A secret electronic file secret transmission management system, method and application

Through an independently controllable classified electronic document secure transmission management system, the encryption and decryption algorithms of "one signature, one key" and "one time, one key" are used. Combined with a domestic operating system and a controllable self-destruct chip, the security and efficiency problems of traditional classified document transmission are solved, and highly reliable data transmission and secure storage are achieved.

CN115842654BActive Publication Date: 2026-03-31XIAN HUALI GUODUN INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing technologies for transmitting classified documents suffer from problems such as low encryption density, susceptibility to cracking, reliance on foreign technologies leading to security risks, high transmission costs and low efficiency, and are constrained by the chip industry.

Method used

It adopts an independent and controllable classified electronic document secure transmission management system, and performs point-to-point encryption and decryption through "one signature, one key" and "one-time key" algorithms. Combined with domestic operating system and chip, it uses a controllable self-destructing key chip to achieve double encryption, and combines lossless storage technology and digital signature technology for secure storage.

Benefits of technology

It achieves highly reliable data transmission security, independent controllability, convenience, and uncrackability, reducing the security risks and costs of traditional methods, and ensuring the immediacy and traceability of file transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115842654B_ABST
    Figure CN115842654B_ABST
Patent Text Reader

Abstract

A secret electronic file secret transmission management system, method and application, including a transmission channel connecting a user end and a supervision end, and a secure transmission management software arranged on the user end and the supervision end, belong to the technical field of data security, characterized in that: the user end includes a computing power device, a storage device, an identification password machine, a special secret transmission encryption and decryption computer and a secure transmission management software; the supervision end includes a computing power server, a storage server, an identification password machine, a special secret transmission encryption and decryption computer, a quantum true random key generator and a secure transmission management software. The secret file is encrypted and decrypted and transmitted in a "point-to-point" manner, and is stored safely using lossless storage technology, which can effectively solve the problems of safe and fast transmission and safe storage of secret electronic files, and is applied to government agencies, secret units, military enterprises, military and military-civilian integration units to transmit secret electronic files and improve the high-level data security management of secret electronic files.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security technology, and in particular relates to a classified electronic document secure transmission management system, method and application. Background Technology

[0002] The transmission of classified documents has high confidentiality requirements. Traditional encryption methods mostly involve encrypting the information to be encrypted before transmission, and then decrypting it at the receiving end; or using a dedicated transmission channel to further enhance confidentiality. However, traditional data encryption methods are easily cracked, and establishing dedicated transmission channels is inefficient and costly. Currently, internationally, the transmission of classified information in military, industrial, and commercial sectors is gradually adopting secure networks and modern information security technologies such as encryption to replace traditional methods.

[0003] At the same time, if modern technology for transmitting classified documents relies entirely on technology designed abroad, especially programs written based on its cryptographic algorithms, there are significant risks. Since the original code of the algorithms comes from abroad, we may be subject to constraints and human biases. Furthermore, using code written by them, which may contain "backdoors," also poses a security risk of leaking our classified documents.

[0004] Whether for communication or encryption / decryption, integrated chips are required. For well-known reasons, we are constrained in the chip industry, especially when it comes to high-performance computing chips. Based on these reasons, and in accordance with relevant regulations and China's national conditions, we have proposed an independent and controllable solution and developed a classified electronic document secure transmission management system.

[0005] The process of domestic substitution will inevitably accelerate! Self-reliance and controllability are prerequisites for ensuring network security and information security. Being self-reliant and controllable means that information security is easy to manage, products and services generally do not have malicious backdoors, and vulnerabilities can be continuously improved or patched; conversely, not being self-reliant and controllable means being "controlled by others," which means being subject to others, and the consequences are: information security is difficult to manage, products and services generally have malicious backdoors, and vulnerabilities are difficult to continuously improve or patch. Summary of the Invention

[0006] This invention aims to solve the above-mentioned problems and provides a classified electronic document secure transmission management system, method and application. It can securely transmit information data with high confidentiality requirements. Classified documents are encrypted and decrypted and transmitted in a "point-to-point" manner between the sending end and the receiving end, and are securely stored using lossless storage technology, which can effectively solve the problem of secure storage of classified electronic documents.

[0007] The technical solution of this invention is:

[0008] In a first aspect, the present invention provides a classified electronic document secret transmission management system, including a transmission channel connecting a user terminal and a supervisory terminal, and secure transmission management software set on the user terminal and the supervisory terminal. The user terminal includes a computing power device, a storage device, an identification cryptographic machine, a dedicated secret transmission encryption and decryption computer, and the secure transmission management software.

[0009] The user terminal encrypts the plaintext to be transmitted into ciphertext, then encrypts the ciphertext into a encrypted packet, and transmits it to the monitoring terminal.

[0010] The monitoring terminal includes a computing server, a storage server, an identification cryptographic machine, a dedicated encrypted and decrypted computer, a true random sequence key generator, and secure transmission management software.

[0011] The monitoring terminal will receive a encrypted packet, and if the key matches, it will decrypt the encrypted packet into ciphertext and plaintext by reversing the encryption process on the user end.

