A document management method, device, equipment and medium
By injecting macro programs into documents, device information can be collected, traced, and dealt with, thus solving the problem of document leakage during network attacks and achieving rapid tracing and protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NSFOCUS INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2022-12-13
- Publication Date
- 2026-05-01
AI Technical Summary
How to effectively trace the source of cyberattacks, find the attackers or leakers, and prevent document leaks and information loss.
Macro programs are injected into documents to collect device information when opened, and traceability and disposal instructions are managed through document management services, including encryption, destruction, and editing permission control.
It enables real-time monitoring and protection of documents, quickly detects leaks, traces and handles them, and improves network security defense capabilities.
Smart Images

Figure CN116185961B_ABST
Abstract
Description
A document management method, apparatus, device and medium Technical Field
[0001] This application relates to the field of network security technology, and in particular to a document management method, apparatus, device and medium. Background Technology
[0002] With the continuous development of computer technology and the increasing prevalence of the internet, network attacks are emerging in endless forms, and network security issues are becoming increasingly prominent, causing greater social impact and economic losses. This presents new demands and challenges for network threat detection and defense. Common network attacks that intrude into cyberspace are often accompanied by highly damaging incidents such as document leaks and information loss. How to trace the source and find the attacker or the leaker is a technical problem that needs to be solved. Summary of the Invention
[0003] This application provides a document management method, apparatus, device, and medium for tracing the source of network attacks and finding attackers or leakers.
[0004] Firstly, this application provides a document management method applied to a document management service, including:
[0005] Determine the identifier of the document to be managed;
[0006] Determine the macro program of the document, wherein the macro program includes the document's identifier;
[0007] Based on the macro program and the document, a document object is obtained, wherein the document object includes the document and the macro program; wherein the macro program in the document object is used to collect information of any device when the document object is opened on any device;
[0008] Send the document object to the first device;
[0009] Receive the document identifier and information of the first device sent by the document object on the first device.
[0010] One possible implementation also includes:
[0011] Receive information about the document object sent by the document object on the first device;
[0012] The macro program in the document object is also used to collect information about the document object when the document object is opened.
[0013] One possible implementation also includes:
[0014] Based on changes in the information of the document object and / or changes in the information of the device when the document object is opened, determine the processing instructions to be sent to the document object;
[0015] Send the processing instruction to the document object; wherein the processing instruction is used by a macro program in the document object to process the document object based on the processing instruction.
[0016] In one possible implementation, the disposal instruction includes one or more of the following:
[0017] The document object can be encrypted, destroyed, edited, written to, read from, or renamed.
[0018] In one possible implementation, determining the identifier of the document to be managed includes:
[0019] Based on the first information of the document and the hash algorithm, the identifier of the document to be managed is determined.
[0020] In one possible implementation, the document object communicates with the document management service based on the User Datagram Protocol (UDP).
[0021] Secondly, a document management method is provided, applied to document objects, including:
[0022] The document object is received from a document management service; wherein the document object includes the document and the macro program; wherein the macro program includes the identifier of the document; the macro program in the document object is used to collect information of any device when the document object is opened on any device.
[0023] When it is determined that the document object itself is opened in the first device, the macro program in the document object collects information about the first device;
[0024] Send the document's identifier and the information of the first device to the document management service.
[0025] In one possible implementation, the macro program in the document object is also used to collect information about the document object when the document object is opened;
[0026] Also includes:
[0027] Send the document object information to the document management service.
[0028] In one possible implementation, if the document object is opened, it also includes:
[0029] Receive processing instructions sent by the document management service;
[0030] The macro program in the document object processes the document object based on the processing instructions.
[0031] In one possible implementation, upon determining that the document object itself is opened in the first device, one or more of the following are also performed:
[0032] Determine whether the IP address of the first device is within the preset IP address range. If not, encrypt the document content of the document object.
[0033] When it is determined that the document object has lost communication with the document management service, the document content of the document object is encrypted.
[0034] When it is determined that the document object has been disconnected from the document management service for a period of time greater than or equal to a set value, the document object is destroyed.
[0035] When it is determined that the information of the document object has changed, the document content of the document object is encrypted.
