A data processing method, device, medium and product for office materials

By generating and embedding watermarks in documents, combined with document, device, and permission information, the problem of data leakage in digital office environments is solved, and the security control and access management of documents are realized.

CN118504034BActive Publication Date: 2025-10-24杭州威灿科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410777982.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-17
Publication Date
2025-10-24
Estimated Expiration
2044-06-17

AI Technical Summary

Technical Problem

Existing methods for protecting written documents are insufficient to effectively prevent data leaks in digital and networked office environments. Traditional physical security measures and encryption or watermarking technologies are easily cracked and cannot effectively prevent the leakage of sensitive information.

Method used

A watermark is generated by acquiring document identification information, generating device information, and operation permission information. This watermark is then embedded in encrypted documents, and permission analysis is performed to control access permissions and prevent unauthorized operations.

Benefits of technology

It improves the security of written materials, reduces the risk of sensitive information leakage, ensures the confidentiality and integrity of data, and prevents unauthorized users from operating the documents illegally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118504034B_ABST
    Figure CN118504034B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing, in particular to a data processing method and device for official documents, medium and product, which comprises the following steps: generating a watermark based on document identification information, document generation device information and document operation permission information, and performing watermark embedding analysis based on the encrypted official documents to determine watermark embedding requirements. Then, the watermark information to be embedded is embedded into the encrypted official documents according to the watermark embedding requirements. When detecting an operation request for the encrypted watermark official documents, request permission analysis is performed based on the request identity information and the embedded watermark information in the encrypted official documents. When the operation request does not have operation permission, the operation request is prohibited from performing operation on the encrypted watermark official documents; when the operation request has operation permission, the operation request is performed on the encrypted watermark official documents. In the watermark generation process, the three factors of documents, devices and permissions are comprehensively considered, and the security of the official documents is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a data processing method and device for documents, a medium and a product. BACKGROUND

[0002] With the rapid development of information technology and the popularity of digital office, the management and transmission of documents are gradually shifting to electronic and networked. However, this change has brought challenges in data security and privacy protection. Sensitive information contained in documents, such as business secrets and personal privacy, may cause serious losses to individuals or organizations if leaked.

[0003] Traditional document protection methods mainly rely on physical security measures, such as file cabinets and access control systems. However, these methods are not effective in a digital and networked office environment. In addition, some simple encryption or watermarking techniques have been applied to document protection, but these techniques are often vulnerable to cracking and tampering, and cannot effectively prevent data leakage.

[0004] Therefore, how to improve the security of documents is a problem to be solved by those skilled in the art. SUMMARY

[0005] The purpose of the present application is to provide a data processing method, device, medium and product for documents to solve at least one of the above technical problems.

[0006] The above invention purpose of the present application is realized by the following technical scheme:

[0007] In a first aspect, the present application provides a data processing method for documents, which adopts the following technical scheme:

[0008] A data processing method for documents, comprising:

[0009] Obtaining document identification information, document generation device information and document operation permission information, and generating a watermark based on the document identification information, the document generation device information and the document operation permission information to obtain watermark information to be embedded;

[0010] Obtaining an encrypted document, and performing watermark embedding analysis based on the encrypted document to determine watermark embedding requirements, wherein the watermark embedding requirements include a watermark embedding position and a watermark embedding method;

[0011] Embedding the watermark information to be embedded into the encrypted document according to the watermark embedding requirements to obtain an encrypted watermark document;

[0012] When the operation request on the encrypted watermark document is detected, the request identity information corresponding to the operation request is acquired, and request permission analysis is performed based on the request identity information and the embedded watermark information in the encrypted document material;

[0013] When the operation request does not have operation permission, the operation request is prohibited from performing operation on the encrypted watermark document; when the operation request has operation permission, operation on the encrypted watermark document is performed according to the operation request.