[0012] The transmission channel is a TCP / IP network.

[0013] Furthermore, in the classified electronic document secure transmission management system of the present invention, the secure transmission management software includes a secure issuance algorithm, a secure transmission algorithm, a secure storage algorithm, and an operating system; the secure issuance algorithm, secure transmission algorithm, and secure storage algorithm include:

[0014] 1) Dedicated cryptographic algorithm: The key uses a one-sign-one-key operation procedure;

[0015] 2) Standard cryptographic algorithms used: symmetric cryptography algorithms DEC and SM4; asymmetric cryptography algorithms SM2 and SM9; hash function algorithms SHA256 and SM3 for hash values;

[0016] 3) Digital envelope encryption and decryption algorithms; dedicated digital envelope RNG one-time password encryption and decryption algorithm, and algorithm for converting electronic signatures into one-time passwords;

[0017] 4) One-time pad encryption algorithm with true random sequence key;

[0018] The operating system used is a domestically developed operating system.

[0019] Furthermore, in the confidential electronic document transmission management system of the present invention, the computing device includes a data management unit, a verification unit, a time unit, a location unit, an encryption / decryption calculation unit, and an identity authentication and signature unit.

[0020] The computing server includes a data management unit, a user registration and creation unit, a verification unit, a time unit, a location unit, an encryption and decryption operation unit, and an identity authentication and signature unit.

[0021] The storage server or storage device includes a file receiving and sending storage database and an electronic evidence database unit for receiving and sending files.

[0022] The true random sequence key generator includes a quantum key true random generator and a storage device; the quantum key true random sequence key generator is used to inject the true random sequence key into the user-end storage device during user registration, and simultaneously inject the same true random sequence key into the supervisory-end storage server; the identification cryptographic machine includes a processor computing chip, which adopts a domestically produced 32-bit MCU;

[0023] The dedicated encrypted and decrypted computer includes a domestically produced central processing unit and a controllable self-destructing key chip array plug-in board; the domestically produced central processing unit is equipped with high-strength identity authentication system logic and computing power chips.

[0024] Furthermore, in the classified electronic document secret transmission management system of the present invention, the user refers to the issuing or receiving unit of the classified electronic document and the corresponding classified management specialist.

[0025] The user must undergo qualification review, verification and registration by the regulatory authority to obtain the security management certification qualification and obtain the right to use the identification cryptographic machine and the dedicated secure encryption and decryption computer;

[0026] The computing server or computing device is used to collect user information, transmit and burn the verified user information into the data storage device of the user information server and the user's identification cryptographic machine, and perform encryption and decryption operations on the files in the transmission system.

[0027] The storage server or storage device is used to archive and store classified electronic documents issued or received by the supervisor or user, as well as digital evidence of the entire process of encryption, decryption, transmission and storage of electronic documents.

[0028] The regulatory data server enables user registration, key distribution, disk card creation, document and evidence verification, and storage.

[0029] Furthermore, the present invention provides a classified electronic document secret transmission management system, which also includes a controllable self-destruct key chip set in the system. The controllable self-destruct key chip uses physical or chemical methods to create irreparable fragments or dissolve the functional medium layer of the chip or device loaded with a true random sequence key, thereby realizing a controllable self-destruct key.

[0030] Secondly, the classified electronic document confidential transmission management method of the present invention includes:

[0031] The user terminal converts the plaintext of the classified electronic document into ciphertext using an identification cryptographic machine, and then uses a secret transmission encryption and decryption computer to convert the ciphertext into a secret packet, instantly triggering a controllable self-destruct chip to destroy the true random sequence encryption key;

[0032] The encrypted packet is transmitted to the monitoring terminal via a TCP / IP network transmission channel;

[0033] After receiving the encrypted packet, the regulatory end converts it into ciphertext using a secret transmission encryption and decryption computer. This instantly triggers a controllable self-destruct chip to destroy the true random sequence decryption key. The regulatory end's security personnel then decrypt the ciphertext using an identification cryptographic machine, converting it into plaintext for archiving and storage.

[0034] Furthermore, in the confidential electronic document transmission management method of the present invention, the user terminal uses a secure issuance algorithm to convert plaintext into ciphertext and encrypted packets. The secure issuance algorithm includes a time and location coordinate identifier pixel element heterogeneous addition algorithm to ensure that the issuance identifier can not be reused. During issuance, an issued electronic evidence is generated, which consists of the hash value of time, location, identifier, and the hash value of the issued document, and can be used to verify the authenticity of the document.

[0035] Furthermore, in the confidential electronic document transmission management method of the present invention, the encryption at the user end and the decryption at the supervisory end follow the following conditions:

[0036] 1) The encryption and decryption key sequences are the same and the same length as the encrypted information. The encryption and decryption use a one-time pad algorithm that XORs the data stream bit by bit.

[0037] 2) The encryption and decryption key sequences are composed of truly random data, using a reliable quantum true randomness generation server to generate true keys of infinite length;

[0038] 3) The encryption and decryption key sequences of the one-time pad algorithm can only be used once and must be destroyed.