[0036] Thirdly, this application provides a document management device for use in document management services, comprising:
[0037] A determination module is used to determine the identifier of a document to be managed; and to determine a macro program for the document, wherein the macro program includes the identifier of the document;
[0038] A registration module is used to obtain a document object based on the macro program and the document, wherein the document object includes the document and the macro program; wherein the macro program in the document object is used to collect information of any device when the document object is opened on any device;
[0039] The transceiver module is configured to send the document object to the first device; and to receive the document identifier and information of the first device sent by the document object on the first device.
[0040] In one possible implementation, the transceiver module is further configured to receive information about the document object sent by the document object on the first device; the macro program in the document object is further configured to collect information about the document object when the document object is opened.
[0041] In one possible implementation, the determining module is further configured to determine a disposal instruction to be sent to the document object based on changes in the information of the document object and / or changes in the information of the device when the document object is opened; the transceiver module is configured to send the disposal instruction to the document object; wherein the disposal instruction is used by a macro program in the document object to dispose of the document object based on the processing instruction.
[0042] In one possible implementation, the disposal instructions include one or more of the following: encrypting the document content of the document object, destroying the document object, allowing or disallowing editing the document content of the document object, allowing or disallowing writing to the document content of the document object, allowing or disallowing reading the document content of the document object, and allowing or disallowing renaming the document object.
[0043] In one possible implementation, the determining module is specifically used to determine the identifier of the document to be managed based on the first information of the document and a hash algorithm.
[0044] In one possible implementation, the document object communicates with the document management service based on the User Datagram Protocol (UDP).
[0045] Fourthly, a document management device is provided, applied to document objects, including:
[0046] A transceiver module is used to receive a document object sent by a document management service; wherein the document object includes the document and the macro program; wherein the macro program includes the identifier of the document; the macro program in the document object is used to collect information of any device when the document object is opened on any device;
[0047] The processing module is used to collect information about the first device from the macro program in the document object when it is determined that the document object itself is opened in the first device;
[0048] The transceiver module is used to send the document's identifier and the information of the first device to the document management service.
[0049] In one possible implementation, the macro program in the document object is also used to collect information about the document object when the document object is opened;
[0050] The transceiver module is also used to send information about the document object to the document management service.
[0051] In one possible implementation, when the document object is opened, the transceiver module is further configured to receive a processing instruction sent by the document management service; the processing module is configured to allow macro programs in the document object to process the document object based on the processing instruction.
[0052] In one possible implementation, the processing module is further configured to: when it is determined that the document object itself is opened on the first device, determine whether the IP address of the first device is within a preset IP address range; if not, encrypt the document content of the document object; and / or, when it is determined that the document object has lost communication with the document management service, encrypt the document content of the document object; when it is determined that the document object has lost communication with the document management service for a duration greater than or equal to a set value, destroy the document object; and when it is determined that the information of the document object has changed, encrypt the document content of the document object.
[0053] Fifthly, this application provides an electronic device, including: a processor, optionally further including a memory; the processor and the memory are coupled; the memory is used to store computer programs or instructions; the processor is used to execute part or all of the computer programs or instructions in the memory, and when the part or all of the computer programs or instructions are executed, it is used to implement the function in any of the above methods.
[0054] In one possible implementation, the apparatus may further include a transceiver for transmitting signals processed by the processor or receiving signals input to the processor. The transceiver may perform either the transmitting or receiving action of any of the methods.
[0055] In a sixth aspect, a computer-readable storage medium is provided for storing a computer program, the computer program including instructions for implementing any of the functions.
[0056] Alternatively, a computer-readable storage medium for storing a computer program, which, when executed by a computer, causes the computer to perform any of the methods described above.
[0057] In this embodiment of the application, a macro program is injected into the document. The macro program can collect information about any device when the document is opened on any device and send it to the document management service. The document management service can know which devices have opened the document, determine whether there is a leak, and trace the source. Attached Figure Description
[0058] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0059] Figure 1 shows a schematic diagram of a document management process provided in an embodiment of this application;
[0060] Figure 2 shows a schematic diagram of the architecture of a document management service provided in an embodiment of this application;
[0061] Figure 3 shows a schematic diagram of the architecture of a macro program provided in an embodiment of this application;
[0062] Figure 4 shows a system structure diagram of a document management service and document objects provided in an embodiment of this application;
[0063] Figure 5 illustrates a schematic diagram of the interaction flow between a document management service and a document object provided in an embodiment of this application.