[0014] By adopting the above technical solution, the watermark generation is performed based on the document identification information, the document generation device information and the document operation permission information, the to-be-embedded watermark information is obtained, the watermark embedding analysis is performed based on the encrypted document material, and the watermark embedding requirement is determined, wherein the watermark embedding requirement includes a watermark embedding position and a watermark embedding mode. Then, the to-be-embedded watermark information is embedded into the encrypted document material according to the watermark embedding requirement, and the encrypted watermark document is obtained. When the operation request on the encrypted watermark document is detected, the request permission analysis is performed based on the request identity information and the embedded watermark information in the encrypted document material, when the operation request does not have operation permission, the operation request is prohibited from performing operation on the encrypted watermark document; when the operation request has operation permission, operation on the encrypted watermark document is performed according to the operation request. In the watermark generation process, the three factors of the document, the device and the permission are comprehensively considered, so that the to-be-embedded watermark information can control the access permission in the document material transmission process, prevent unauthorized users from performing illegal operation on the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0015] In a preferred example, the application can be further configured to, before the encrypted document material is acquired, further include:

[0016] The content distribution and the data level division strategy of the document material are acquired, and the data sensitivity of the document material is divided based on the content distribution and the data level division strategy, and the target document material is obtained, wherein the material content in the target document material is divided into different data levels;

[0017] The data hierarchical encryption operation is performed based on the target document material, and the encrypted document material is obtained, wherein the data hierarchical encryption operation uses corresponding encryption modes for data of different data levels.

[0018] In a preferred example, the application can be further configured to, the watermark embedding analysis based on the encrypted document material to determine the watermark embedding requirement, including:

[0019] Obtaining security requirements of the encrypted document material, performing embedding mode analysis based on the security requirements, and determining a watermark embedding mode, wherein the watermark embedding mode includes visible watermark embedding and invisible watermark embedding;

[0020] For the visible watermark embedding, performing position screening based on content distribution of the encrypted document material, and determining a watermark embedding position;

[0021] For the invisible watermark embedding, performing position screening based on data sensitivity distribution in the encrypted document material, and determining a watermark embedding position;

[0022] Integrating the watermark embedding mode and the watermark embedding position, and determining a watermark embedding requirement.

[0023] In a preferred example, the application can be further configured to, after the request permission analysis based on the request identity information and the embedded watermark information in the encrypted document material, further include:

[0024] Obtaining a request permission analysis result in a period, performing security evaluation based on the request permission analysis result, and obtaining a security evaluation result;

[0025] When the security evaluation result is abnormal, performing watermark analysis based on the encrypted watermark document, obtaining document publishing information, and completing the traceability operation of the document material.

[0026] In a preferred example, the application can be further configured to, based on the document identification information, the document generation device information and the document operation permission information, to generate a watermark, and obtain embedded watermark information, including:

[0027] Based on the document identification information, the document generation device information and the document operation permission information, pre-processing is performed, wherein the pre-processing is used to ensure the accuracy and consistency of the data;

[0028] Based on the pre-processed document identification information, document generation device information and document operation permission information, data encoding is performed to obtain embedded watermark information.

[0029] In a preferred example, the application can be further configured to, based on the request identity information and the embedded watermark information in the encrypted document material, to perform request permission analysis, including:

[0030] Based on the request identity information, role matching is performed to determine a target role, and based on the embedded watermark information, watermark analysis is performed to obtain the document operation permission information;

[0031] The target role is matched with the document operation permission information based on the target role, and target operation permission is obtained;

[0032] The target operation permission is analyzed based on the target operation permission and the operation request, to determine whether the operation request is within the permission range corresponding to the target role.

[0033] In a second aspect, the present application provides an electronic device, which adopts the following technical solution:

[0034] At least one processor;

[0035] Memory;

[0036] At least one application program, wherein the at least one application program is stored in the memory and is configured to be executed by the at least one processor, and the at least one application program is configured to execute the above-mentioned data processing method of the document material.

[0037] In a third aspect, the present application provides a computer readable storage medium, which adopts the following technical solution:

[0038] A computer readable storage medium, which stores a computer program, and when the computer program is executed in a computer, the computer is caused to execute the above-mentioned data processing method of the document material.