[0039] Furthermore, in the confidential electronic document transmission management method of the present invention, the user-end encryption and supervision end use a quantum true random key sequence generation server to generate a true random key sequence to encrypt and decrypt the confidential electronic document. Simultaneously, data with the same format and data that are synchronized are injected into the key sequence databases of both the encryption and decryption parties through a secure distribution method, and encryption and decryption operations are performed. Both parties extract a true random key sequence data of the same length as the encrypted information from their respective key sequence databases and perform encryption and decryption operations to obtain the encrypted information.

[0040] The beneficial effects of this invention are:

[0041] (1) Double encryption, public network transmission, uncrackable.

[0042] The system employs a "one-key-one-password" spatiotemporal fusion and heterogeneous algorithm for encrypting and decrypting electronic documents, i.e., encrypting plaintext into ciphertext and decrypting ciphertext back into plaintext. It also uses a "one-time key" bitwise XOR algorithm for encrypting and decrypting ciphertext, i.e., encrypting ciphertext into a encrypted packet and decrypting the encrypted packet back into ciphertext. Utilizing controllable self-destruct chip technology, the encryption and decryption key sequences can only be used once and are immediately destroyed after use. This ensures highly reliable transmission of confidential documents, with data encryption and transmission between the system client and server in a "point-to-point" manner. It possesses independent controllability, security, and reliability characteristics, offering higher confidentiality, security, immediacy, convenience, traceability, and unbreakable ciphertext compared to traditional methods and systems utilizing foreign technology.

[0043] (2) AI intelligent computing and digital evidence storage prevent repudiation and tampering.

[0044] Digital signature technology is used to solve authentication, tamper-proofing, and non-repudiation of file transfer behavior and process during transmission.

[0045] (3) Lossless storage ensures secure storage of file data.

[0046] It employs a triple-redundancy lookup and error-correction storage algorithm with multiple access and multiple modes to ensure that the data files stored in the system will not be corrupted or lost. It uses R-ary encrypted storage to convert files into encrypted form, ensuring that files are unreadable if stolen. It manages the lifecycle of files and storage hardware by determining whether to terminate or extend file storage based on file characteristics, providing early warnings of device lifecycle issues and prompting replacement.

[0047] (4) It integrates domestically produced heterogeneous chips and domestic operating systems, meeting the requirements of information technology innovation.

[0048] The system uses the domestically developed "NeoKylin" and "HarmonyOS" operating systems and domestically produced control algorithm chips. It integrates different functions and structures of software and hardware within the chip using Chinese-developed and manufactured technologies, including: CPU, hardware encryption chip (TF series), verification operation (XOR) logic, spatiotemporal data alienation operation logic, regulatory key, as well as signed document database, electronic evidence database, real-time time (RTc) timestamp and location stamp synchronized with BeiDou.

[0049] (5) Safe, reliable, instant and convenient:

[0050] The transmission of classified documents (paper or electronic) requires a high degree of confidentiality. Traditional methods involve sending a dedicated vehicle with two people or using a confidential document exchange station. For classified documents traveling long distances, they must be delivered through specialized confidential transportation or communications departments. Using traditional methods of transmitting classified documents is costly in terms of manpower, resources, and time, with incalculable overall costs, and also poses many security risks. Attached Figure Description

[0051] Figure 1 This is a schematic diagram of the confidential electronic document transmission management method described in this invention. Detailed Implementation

[0052] The following detailed description of the classified electronic document secure transmission management system, method, and application of the present invention, with reference to the accompanying drawings and embodiments, is provided in detail.

[0053] Example 1

[0054] This embodiment discloses a classified electronic document secure transmission management system, including a transmission channel connecting the user terminal and the monitoring terminal, and secure transmission management software set on the user terminal and the monitoring terminal. The user terminal includes a computing power device, a storage device, an identification cryptographic machine, a dedicated secure transmission encryption and decryption computer, and secure transmission management software.

[0055] The user terminal encrypts the plaintext to be transmitted into ciphertext, then encrypts the ciphertext into a encrypted packet, and transmits it to the monitoring terminal.

[0056] The monitoring terminal includes a computing server, a storage server, an identification cryptographic machine, a dedicated encrypted and decrypted computer, a true random sequence key generator, and secure transmission management software.

[0057] The monitoring terminal will receive a encrypted packet, and if the key matches, it will decrypt the encrypted packet into ciphertext and plaintext by reversing the encryption process on the user end.

[0058] The transmission channel is a TCP / IP network, which is a dedicated channel for connecting user-end equipment and monitoring equipment via a secure and reliable TCP / IP communication channel;

[0059] The computing power device includes a data management unit, a verification unit, a time unit, a location unit, an encryption / decryption operation unit, and an identity authentication and signature unit;

[0060] The computing server includes a data management unit, a user registration and creation unit, a verification unit, a time unit, a location unit, an encryption and decryption operation unit, and an identity authentication and signature unit.

[0061] The storage server or storage device includes a file receiving and sending storage database and an electronic evidence database unit for receiving and sending files.