[0064] Figure 6 shows a structural diagram of a document management device provided in an embodiment of this application;
[0065] Figure 7 shows a structural diagram of a document management device provided in an embodiment of this application;
[0066] Figure 8 shows a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0067] To make the objectives and implementation methods of this application clearer, exemplary embodiments of this application will be clearly and completely described below with reference to the accompanying drawings of the exemplary embodiments. Obviously, the described exemplary embodiments are only a part of the embodiments of this application, and not all of the embodiments. The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms can be used interchangeably where appropriate.
[0068] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0069] To facilitate understanding, the terminology used in this application will be introduced first:
[0070] 1) Document Management Service: The document management service is a set of process services that manage sensitive or decoy documents that need to be managed. It can be deployed on a server platform and can inject macro programs into decoy and sensitive documents.
[0071] 2) Macro program: A program that can be injected into a document and run when the document is opened or read.
[0072] 3) Document objects: Documents registered in the document management service and injected with macro programs.
[0073] Figure 1 illustrates a document management process, including the following steps:
[0074] Step 100: The document management service retrieves the documents to be managed.
[0075] For example, some devices upload documents to be managed to the document management service, and the document management service then obtains the documents to be managed.
[0076] For example, the document to be managed can be a sensitive document or a decoy document, which can be an Office document or a WPS document, etc.
[0077] Step 101: The document management service determines the unique identifier of the document.
[0078] After obtaining a document to be managed, the document management service can read the document's information. This information includes, but is not limited to, one or more of the following: document format (or document type), document's user group, document's owner, document content, editing permissions (e.g., editable, not editable), read permissions (e.g., readable, not readable), write permissions (e.g., writeable, not writeable), renaming permissions (renamed, not renamed), and the document's last update time.
[0079] For example, document formats / types include: docx, doc, xls, ppt, etc.
[0080] For example, a document may belong to user group A, user group B, etc. For example, a document may belong to user a1, user a2, user b1, user b2, etc.
[0081] For ease of distinction, the information of the document retrieved by the document management service is referred to as the first information. The document management service can determine the unique identifier of the document based on this first information. Specifically, the document management service can determine the document's identifier based on the first information and a hash algorithm (or other algorithms). For example, the document management service can perform a hash calculation on the first information of the document using a hash algorithm to generate the document's unique identifier. Regardless of how the document's information changes subsequently, this unique identifier will not change.
[0082] Step 102: The document management service determines the macro program of the document, the macro program including the unique identifier of the document.
[0083] When defining a macro program, it can be generated based on a predefined macro program template (such as a VB code template) and document registration parameters (also known as a strategy).
[0084] This strategy includes, but is not limited to, what actions to take on document objects under what circumstances.
[0085] Strategies include, but are not limited to, one or more of the following:
[0086] If the device's IP address is not within the preset IP address range when the document is opened, the document content of the document object will be encrypted.
[0087] When the document object disconnects from the document management service, the document content of the document object is encrypted.
[0088] When the document object disconnects from the document management service for a period of time greater than or equal to a set value, the document object is destroyed.
[0089] When the information of the document object changes, the document content of the document object is encrypted.
[0090] When the security level of a document object exceeds a set density threshold, and the information of the document object changes, the document object is destroyed.
[0091] Step 103: The document management service obtains a document object based on the macro program and the document; the document object includes the document and the macro program.
[0092] This can be understood as the document management service injecting the macro program into the document to obtain a document object.
[0093] Document management services can inject macro programs into documents by using custom macros.
[0094] It's understandable that the unique identifier of a document and the unique identifier of a document object are the same. The content of a document object is no different from the content of a document; the differences include: macros are injected into the document object, and these macros will run by default when the document object is opened or read.
[0095] Macros have the following capabilities (the order in which these capabilities are described is not restricted):
[0096] First, monitor document objects. For example, monitor the device information where the document object is located when it is opened, and monitor changes to the document object's information. Device information includes, but is not limited to, one or more of the following: device fingerprint information (a unique identifier for Linux hosts using the SSH protocol by the bastion host), and may also include device hardware information (e.g., hard drive size, memory size), device network information (e.g., IP address), etc. Document object information includes, but is not limited to, one or more of the following: document format (or document type), document's user group, document's owner, document content, editing permissions (e.g., editable, not editable), read permissions (e.g., readable, not readable), write permissions (e.g., writeable, not writeable), renaming permissions (e.g., renaming allowed, renaming not allowed), and the time the document was last updated.