[0039] In a fourth aspect, the present application provides a computer program product, which adopts the following technical solution:

[0040] A computer program product, comprising a computer program, which is executed by a processor to realize the above-mentioned data processing method of the document material.

[0041] In summary, the present application includes at least one of the following beneficial technical effects:

[0042] The watermark generation is performed based on the document identification information, the document generation device information and the document operation permission information, and watermark embedding information is obtained. Watermark embedding analysis is performed based on the encrypted document material, and watermark embedding requirements are determined, wherein the watermark embedding requirements include a watermark embedding position and a watermark embedding manner. Then, the watermark embedding information is embedded into the encrypted document material according to the watermark embedding requirements, and an encrypted watermark document is obtained. When an operation request for the encrypted watermark document is detected, request permission analysis is performed based on the request identity information and the embedded watermark information in the encrypted document material. When the operation request does not have operation permission, the operation request is prohibited from performing operation on the encrypted watermark document; when the operation request has operation permission, the operation request is performed on the encrypted watermark document. In the watermark generation process, the three factors of document, device and permission are comprehensively considered, so that the watermark embedding information can control the access permission in the document material transmission process, prevent unauthorized users from performing illegal operations on the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0043] The content distribution and data level division strategy of the document material are obtained, and the target document material is obtained by performing data sensitivity division on the document material based on the content distribution and data level division strategy. Then, the data hierarchical encryption operation is performed based on the target document material, and the encrypted document material is obtained. The encryption processing of the document material is used to protect the confidentiality of the data and prevent the data from being tampered with, so as to ensure the integrity and authenticity of the data. At the same time, different encryption methods are used for different data levels, which means that sensitive information will be protected at a higher level, reducing the risk of data leakage or illegal access. BRIEF DESCRIPTION OF DRAWINGS

[0044] Fig. 1 is a flowchart of a data processing method of a document material according to an embodiment of the present application;

[0045] Fig. 2 is a structural diagram of a data processing device of a document material according to an embodiment of the present application;

[0046] Fig. 3 is a structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0047] The following Figs. 1 to 3 The present application is further described in detail.

[0048] The present embodiment is only an explanation of the present application, and is not a limitation of the present application. Those skilled in the art can make modifications to the present embodiment without creative contribution after reading the present specification, but as long as the modifications are within the scope of the present application, they are protected by the patent law.

[0049] To make the purposes, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application. It should be noted that, in optional embodiments of the present application, the object information and other related data involved in the embodiments of the present application need to be obtained with the permission or consent of the object when the embodiments of the present application are applied to specific products or technologies, and the collection, use, and processing of the related data need to comply with relevant laws, regulations, and standards of the country and region. That is, the data related to the object in the embodiments of the present application need to be obtained with the authorization and consent of the object, the authorization and consent of the relevant department, and the compliance with the relevant laws, regulations, and standards of the country and region. If the embodiments involve personal information, the consent of the individual needs to be obtained for the acquisition of all personal information, and the separate consent of the information subject needs to be obtained for the acquisition of sensitive information, and the embodiments also need to be implemented with the authorization and consent of the object.

[0050] In addition, the term “and / or” in this paper only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. In addition, the character “ / ” in this paper generally represents an “or” relationship between the associated objects unless otherwise specified.

[0051] The embodiments of the present application will be described in further detail below with reference to the drawings of the specification.

[0052] The embodiments of the present application provide a data processing method of a document, executed by an electronic device, which can be a server or a terminal device. The server can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited thereto. The terminal device and the server can be directly or indirectly connected through wired or wireless communication, and the embodiments of the present application do not limit this. Fig. 1 As shown in the figure, the method comprises steps S101, S102, S103, S104, and S105, wherein:

[0053] Step S101: Obtain document identification information, document generation device information and document operation permission information, and generate a watermark based on the document identification information, the document generation device information and the document operation permission information to obtain watermark information to be embedded.