[0062] The true random key generator includes a quantum key true random generator and a password storage device. When a user registers, the registration server injects a true random long key into the user's true random password storage device, and at the same time injects the same true random password into the storage server of the supervisory end corresponding to the user's true random password.

[0063] In this embodiment, the identification cryptographic machine includes a processor computing chip, which adopts a domestic (GigaDevice) 32-bit MCU, with main parameters including internal Flash 512k, Ram 192k, RNG; external 64G Flash chip memory; and external 64G SD memory card.

[0064] The dedicated encrypted and decrypted computer includes a domestically produced central processing unit and a controllable self-destructing key chip array plug-in board; the domestically produced central processing unit is equipped with a high-strength identity authentication system logic;

[0065] The secure transmission management software includes secure issuance algorithms, secure transmission algorithms, and secure storage algorithms. The operating system uses the domestically developed Kylin OS. Dedicated cryptographic algorithms are employed, with the key using a one-signature-one-key operation program. The cryptographic algorithms used include: one-time pad symmetric cryptographic algorithms (DEC, SM4); asymmetric cryptographic algorithms with mutual key anonymity (RSA, IBC, SM2, SM9); hash function algorithms for hash values ​​(SHA256, SM3); digital envelope encryption / decryption algorithms; dedicated digital envelope RNG one-time pad encryption / decryption algorithms; algorithms for converting electronic signature one-signature-one-key to one-time pad; and a true random sequence key one-time pad encryption algorithm.

[0066] In this embodiment, the classified electronic document secure transmission management system enables users to obtain secure management certification after registration, qualification review and verification by the regulatory authority, and access to an electronic identification signing card (proving user identity), an identification cryptographic machine, and a dedicated secure transmission encryption / decryption computer. Users convert plaintext to ciphertext using the identification cryptographic machine, then convert the ciphertext into a secure packet using the secure transmission encryption / decryption computer. This instantaneously triggers a controllable self-destruct chip to destroy the true encryption key. The user then transmits the secure packet to the regulatory authority via a reliable TCP / IP communication channel. Upon receiving the secure packet, the regulatory authority's security specialist converts it back to ciphertext using the secure transmission encryption / decryption computer, instantly triggering a controllable self-destruct chip to destroy the true decryption key. The security specialist then decrypts the ciphertext back to plaintext using the identification cryptographic machine. The plaintext is archived and stored on a storage server. The regulatory authority can reversely transmit the ciphertext back to the user.

[0067] The process by which the user (issuing party) signs, encrypts, stores, and sends the prepared classified electronic document to the receiving party at the regulatory end includes:

[0068] After receiving the electronic encrypted packet, the recipient goes through the processes of receiving, decrypting, and storing it. The secure storage process for the electronic encrypted text is as follows: the data storage server is verified and notarized to use redundant fault-tolerant, error-checking, and error-correcting algorithms to ensure the losslessness of classified document data; the sender, recipient, and supervisor also adopt mutually backed-up and mutually supervised encrypted storage, as well as key judgment logic, to prohibit unilateral modification; classified electronic documents and archives are comprehensively managed, and are automatically classified using the attribute stamps signed on the electronic documents, and are encrypted and entered into the corresponding database according to the classification.

[0069] In this embodiment of the disclosure, the data transmission process of the classified electronic document confidential transmission management system includes the following steps:

[0070] 1) Identity information authentication and registration: Authenticate user identity, users (including user terminal, regulatory terminal and security specialist) register identity information, the regulatory terminal reviews and verifies user qualifications and identity information, the regulatory terminal issues secret management certification qualification, users obtain electronic identification signing card, initial identification cryptographic machine, and obtain dedicated secret transmission encryption and decryption computer access rights;

[0071] 1-1) User Information Collection on the User End: User end users include user organizations and security personnel. The user-specific electronic signature creation data is obtained from the qualification and identity information collected by the user information collection device on the user end. Data using subjectively granted legal connotations and credible characteristics, and directly demonstrable qualification certificates and ID card information, is used as the user-end user signing registration parameters. The data collection section is equipped with ID card readers and qualification certificate readers. The user-specific electronic signature card is issued by the regulatory authority after verifying the user's identity information.

[0072] The registration information collected by the ID card reader and qualification certificate reader is transmitted to the registration computer. The registration computer classifies and processes the information collected from the security specialist's ID card: the name and photo collected from the ID card are used as the imprint of the security specialist's electronic seal, and the qualification certificate is used to mark the user's unit in the electronic seal graphic, generating the user's original electronic signature creation data; the registration computer sends the user's signature mark, comprehensive registration and other information to the registration information unit of the regulatory computing power server. The registration information unit stores the registration information in the verification unit, and realizes the exclusivity of the user's electronic signature creation data through registration review and verification algorithms. Then, the user's signature mark, comprehensive registration and other information are input into the creation computer, and the computing power server creation computer creates the electronic signature card.

[0073] 1-2) Regulatory User Information Collection: Regulatory users include regulatory agencies and security personnel. The data for creating electronic signatures unique to regulatory users is obtained from the qualification and identity information collected by the regulatory user information collection device. This data uses subjectively granted legal connotations and credible attributes, and directly demonstrable qualification certificates and ID card information, as the registration parameters for regulatory user signatures. The data collection section is equipped with ID card readers and qualification certificate readers. The user-specific electronic signature card is issued after the regulatory agency verifies the user's identity information.