[0097] Second, it enables communication between document objects and the document management service, sending monitored information to the service. Document objects and the document management service can communicate via the User Datagram Protocol (UDP). When a document object sends monitored information to the document management service, it can do so only when it determines that the monitored information has changed, or periodically while the document is open. For example, when a document object is open, a macro program collects device information; the document object only sends the changed device information to the document management service when it determines that the device information has changed. As another example, when a document object is open, a macro program collects information from the document object; the document object only sends the changed document object information to the document management service when it determines that the document object's information has changed (e.g., from editable to disallowed).
[0098] Third, receive processing instructions from the document management service. The macro program can process the document object based on these instructions. For example, these processing instructions include, but are not limited to, one or more of the following: encrypting the document content of the document object, destroying the document object, allowing or disallowing editing the document content of the document object, allowing or disallowing writing to the document content of the document object, allowing or disallowing reading the document content of the document object, and allowing or disallowing renaming the document object.
[0099] Fourth, based on the current scenario / environment, the system can autonomously handle document objects according to specific policies. For example, handling methods include, but are not limited to, one or more of the following: encrypting the document content, destroying the document object, allowing or disallowing editing the document content, allowing or disallowing writing to the document object, allowing or disallowing reading the document content, and allowing or disallowing renaming the document object. In one specific example, it determines whether the IP address of the first device is within a preset IP address range; if not, it encrypts the document content. In another specific example, it encrypts the document content when it determines that the document object has lost communication with the document management service. In yet another specific example, it destroys the document object when it determines that the document object has lost communication with the document management service for a duration greater than or equal to a set value. In yet another specific example, it encrypts the document content when it determines that the information of the document object has changed.
[0100] Furthermore, after the document content of a document object is encrypted, the document object can receive a decryption command sent by the document management service to decrypt the document content; alternatively, the document object can decrypt the document content after a preset encryption duration. If the encryption is caused by a disconnection between the document object and the document management service, the document content can be decrypted after the disconnection is confirmed.
[0101] Step 104: The document management service sends the document object to the first device.
[0102] Correspondingly, the first device receives the document object sent by the document management service.
[0103] Other devices can download the document object from the document management service, or the document management service can distribute the document object to other devices. Other devices include, but are not limited to, the first device.
[0104] Step 105: When a document object on the first device determines that it is opened on the first device, the macro program in the document object collects information from the first device.
[0105] The information of the first device includes the fingerprint information of the first device, and may also include the hardware information of the first device, the network information of the first device, etc.
[0106] Step 106: The document object on the first device sends the document's identifier and the information of the first device to the document management service.
[0107] Accordingly, the document management service receives the document identifier and information of the first device from the document object on the first device.
[0108] In this embodiment of the application, a macro program is injected into the document. The macro program can collect information about any device when the document is opened on any device and send it to the document management service. The document management service can then know which devices have opened the document, thus enabling traceability.
[0109] Optionally, the macro program in the document object can also be used to collect information about the document object when it is opened; the document object in the first device can also send its information to the document management service. Correspondingly, the document management service receives the document object information sent by the document object on the first device.
[0110] Optionally, the document management service can determine a processing instruction to send to the document object based on changes in the document object's information and / or changes in the device's information when the document object is opened. The document management service sends the processing instruction to the document object (which is located on a device, possibly a first device or another device). The processing instruction is used by a macro program within the document object to process the document object based on the processing instruction. Correspondingly, the document object on the device receives the processing instruction sent by the document management service; the macro program within the document object processes the document object based on the processing instruction.
[0111] For example, if the device's IP address is in the IP address blacklist when the document object is opened, a destroy command can be sent to the document object.
[0112] For example, when it is determined that the information of the document object has changed, an encryption command can be sent to the document object.
[0113] Figure 2 illustrates the architecture of a document management service.
[0114] The document management service is designed with a B / S architecture.
[0115] A communication component is used for communication between the document management service and document objects, such as maintaining heartbeats and data transmission between the document management service and document objects. Communication via the UDP protocol is supported. The entire data transmission process is encrypted.
[0116] The data parsing function is used to parse packet headers based on communication protocols, and can add or remove packet headers.
[0117] Encryption and decryption functions are used to encrypt or decrypt data transmitted between the document management service and document objects.
[0118] The data processing function is used to process the data transmitted between the document management service and the document object based on business requirements.
[0119] Document management functionality is used to manage documents, such as issuing disposal instructions.
