about to expire or has already expired, the user needs to submit information such as the organization name and the new duration to the server to apply for renewal. The server generates a new authorization QR code (hiding the old file authorization). The user scans this QR code to update the license time, and then scans the PC client's device code again via the mobile client to obtain the activation code, which is then entered into the client to complete the renewal.

[0097] In one possible implementation, there are multiple encrypted files from different servers. In this case, the user needs to scan the device code through a mobile client, select multiple different servers to generate corresponding Chinese character activation codes, and then input the Chinese character activation codes into the PC client in sequence to complete the activation of multiple servers.

[0098] Step 204: The end receiving the encrypted file processes the decrypted file using the software corresponding to the decryption software type.

[0099] After decryption, the system enters the client-side compliance management phase. During normal use, the client can directly open encrypted files using the software corresponding to the decryption software type. It also supports exporting files to other formats, but the exported files remain encrypted to ensure file security. If the contents of an encrypted file are copied to an unencrypted file and saved, the unencrypted file will automatically become encrypted to prevent content leakage through copying. Simultaneously, the system sets strict unauthorized restrictions: when unauthorized software attempts to open an encrypted file, a "Software not authorized" message will pop up, and the system will record relevant operation logs; if the authorization expires and an encrypted file is used, a "Authorization expired" message will appear, and operation logs will also be recorded for traceability and management. If the client encounters an abnormal failure to open an encrypted file, the system will automatically trigger a one-click repair function. If the repair fails, the client can export the "log black box" (the log black box is a fault log file generated when the client encounters an abnormal failure; after exporting, sending it to the vendor can assist in troubleshooting and obtaining targeted repair solutions) and send it to the vendor. After the vendor provides a solution based on the logs, the client can perform self-repair.

[0100] In addition, the server can perform decryption operations on the server side:

[0101] On the PC client, the server opens the corresponding software, locates the encrypted file that needs to be decrypted, and performs the decryption operation. After that, the file will be displayed directly in plaintext in the "Encrypted File Management" module, making it convenient for the server to edit or manage it.

[0102] The decryption process on the user end strictly adheres to the principle of "authorization verification + validity period control." Multiple verification mechanisms, including activation codes and authorization QR codes, ensure that encrypted files can only be used by compliant and authorized users, preventing unauthorized access or misuse. Compliance control during client-side usage ensures operational flexibility in normal use scenarios while enabling full-process traceability of file usage through unauthorized restrictions and operation logs, reducing the risk of leakage. The server-side's dedicated decryption permissions allow for secondary management of encrypted files based on actual needs, such as editing and archiving. This overall process satisfies the user's compliant use of encrypted files while granting the server core control over the files, ultimately achieving compliant use and flexible secondary management throughout the file's lifecycle, balancing file security and ease of use.

[0103] Thus, through the complete process of "activation-encryption-distribution-decryption (declassification)" described above, the file management method, system, and media provided by this invention, which can be authorized on multiple terminals, construct a rigorous and flexible file security management system. From the user completing registration and obtaining authorization on the mobile client, to the server encrypting the file and selecting an appropriate method for distribution, and then to the user performing decryption operations according to different scenarios, each link is closely connected and mutually restrictive, forming an organic whole.

[0104] In terms of security, multiple authorization and verification mechanisms, such as activation codes, authorization QR codes, and UKeys, act as layers of robust defenses, effectively preventing unauthorized devices from accessing and manipulating encrypted files, thus eliminating the risk of file leakage at the source. Simultaneously, detailed encryption and operation logs provide strong evidence for file traceability management, ensuring that every transfer and use of files is traceable, further enhancing file security.

[0105] In terms of flexibility, three different authorization modes—offline file authorization, UKey authorization, and mini-program unit management authorization—along with diverse file distribution methods, including offline distribution and mini-program distribution, can meet the file transfer and usage needs in different scenarios. Whether it's single-machine use within the same unit, single-machine hardware binding, or online management for multi-terminal use; whether it's distributing files offline via mail or conveniently importing authorizations via mobile clients, it can all be easily achieved, providing users with great convenience.

[0106] Furthermore, this invention fully considers various situations that may arise during actual use and provides corresponding solutions. These include operational procedures such as capacity expansion, offline license renewal, increasing the number of licenses, UKey renewal, organization name change, and changes in registered personnel, enabling the system to adapt to constantly changing usage needs. Simultaneously, for abnormal failures that may occur during the use of encrypted files, such as opening failures or client anomalies, it also provides automatic repair and log black box export methods to ensure the stability and reliability of the system.

[0107] In summary, the file management method, system, and media proposed in this invention, which enable multi-terminal authorization, provide an innovative and effective solution for the secure distribution and use of files with its robust security, high flexibility, and comprehensive exception handling mechanism. It has broad application prospects and promotional value.

[0108] The following is for reference. Figure 3 It shows a schematic diagram of the structure of a computer 300 suitable for implementing the electronic device of the present invention. Figure 3 The computer 300 shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of the present invention.

[0109] like Figure 3 As shown, the computer 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the computer 300. The processing device 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0110] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows computer 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 A computer 300 with various electronic devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0111] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 309, or installed from a storage device 308, or installed from a ROM 302. When the computer program is executed by the processing device 301, it performs the functions defined in the methods of the embodiments of the present invention.

[0112] It should be noted that the computer-readable medium described above in this invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device or apparatus, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be executed by instructions, used by a device or apparatus, or used in conjunction with it. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with instructions, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0113] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0114] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the following functions: Figure 2 The methods illustrated in the embodiments and their alternative implementations are methods.