[0074] The registration information collected by the ID card reader and qualification certificate reader is transmitted to the registration computer. The registration computer classifies and processes the information collected from the security specialist's ID card: the name and photo collected from the ID card are used as the imprint of the security specialist's electronic seal, and the qualification certificate is used to mark the user's unit in the electronic seal graphic, generating the user's original electronic signature creation data; the registration computer sends the user's signature mark, comprehensive registration and other information to the registration information unit of the regulatory computing power server. The registration information unit stores the registration information in the verification unit, and realizes the exclusivity of the user's electronic signature creation data through registration review and verification algorithms. Then, the user's signature mark, comprehensive registration and other information are input into the creation computer, and the computing power server creation computer creates the electronic signature card.

[0075] 2) Registration and issuance of electronic identification signature cards and initial identification cryptographic devices: According to the registration information, the regulatory end activates the registration and production unit program of the regulatory end computing power server to issue exclusive electronic identification signature cards for the registrant (i.e., the user end) and the regulatory end and security specialist. The exclusive electronic identification signature cards are burned point-to-point into the exclusive electronic identification signature card of the user end and the exclusive electronic identification signature card of the user end. The exclusive electronic identification signature card is controlled by the security specialist.

[0076] 2-1) Electronic Identification Signing Card: This is a multi-functional signing device containing a microcomputer system that can sign electronic documents. Its signing part contains an algorithm program that uses dynamic variable parameters to perform data fusion calculations on the original electronic signature creation data. It stores the original electronic signature creation data, the dynamic variable parameters involved in the calculation, time, location, key, and supervision code.

[0077] 2-2) Identification Cryptography Machine: An identification cryptography machine is a device that uses identification data (identification data representing identity characteristics such as user name, address, email, trademark, etc.) to generate encryption and decryption cryptographic algorithms and encrypt and decrypt information. It generates an asymmetric identification public-private key pair through the "identification cryptographic algorithm". The identification cryptographic data used as the public key is converted into a visual identification graphic for signing documents and is registered and distributed to the signing end and the verification end. It is an electronic device that implements the patent transformation of the inventor's application number 201711471521.5 "A method for signing documents with identification keys and verification".

[0078] 3) Encryption for document issuance:

[0079] After a user (issuing party) creates a confidential electronic document, it is issued using "one signature, one key" technology. The user's identity information and the identifier for verifying the document's content are loaded onto the document. This, along with the verification party, forms an issuance verification system through an information transmission channel. The issued document is not transmitted to the computing server. The computing server uses the issued electronic evidence, composed of the issuance time, a modified "one-time key" identifier graphic, and the electronic document with the identifier graphic, to query the evidence and determine the issuer's identity, the qualifications, authority, and recognition of the substitute issuer, as well as the authenticity and originality of the issued document. The results are then sent back to the issuer.

[0080] The sender's security specialist first encrypts the confidential electronic document to be sent using the "one signature, one key" technology of the spatiotemporal fusion alienation algorithm, converting it into ciphertext. The ciphertext is then converted into a encrypted packet by the secret transmission machine using the key sequence and the information "bitwise XOR operation" and "one key at a time" technology for encryption and transmission.

[0081] The workflow for secure transmission of classified electronic documents is as follows: The sender's security specialist first encrypts the classified electronic document to be sent into ciphertext using "one-signature-one-key" technology. The ciphertext is then converted into a encrypted packet using "one-time key" technology via a secure transmission device and sent. The encryption (or decryption) cipher is a true random cipher (generated by the supervisor's quantum key generator) injected into a controllable self-destruct chip. Before the encrypted packet is sent, the controllable self-destruct chip is triggered to destroy the cipher. The encrypted packet can be transmitted to the recipient via a PCT / IP network. The recipient's security specialist receives the encrypted packet via a secure transmission device, decrypts it into plaintext using "one-time key" technology, triggers the controllable self-destruct chip to destroy the cipher, and then decrypts the ciphertext into plaintext using "one-signature-one-key" technology. The plaintext is then archived and stored losslessly on a storage server (or storage device).

[0082] The computing server's "evidence database" records the electronic evidence data generated during each document issuance process. This data is compared, verified, and traced against the electronic evidence database records in the signer, effectively preventing others from forging issuance information and users from denying issuance information. The "issued document database" stores all issued documents, allowing for traceability, verification, downloading, and use based on permissions.

[0083] The issued evidence is securely transmitted to the verification network. Since the data content of the issued evidence is very short, an asymmetric encryption and decryption algorithm is used directly, while the content of the verification query book is encrypted and decrypted using a symmetric encryption and decryption algorithm.

[0084] The technology of issuing documents without uploading verifiable information ensures that the document information is not publicly disclosed on the verification network. Combined with the true number sequence cryptography system for classified documents in this system, it has a high level of security.