[0054] For the embodiments of the present application, the document identification information is used to represent some related information of the document material, including but not limited to: document material name, version number, creation date, author, which helps to identify the source and version history of the document material; the document generation device information is used to represent the device information for creating or modifying the document material, including but not limited to: the device IP address for generating the document, or other information capable of uniquely identifying the device, which helps to lock the generation device when tracing the document material later; the document operation permission information records in detail the user permissions possessed by different user roles, so as to avoid illegal access of the document material by users without operation permission. Then, based on the document identification information, the document generation device information and the document operation permission information, the watermark information to be embedded is obtained by processing according to a preset encoding rule (for example, an encryption algorithm, a hash algorithm, etc.), wherein the watermark information to be embedded has uniqueness and verifiability, so as to facilitate tracing and verification when the document material is forged and tampered. In the watermark generation process, the three factors of document, device and permission are comprehensively considered, so that the watermark information to be embedded can control the access permission in the propagation process of the document material, prevent unauthorized users from illegally operating the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0055] Step S102: Obtain the encrypted document material, and perform watermark embedding analysis based on the encrypted document material to determine watermark embedding requirements, wherein the watermark embedding requirements include: watermark embedding position and watermark embedding mode;

[0056] Step S103: Embed the watermark information to be embedded into the encrypted document material according to the watermark embedding requirements to obtain an encrypted watermark document.

[0057] For the embodiments of the present application, the document material may contain some important sensitive information, for example, customer data, personal privacy, etc. If the sensitive information is leaked, it will cause great loss to individuals or organizations. Therefore, the document material is encrypted to protect the confidentiality of the data and prevent the data from being tampered with to ensure the integrity and authenticity of the data. There are many ways to encrypt the document material, and the embodiments of the present application are not limited. In one realizable way, the content distribution and data level division strategy of the document material are obtained, and the data sensitivity of the document material is divided based on the content distribution and data level division strategy to obtain the target document material, wherein the material content in the target document material is divided into different data levels. Based on the target document material, a data hierarchical encryption operation is performed to obtain the encrypted document material, wherein the data hierarchical encryption operation uses a corresponding encryption method for data of different data levels. However, due to the different needs of different types and needs of the encrypted document material for watermark embedding, for example, misuse prevention document material, brand promotion document material, copyright protection document material, different types of encrypted document material are suitable for different watermark embedding needs. Therefore, based on the encrypted document material, watermark embedding analysis is performed to determine the watermark embedding requirement, wherein the watermark embedding requirement includes: watermark embedding position and watermark embedding method. Selecting appropriate watermark embedding requirements for encrypted document material can provide personalized protection and management solutions for different types of document materials, thereby achieving the purposes of misuse prevention, brand promotion, copyright protection, etc., and improving the security and integrity of the document. There are many ways to analyze the watermark embedding, and the embodiments of the present application are not limited. In one realizable way, the security requirement of the encrypted document material is obtained, the embedding method is analyzed based on the security requirement, and the watermark embedding method is determined, wherein the watermark embedding method includes: visible watermark embedding and invisible watermark embedding; the position is selected based on the content distribution of the encrypted document material to determine the watermark embedding position; and the watermark embedding method and the watermark embedding position are combined to determine the watermark embedding requirement. Further, according to the watermark embedding requirement, the watermark information to be embedded is embedded into the encrypted document material to obtain an encrypted watermark document, that is, the watermark is embedded in the watermark embedding position of the encrypted document material according to the watermark embedding method in the watermark embedding requirement to obtain the encrypted watermark document.

[0058] Step S104: When detecting the operation request for the encrypted watermark document, obtaining the request identity information corresponding to the operation request, and performing request authority analysis based on the request identity information and the embedded watermark information in the encrypted document material;

[0059] Step S105: When the operation request does not have operation authority, the operation request is prohibited to perform operation on the encrypted watermark document; when the operation request has operation authority, the operation request is performed on the encrypted watermark document according to the operation request.