[0115] Computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using dedicated hardware-based implementations that perform the specified functions or operations, or using a combination of dedicated hardware and computer instructions.

[0117] The units or modules described in the embodiments of the present invention can be implemented in software or hardware. In some cases, the user identifier of a unit or module does not constitute a limitation on the unit itself.

[0118] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.

Claims

1. A file management method with multi-terminal authorization, characterized in that, The method includes: The server and at least one user terminal are granted software and / or hardware licenses by the manufacturer. The software license is granted by the manufacturer by issuing an authorization file to the server or user terminal offline, or by issuing a verification code to the server or user terminal online. The hardware license is granted by the manufacturer by issuing a USB flash drive key to the server or user terminal. The server encrypts the file to obtain an encrypted file, and sends the encrypted file to at least one user terminal. The encrypted file includes decryption software type. The receiving end decrypts the encrypted file using any authorized method to obtain the decrypted file; The receiving end processes the encrypted file using the software corresponding to the decryption software type.

2. The method according to claim 1, characterized in that, The server obtains software licensing from the vendor, including: The server submits an authorization request to the manufacturer. The authorization request includes organization information and order information. The organization information includes the full name of the organization to which the server belongs, communication information, contact person and / or device code. The order information includes the number of authorizations, the validity period of the authorization and / or the type of authorization file. Based on the authorization application, the manufacturer generates an authorization file containing the authorization policy and distributes it to the server offline. The authorization policy includes the authorization validity period, the total number of authorized clients, and / or the type of authorization file. The server imports the license file to complete the software license.

3. The method according to claim 1, characterized in that, The user end includes PC clients and mobile clients. The user end obtains software licensing from the vendor, including: The mobile client scans the manufacturer's registration QR code and enters an authorization request to send the authorization request to the manufacturer. The authorization request includes communication information, the full name of the affiliated unit and / or the contact person. The manufacturer generates a verification code based on the authorization application and sends the verification code to the mobile client corresponding to the communication information; The PC client or mobile client sends the verification code to the manufacturer to complete the software authorization.

4. The method according to claim 1, characterized in that, The server and multiple end-user devices are licensed to the manufacturer for hardware, including: The server submits an authorization request to the manufacturer. The authorization request includes organization information and order information. The organization information includes the full name of the organization to which the server belongs, communication information, contact person and / or device code. The order information includes the number of authorizations, the validity period of the authorization and / or the type of authorization file. Based on the authorization application, the manufacturer burns the authorization information into the server-side USB flash drive key and delivers the server-side USB flash drive key and the number of user-side USB flash drive keys corresponding to the authorization application to the server. The server inserts the server USB flash drive key to complete hardware authorization; The server configures the authorization information corresponding to the user device code in the user's USB flash drive key, and delivers the user's USB flash drive key to the user corresponding to the device code; The user inserts the USB flash drive key to complete hardware authorization.

5. The method according to claim 3, characterized in that, The server sends the encrypted file to at least one user, including: The server packages the encrypted file, the decryption software installation package, and / or uses the white paper, and distributes them to at least one user terminal offline. Alternatively, the user's mobile client can scan the authorization QR code provided by the server, and the server will synchronize the encrypted file to the user's PC client.

6. The method according to claim 5, characterized in that, The terminal receiving the encrypted file decrypts the encrypted file using any authorized method to obtain a decrypted file, including: The mobile client corresponding to the user terminal that receives the encrypted file scans the device code and / or authorization QR code displayed on the PC client in order to send the device code and / or authorization QR code to the manufacturer; The mobile client corresponding to the terminal that receives the encrypted file receives a Chinese character activation code. Upon receiving the encrypted file, the user enters the Chinese activation code on the PC client to decrypt the encrypted file and obtain the decrypted file.

7. The method according to claim 1, characterized in that, The method further includes: The server performs a decryption operation on the encrypted file to obtain the plaintext file corresponding to the encrypted file.

8. A file management system with multi-terminal authorization capability, characterized in that, include: The manufacturer, the server, and at least one user; The manufacturer is used to grant software and / or hardware licenses to the server and at least one user terminal. The software license is granted by the manufacturer sending an authorization file to the server or user terminal offline, or by the manufacturer sending a verification code to the server or user terminal online. The hardware license is granted by the manufacturer sending a USB flash drive key to the server or user terminal. The server is used to encrypt the file, obtain the encrypted file, and send the encrypted file to at least one user terminal. The encrypted file includes decryption software type. The user terminal is used to decrypt the encrypted file using any authorized method to obtain a decrypted file; and to process the decrypted file using software corresponding to the decryption software type.

9. The system according to claim 8, characterized in that, The user terminals include mobile clients and PC clients; The mobile client is used to scan the manufacturer's registration QR code, input an authorization request, and send the authorization request to the manufacturer. The authorization request includes communication information, the full name of the affiliated unit and / or contact person; send a verification code to the manufacturer to complete the software authorization; and scan the device code and / or authorization QR code displayed on the PC client to send the device code and / or authorization QR code to the manufacturer. Receive Chinese character activation code; The PC client is used to send the verification code to the manufacturer to complete the software authorization; input the Chinese activation code to decrypt the encrypted file and obtain the decrypted file.

10. A readable storage medium having executable instructions stored thereon, characterized in that, When the executable instructions are executed by the processor, they implement the method of any one of claims 1 to 7.