[0085] 4) Secure document transmission:

[0086] The password sequence is generated by the regulator's quantum key true random generator and recorded into the self-destructing chip of the secret transmission device. It self-destructs instantly after use. The self-destructing chip is triggered to destroy the password before the secret packet is sent. The secret packet can be transmitted to the recipient via the PCT / IP network.

[0087] This embodiment employs a nested encryption scheme with a one-time pad cryptosystem. The one-time pad cryptosystem for true numbers is nested within the one-time pad cryptosystem for a sequence of true functions, which improves the encryption strength of the file and also performs user authentication.

[0088] The one-time pad symmetric cryptosystem based on random numbers and the one-time pad cryptosystem based on true random function sequences are completely different in terms of the number of keys generated and the encryption and decryption algorithms. The one-time pad symmetric key based on random numbers only requires a random number that conforms to the symmetric key algorithm (length) as the key. The encryption and decryption of files still use the classic algorithm of "encrypting and decrypting files with the same key". The one-time pad random number key used in this embodiment is a random number (or a dynamic function) obtained by the file sender and receiver according to an agreement. The true random number sequence generated by the quantum true random number server is input into a self-destructible chip array and distributed to the sender and receiver. The main features are:

[0089] The key does not need to be pre-set or remembered, eliminating setup and storage issues.

[0090] The key does not need to be exposed during the transmission of encrypted data, thus eliminating the risk of interception.

[0091] The key is used only once for a file, and is destroyed immediately after use, with no possibility of reuse.

[0092] The sender uses a signature-one-key system to convert plaintext into ciphertext. The transmission system then uses a one-time key technique to package the ciphertext into a encrypted packet, immediately destroying the encryption key via a self-destruct chip before transmitting it over the public network (see appendix). Figure 1 The receiving party decrypts the encrypted packet using a one-time key technique, converts it into ciphertext, and immediately destroys the decryption key through a self-destruct chip. Then, it uses a one-signature-one-key key to convert the ciphertext into plaintext and archives it without loss in the storage server (or storage device).

[0093] When applied to data transmission, a one-time pad symmetric cryptosystem based on random numbers can, in conjunction with authentication of the data creator and a document signing system, enable the recipient to verify the authenticity, originality, and non-repudiation of the document. Furthermore, by utilizing the "one-signature-one-key" information within the signing system, a one-time pad symmetric cryptosystem based on random numbers (or a dynamic one-time pad) can be obtained through conversion, achieving a higher level of secure transmission. Its security feature is that the key does not appear in the transmission channel.

[0094] The one-time pad symmetric cryptosystem for random numbers described in this embodiment has practical value compared to the classical symmetric cryptographic algorithms that increase the difficulty of cracking by continuously increasing the key length. The one-time pad symmetric cryptosystem for random numbers does not require dedicated hardware for generating the one-time pad, thus ensuring that the random number key does not appear during file transmission or transfer, thereby increasing the difficulty of cracking the key and ciphertext.

[0095] The system described in this embodiment uses a controllable self-destruct chip loaded with a true random number sequence key. This chip destroys the core chip or device through physical or chemical methods, causing irreparable fragmentation or dissolving the functional dielectric layer. Its physical structure is completely destroyed, resulting in complete and irreversible loss of function. This is currently the safest and most reliable self-destruction method. By introducing microfluidic technology, controllable self-destruction of the chip is achieved. The gradual release of the corrosive liquid is controlled wirelessly, enabling timed and targeted rapid self-destruction of the chip loaded with the true random number sequence key as needed.

[0096] 5) File reception and decryption:

[0097] The receiving security specialist receives the encrypted packet through the encrypted transmitter, uses the "one-time password" technology to decrypt the encrypted packet into ciphertext, triggers the controllable self-destruct chip to destroy the password, and then uses the "one-signature password" technology to decrypt the ciphertext into plaintext, and archives it without loss to the storage server (or storage device).

[0098] 6) Secure file storage:

[0099] Encrypted files transmitted from the classified electronic document secure transmission management system are transferred to a secure storage system. Before the files are sent to the database, they are converted to R-base for encryption and then stored.

[0100] The R-radix-based conversion storage method involves converting and encrypting files into ciphertext, ensuring that the files are unreadable after being stolen. The secure file storage system utilizes periodic refreshes to allow for file regeneration. It also features storage hardware lifecycle monitoring, enabling hardware replacement before the end of its designated lifespan, ensuring the continued secure storage of files.

[0101] The secure file storage employs a multi-address, multi-mode, triple-redundancy lookup and error-correction storage algorithm: a lossless storage algorithm that ensures that the data files stored in the system will not be damaged or lost.

[0102] The secure file storage system employs technical measures such as file lifecycle management, file regeneration and archiving, input / output security settings, and electronic document verification to ensure the secure storage of electronic file data, as well as equipment lifecycle calculation, early warning, and replacement.