[0120] Macro templates are used to store predefined VB code.
[0121] The strategy function can be configured with various strategies, such as those described in step 102.
[0122] The macro generation function is used to generate macro programs based on macro program templates and various configured strategies.
[0123] The document registration function injects macro programs into the documents that need to be managed to obtain document objects; calculates and records the unique identifier of each document.
[0124] The data aggregation function aggregates and analyzes document object data according to the unique identifier of each document, and provides this information to the outside world through the WebUI interface.
[0125] Database (DB): Used to store document-related information. For example, the document management service associates the initial information of the document, the hash value of the document content, etc., with the document's unique identifier and stores them in the database. The document management service can also store copies of document objects in the database, as well as information received from document objects, data sent to document objects, and processing instructions, all in the database. All related queries and data aggregations related to this document use this unique identifier as the primary key.
[0126] The association function associates document object information with a unique identifier and stores it in the database DB.
[0127] Figure 3 shows a schematic diagram of a macro program architecture.
[0128] Macro programs include, but are not limited to, encryption / decryption functions, communication functions, policy functions, processing functions, and data acquisition functions.
[0129] The communication function is used for communication between the document management service and document objects, such as maintaining heartbeats and transmitting data. Communication via the UDP protocol is supported. The entire data transmission process is encrypted. After receiving data from the document management service, the communication function categorizes and processes the data. If it is data requiring disposal, it will invoke the disposal function to handle the document object. The disposal function's disposal capabilities are achieved by calling the corresponding Windows API.
[0130] The disposal function can also be combined with the strategy function to dispose of document objects independently.
[0131] The strategy function is used to store strategy content and, based on the strategy content and changes in the environment / scenario, invoke the relevant capabilities of the disposal function to process document objects.
[0132] Encryption and decryption functions are used to encrypt and decrypt data transmitted between document objects and document management services at the application layer.
[0133] The data acquisition function is used to collect information about the device and document objects.
[0134] Figure 4 shows a system architecture diagram of a document management service and document objects.
[0135] The document management service receives and registers documents. Specifically, it first checks the format of uploaded documents. If the format meets the requirements, it generates a macro program based on strategies and macro program templates. This macro program is then injected into the document, completing the macro injection operation and generating a document object. This process enables document registration.
[0136] When a document object is distributed to a device and opened, information about the device and the document object can be collected. This information is then sent to the document management service, while maintaining communication between the document management service and the document object.
[0137] The document management service, based on pre-defined policies, can manage document objects, analyze the location of the devices containing the document objects, and issue disposal instructions to the document objects. Upon receiving the disposal instructions, the document objects will perform the corresponding disposal operations.
[0138] The above description of communication maintenance and handling assumes that the document object remains open.
[0139] Table 1 illustrates a message format between a document object and a document management service:
[0140]
[0141] Message example:
[0142]
[0143] Figure 5 illustrates a schematic diagram of the interaction process between a document management service and a document object.
[0144] The document object sends a heartbeat message to the document management service, and the document management service responds to the heartbeat message after receiving it.
[0145] The entire heartbeat maintenance process ensures packet continuity through packet ID and ACK number, meaning that the I communication process of the heartbeat message packet adopts an acknowledgment mode.
[0146] If a document object is missing several heartbeats from the document management service quality inspection, it may be due to a loss of communication connection. In this case, the document object can be encrypted to protect its content based on a policy.
[0147] When information about a document object (such as document content, last opened time, etc.) or device information changes, the document object reports the corresponding change information to the document management service. The document management service can then save the document object information and device information based on the document's unique identifier. Upon receiving the change information, the document management service can also reply with a corresponding ACK message.
[0148] The document management service can send disposal instructions to document objects. When a document object receives a disposal instruction, it will take corresponding measures on the document according to the disposal instruction. After completion, it will send a confirmation message back to the document management service.
[0149] By injecting macros into documents, they are enabled to become document objects. These document objects do not affect the daily use of the documents, but they possess the ability to monitor the documents themselves and upload monitored information to the document management service. The document management service can analyze the information monitored by all document objects. This analysis can achieve the purposes of preventing data leakage and tracing attack sources. In some scenarios, document objects can be used as decoy traps or honeypots. In addition, the document management service issues disposal instructions to document objects to protect the documents.