[0103] Example 2

[0104] This embodiment discloses a method for managing the secure transmission of classified electronic documents, the method comprising:

[0105] The user terminal converts the plaintext of the classified electronic document into ciphertext using an identification cryptography machine, and then uses a secret transmission encryption and decryption computer to convert the ciphertext into a secret packet, instantly triggering a controllable self-destruct chip to destroy the encryption key;

[0106] The encrypted packet is transmitted to the monitoring terminal via a TCP / IP network transmission channel;

[0107] After receiving the encrypted packet, the regulatory end converts it into ciphertext using a secret transmission encryption and decryption computer. This instantly triggers a controllable self-destruct chip to destroy the decryption key. The regulatory end's security personnel then decrypt the ciphertext into plaintext using an identification cryptographic machine, and the plaintext is archived and stored.

[0108] In this embodiment of the disclosure, the user terminal uses a secure issuance algorithm to convert plaintext into ciphertext and encrypted packets. The secure issuance algorithm includes a time and location coordinate identifier pixel element heterogeneous addition algorithm to ensure that the issued identifier can not be reused. During issuance, an issued electronic evidence is generated, which consists of the hash value of time, location, identifier, and the hash value of the issued document, and can be used to verify the authenticity of the document.

[0109] In this embodiment of the disclosure, the user-side encryption and the supervisory-side decryption follow the following conditions:

[0110] 1) The encryption and decryption key sequences are the same and the same length as the encrypted information. The encryption and decryption use a one-time pad algorithm that XORs the data stream bit by bit.

[0111] 2) The encryption and decryption key sequences are composed of true random number sequences, and a reliable quantum true random number generation server is used to generate true keys of infinite length;

[0112] 3) The encryption and decryption key sequences of the one-time pad algorithm can only be used once and must be destroyed.

[0113] In this embodiment of the disclosure, the user-end encryption and monitoring end uses a quantum true random number key sequence generation server to generate true random number key sequences to encrypt and decrypt classified electronic documents. Simultaneously, data with the same format and data that are synchronized are injected into the key sequence databases of both the encryption and decryption parties through a secure distribution method. Encryption and decryption operations are performed. Both parties extract a key sequence data of the same length as the encrypted information from their respective key sequence databases and perform encryption and decryption operations to obtain the encrypted information.

[0114] The method described in this embodiment of the disclosure, in the process of transmitting classified electronic documents, includes: loading user identity information and an identifier for verifying the content of the document onto the document; forming a signing and verification system with the verification party through an information transmission channel; the signed document is not transmitted to the computing power server; the computing power server uses the signed electronic evidence composed of the signing time, a modified "one-time password" identifier graphic, and the electronic document with the identifier graphic loaded to query the evidence to determine the identity of the signer, the qualifications, authority, and recognition of the signer, as well as the authenticity and originality of the signed document, and sends the result back to the signer.

[0115] The sender's security specialist first encrypts the confidential electronic document to be sent using "one signature, one key" technology, converting it into ciphertext. The ciphertext is then converted into a encrypted packet using a secret transmission device with a random number key sequence and "bitwise XOR operation" and "one-time key" technology, and then sent in encrypted form.

[0116] Based on the confidential electronic document transmission management system disclosed in Example 1, the confidential electronic document transmission workflow is as follows: The sending party's security specialist first encrypts the confidential electronic document to be sent into ciphertext using the "one-signature-one-key" technology. The ciphertext is transmitted to the secret transmission machine via an identification cryptographic machine. It is then converted into a cipher packet using the "one-time key" technology and encrypted and sent via the secret transmission machine. The encryption (or decryption) cipher is a true randomness (generated by the supervisor's quantum key generator) injected into a controllable self-destruct chip. Before the cipher packet is sent, the controllable self-destruct chip is triggered to destroy the cipher. The cipher packet can be transmitted to the receiving party via a PCT / IP network. The receiving party's security specialist receives the cipher packet through the secret transmission machine, decrypts the cipher packet into ciphertext using the "one-time key" technology, triggers the controllable self-destruct chip to destroy the cipher, and then decrypts the ciphertext into plaintext using the "one-signature-one-key" technology. The plaintext is then archived and stored losslessly in a storage server (or storage device).

[0117] like Figure 1 As shown, each step includes plaintext to ciphertext: the sender's security specialist uses a cryptographic device to encrypt the confidential electronic document to be sent into ciphertext using a "one-signature-one-key" technique.

[0118] Ciphertext to Encrypted Packet: The ciphertext is transmitted to the encryption transmitter via an identification cipher machine. It is then converted into an encrypted packet using a true random number key sequence and a bitwise XOR operation on the information, employing a "one-time pad" technique. The true random number cipher sequence is generated by a quantum key generator from the regulatory body and stored on a self-destructing chip in the encryption transmitter. This chip self-destructs instantly after use, and the ciphertext is destroyed before the encrypted packet is sent.

[0119] Encrypted packet transmission: The encrypted packet is transmitted by the encrypted transmitter via a PCT / IP network, and the receiving security specialist receives the encrypted packet through the encrypted transmitter.

[0120] Encryption packet to ciphertext: The receiving security specialist receives the encrypted packet through the encryption device, uses "one-time encryption" technology to decrypt the encrypted packet and convert it into ciphertext, triggering a controllable self-destruct chip to destroy the password.