[0150] The document management service monitors and analyzes files or decoy information. When a document or decoy is found to be outside the designated network, it can immediately locate and further analyze the network location of the document. It can quickly detect data breaches, and if a breach is confirmed, it can immediately issue a file destruction order. This creates a complete closed loop from the occurrence of a data breach to its resolution. The collected device information can help trace the attack source of intruders or data breach perpetrators. It is also very helpful for routine inspections by operations and maintenance personnel.
[0151] This application makes it very convenient to generate document objects, and document objects look no different from ordinary documents. Therefore, a large number of document object decoys can be deployed into the network, which greatly improves the efficiency of trapping.
[0152] Based on the same technical concept, as shown in Figure 6, this application also provides a document management device for document management services, including:
[0153] The determination module 61 is used to determine the identifier of the document to be managed; and to determine the macro program of the document, wherein the macro program includes the identifier of the document;
[0154] Registration module 62 is used to obtain a document object based on the macro program and the document, wherein the document object includes the document and the macro program; wherein the macro program in the document object is used to collect information of any device when the document object is opened on any device;
[0155] The transceiver module 63 is used to send the document object to the first device; and to receive the document identifier and information of the first device sent by the document object on the first device.
[0156] In one possible implementation, the transceiver module 63 is further configured to receive information about the document object sent by the document object on the first device; the macro program in the document object is further configured to collect information about the document object when the document object is opened.
[0157] In one possible implementation, the determining module 61 is further configured to determine a processing instruction to be sent to the document object based on changes in the information of the document object and / or changes in the information of the device when the document object is opened; the transceiver module 63 is configured to send the processing instruction to the document object; wherein the processing instruction is used by a macro program in the document object to process the document object based on the processing instruction.
[0158] In one possible implementation, the disposal instructions include one or more of the following: encrypting the document content of the document object, destroying the document object, allowing or disallowing editing the document content of the document object, allowing or disallowing writing to the document content of the document object, allowing or disallowing reading the document content of the document object, and allowing or disallowing renaming the document object.
[0159] In one possible implementation, the determining module 61 is specifically used to determine the identifier of the document to be managed based on the first information of the document and a hash algorithm.
[0160] In one possible implementation, the document object communicates with the document management service based on the User Datagram Protocol (UDP).
[0161] Based on the same technical concept, as shown in Figure 7, this application also provides a document management device applied to document objects, including:
[0162] The transceiver module 71 is used to receive a document object sent by the document management service; wherein the document object includes the document and the macro program; wherein the macro program includes the identifier of the document; the macro program in the document object is used to collect information of any device when the document object is opened on any device;
[0163] Processing module 72 is used to collect information about the first device by a macro program in the document object when it is determined that the document object itself is opened in the first device;
[0164] The transceiver module 71 is used to send the document identifier and the information of the first device to the document management service.
[0165] In one possible implementation, the macro program in the document object is also used to collect information about the document object when the document object is opened;
[0166] The transceiver module 71 is also used to send information about the document object to the document management service.
[0167] In one possible implementation, when the document object is opened, the transceiver module 71 is further configured to receive a processing instruction sent by the document management service; the processing module 72 is configured to allow the macro program in the document object to process the document object based on the processing instruction.
[0168] In one possible implementation, the processing module 72 is further configured to: when it is determined that the document object itself is opened on the first device, determine whether the IP address of the first device is within a preset IP address range; if not, encrypt the document content of the document object; and / or, when it is determined that the document object has disconnected from the document management service, encrypt the document content of the document object; when it is determined that the disconnection between the document object and the document management service is greater than or equal to a set duration, destroy the document object; and when it is determined that the information of the document object has changed, encrypt the document content of the document object.
[0169] Based on the same technical concept, this application also provides an electronic device. Figure 8 shows a schematic diagram of the structure of an electronic device. As shown in Figure 8, it includes: a processor 81, and optionally, it also includes: a communication interface 82, a memory 83, and a communication bus 84. The processor 81, the communication interface 82, and the memory 83 communicate with each other through the communication bus 84.
[0170] The memory 83 stores a computer program, which, when executed by the processor 81, causes the processor 81 to complete the steps of the document management method described above.
[0171] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0172] Communication interface 82 is used for communication between the above-mentioned electronic device and other devices.
[0173] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0174] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0175] Based on the same technical concept and the above embodiments, this application provides a computer-readable storage medium storing a computer program executable by an electronic device, wherein computer-executable instructions are used to cause a computer to perform the steps of the above-described document management method.
[0176] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash memory), solid-state drives (SSDs), etc.
[0177] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0178] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0179] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0180] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0181] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A document management method, characterized in that, This is applied to document management services and includes: determining the identifier of a document to be managed; determining a macro program for the document, the macro program including the document identifier; obtaining a document object based on the macro program and the document, wherein the document object includes the document and the macro program; wherein the macro program in the document object is used to collect information of any device when the document object is opened on any device; sending the document object to a first device; and receiving the document identifier and information of the first device sent by the document object on the first device when the information of the document object changes; wherein the process of determining the macro program includes: based on a predefined macro program template and document registration parameters, Generate a macro program; the document registration parameters include: under what circumstances and what actions to take on the document object; wherein, the document registration parameters include one or more of the following: determining whether the IP address of the first device is within a preset IP address range, and if not, encrypting the document content of the document object; encrypting the document content of the document object when it is determined that the document object has lost communication with the document management service; destroying the document object when it is determined that the document object has lost communication with the document management service for a duration greater than or equal to a set value; encrypting the document content of the document object when it is determined that the information of the document object has changed.
2. The method as described in claim 1, characterized in that, Also includes: The document object receives information from the document object on the first device; the macro program in the document object is also used to collect information from the document object when the document object is opened.
3. The method as described in claim 2, characterized in that, Also includes: Based on changes in the information of the document object and / or changes in the information of the device when the document object is opened, determine the processing instructions to be sent to the document object; Send the disposal instruction to the document object; wherein the disposal instruction is used by a macro program in the document object to dispose of the document object based on the disposal instruction.
4. The method as described in claim 3, characterized in that, The processing instructions include one or more of the following: encrypting the document content of the document object, destroying the document object, allowing or disallowing editing the document content of the document object, allowing or disallowing writing to the document content of the document object, allowing or disallowing reading the document content of the document object, and allowing or disallowing renaming the document object.
5. The method as described in claim 1, characterized in that, Determining the identifier of a document to be managed includes: determining the identifier of the document to be managed based on the first information of the document and a hash algorithm.
6. The method as described in claim 1, characterized in that, The document object communicates with the document management service based on the User Datagram Protocol (UDP).
7. A document management method, characterized in that, This is applied to document objects, including: receiving a document object sent by a document management service; wherein the document object includes a document and a macro program; wherein the macro program includes an identifier of the document; the macro program in the document object is used to collect information of any device when the document object is opened on any device; when it is determined that the document object itself is opened on a first device, the macro program in the document object collects information of the first device; when it is determined that the information of the document object changes, the macro program sends the identifier of the document and the information of the first device to the document management service; wherein the determination process of the macro program includes: generating a macro program according to a predefined macro program template and document registration parameters; document registration parameters... The strategy includes determining the appropriate actions to take against a document object under different circumstances. Specifically, when a document object is determined to be opened on a first device, one or more of the following actions are performed: determining whether the IP address of the first device is within a preset IP address range; if not, encrypting the document content of the document object; encrypting the document content of the document object when the document object is determined to have lost communication with the document management service; destroying the document object when the communication connection between the document object and the document management service has been lost for a duration greater than or equal to a set value; and encrypting the document content of the document object when the information of the document object has changed.
8. The method as described in claim 7, characterized in that, The macro program in the document object is also used to collect information about the document object when the document object is opened; it also includes sending the information about the document object to the document management service.
9. The method as described in claim 7, characterized in that, When the document object is opened, the method further includes: receiving a processing instruction sent by the document management service; and the macro program in the document object processing the document object based on the processing instruction.
10. A document management device, characterized in that, Applied to document management services, including: functional modules for implementing the method as described in any one of claims 1-6.
11. A document management device, characterized in that, Applied to document management services, including: functional modules for implementing the method as described in any one of claims 7-9.
12. An electronic device, characterized in that, include: Processor and memory; The memory is used to store computer programs or instructions; The processor is configured to execute some or all of the computer programs or instructions in the memory, and when the some or all of the computer programs or instructions are executed, to implement the method as described in any one of claims 1-9.
13. A computer-readable storage medium, characterized in that, Used to store a computer program, the computer program including instructions for implementing the method as claimed in any one of claims 1-9.
Citation Information
Patent Citations
Abnormality sensing and tracking method and system
CN107046535A
Download processing method and device based on honeypot system and electronic equipment
CN114205097A