[0121] Ciphertext to plaintext: The receiving security specialist transmits the ciphertext to the identification cipher machine via a cipher machine, and then uses the "one signature, one key" technology to decrypt the ciphertext and convert it into plaintext.

[0122] Lossless storage: Perform lossless storage.

[0123] It should be understood that the specific embodiments described above are merely illustrative or explanatory of the principles of the invention and do not constitute a limitation thereof. Therefore, any modifications, equivalent substitutions, improvements, etc., made without departing from the spirit and scope of the invention should be included within the protection scope of the invention. Furthermore, the appended claims are intended to cover all variations and modifications falling within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. A secret electronic file transmission management system, comprising a transmission channel connecting a user end and a supervision end, and a secure transmission management software arranged in the user end and the supervision end, characterized in that: the user end comprises a computing power device, a storage power device, an identification password machine, a special encryption computer and a secure transmission management software; the user end encrypts plaintext into ciphertext, and then encrypts the ciphertext into a secret package, and transmits the secret package to the supervision end; the supervision end comprises a computing power server, a storage power server, an identification password machine, a special encryption computer, a true random sequence key generator and a secure transmission management software; the supervision end receives the secret package, and if the key matches, decrypts the secret package into ciphertext and plaintext according to the inverse process of the encryption process of the user end; the transmission channel is a TCP / IP network; the computing power device comprises a data management unit, a verification unit, a time unit, a location unit, an encryption and decryption operation unit, an identity authentication and signature unit; the computing power server comprises a data management unit, a user registration unit, a verification unit, a time unit, a location unit, an encryption and decryption operation unit, an identity authentication and signature unit; the storage power server or the storage power device comprises a receiving and sending file storage database and an electronic evidence database unit for receiving and sending files; the true random key generator comprises a quantum key true random generator and a true random password storage device; the quantum key true random generator is used to inject a true random key into the user end true random password storage device when the user end is registered, and at the same time, the same true random key is injected into the true random password storage server of the supervision end; the identification password machine comprises a processor calculation chip, which adopts a domestic 32-bit MCU; the special encryption computer comprises a domestic central processing unit and a controllable self-destruction key chip array plug-in board; the domestic central processing unit is provided with an identity authentication system logic and a computing power chip.

2. The secret electronic file transmission management system according to claim 1, characterized in that: the user refers to a sending or receiving unit of secret electronic files and a corresponding secret management officer; the user must be qualified after being verified and registered by the supervision end to obtain a secret pipe certification qualification and the use right of the identification password machine and the special encryption computer; the computing power server or the computing power device is used to collect user information, and transmit and burn the verified user information into the user information server and the data storage device of the identification password machine of the user, and perform encryption and decryption operation on the files of the transmission system; the storage power server or the storage power device is used to archive and store secret electronic files sent or received by the supervision party or the user and digital evidence of the whole process of encryption, decryption, transmission and storage of the electronic files; the data server of the supervision end realizes user registration, key distribution, card making, document and evidence verification and storage. Further comprising a controllable self-destruction key chip arranged in the system, which uses physical or chemical methods to cause a non-recoverable fragment or a dissolved functional medium layer to the true random sequence key chip or device loaded therein, so as to realize controllable self-destruction key. The method comprises: ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ 3. The secret electronic file transmission management system according to claim 2, characterized in that: ​ 4. A method for classified electronic file transmission management, characterized in that, ​ The user terminal converts the plaintext into ciphertext by the identification password machine, and then converts the ciphertext into a secret package by the secret transmission encryption and decryption computer, and destroys the real random sequence encryption key by triggering the controllable self-destruction chip; The secret package is transmitted to the supervision terminal through the TCP / IP network transmission channel; After receiving the secret package, the supervision terminal converts the secret package into ciphertext by the secret transmission encryption and decryption computer, destroys the real random sequence decryption key by triggering the controllable self-destruction chip, and converts the ciphertext into plaintext by the identification password machine, and then archives and stores the plaintext; The user terminal encryption and the supervision terminal decryption comply with the following conditions: 1) The encryption and decryption key sequences are the same, and the same length as the encrypted information, and the encryption and decryption uses the data stream bit by bit XOR one-time pad algorithm; 2) The encryption and decryption key sequences are composed of real random data, and a reliable quantum real random key sequence generation server is used to generate an infinite length real key; 3) The encryption and decryption key sequence of the one-time pad algorithm can only be used once, and must be destroyed.

5. The method according to claim 4, characterized in that: The user terminal encryption and the supervision terminal use the quantum real key sequence generation server to generate real random key sequences for encryption and decryption of the confidential electronic file, and simultaneously inject the same format, same data and synchronous data into the key sequence database of the encryption and decryption sides by a safe distribution method, and perform encryption and decryption operations. The two sides intercept a key sequence data with the same length as the encrypted information in the respective key sequence database, and perform encryption and decryption operations to obtain.

Citation Information

Patent Citations

  • A document signing and verification method using an identifier key

    CN108229188B

  • Encrypted storage key management system and method of high-speed network

    CN106330868A

  • Identity key file signing and verifying method

    CN108229188A