[0060] For the embodiments of the present application, different users have different operation permissions for the encrypted watermark document, the confidentiality of the data is protected, and the data is prevented from being tampered with, so when an operation request for the encrypted watermark document is detected, request permission analysis is performed based on the request identity information corresponding to the operation request and the embedded watermark information in the encrypted document material, ensuring that only users with operation permissions can perform related operations on the encrypted watermark document. There are many ways to perform request permission analysis, and the embodiments of the present application will not be limited, in one implementable way, role matching is performed based on the request identity information, the target role is determined, and watermark analysis is performed based on the embedded watermark information to obtain document operation permission information; permission matching is performed based on the target role and the document operation permission information to obtain the target operation permission; request permission analysis is performed based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role. Finally, when the operation request does not have operation permission, the operation request is prohibited from performing operations on the encrypted watermark document; when the operation request has operation permission, the operation request is performed on the encrypted watermark document according to the operation request.

[0061] It can be seen that in the embodiments of the present application, watermark generation is performed based on document identification information, document generation device information and document operation permission information to obtain to-be-embedded watermark information, and watermark embedding analysis is performed based on the encrypted document material to determine watermark embedding requirements, wherein the watermark embedding requirements include: watermark embedding position and watermark embedding method. Then, according to the watermark embedding requirements, the to-be-embedded watermark information is embedded into the encrypted document material to obtain the encrypted watermark document. When an operation request for the encrypted watermark document is detected, request permission analysis is performed based on the request identity information and the embedded watermark information in the encrypted document material, when the operation request does not have operation permission, the operation request is prohibited from performing operations on the encrypted watermark document; when the operation request has operation permission, the operation request is performed on the encrypted watermark document according to the operation request. In the watermark generation process, the three factors of document, device and permission are comprehensively considered, so that the to-be-embedded watermark information can control the access permission in the document material propagation process, prevent unauthorized users from performing illegal operations on the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0062] Further, in order to reduce the risk of data leakage or illegal access, in the embodiments of the present application, before the encrypted document material is obtained, the following steps are further included:

[0063] The content distribution and data level division strategy of the document material are obtained, and the data sensitivity of the document material is divided based on the content distribution and data level division strategy to obtain the target document material, wherein the material content in the target document material is divided into different data levels;

[0064] The data hierarchical encryption operation is performed based on the target document material, and encrypted document material is obtained, wherein the data hierarchical encryption operation uses corresponding encryption modes for data of different data levels.

[0065] For the embodiments of the present application, a data level division strategy is pre-stored in the electronic device, that is, the data level division strategy records in detail the data levels corresponding to different types of content in the document material, and the data levels can be classified into different levels such as top secret, secret, confidential, and general. The content distribution of the document material records in detail the distribution of different types of content in the document material, and the different types of content of the document material include but are not limited to basic information, background part, main part, conclusion part, supporting material, legal policy basis, signature and seal information, etc. Then, based on the content distribution and the data level division strategy, the data sensitivity of the document material is divided to obtain the target document material, wherein the target document material is the document material marked with the corresponding data level according to the data level division strategy, and clearly marks which information in the document material is important and sensitive and needs special protection. Further, the data hierarchical encryption operation is performed based on the target document material to obtain the encrypted document material. In the data hierarchical encryption operation, more complex and secure encryption algorithms are used for high-sensitivity data (for example, parts with data levels of top secret and secret), to ensure the security of the document material data, and relatively simple encryption algorithms can be used for parts with data levels of general. The encryption processing of the document material is used to protect the confidentiality of the data and prevent the data from being tampered with, to ensure the integrity and authenticity of the data. At the same time, different encryption modes are used for data of different data levels, which means that sensitive information will be protected at a higher level, reducing the risk of data leakage or illegal access.

[0066] It can be seen that in the embodiments of the present application, the content distribution of the document material and the data level division strategy are obtained, and based on the content distribution and the data level division strategy, the data sensitivity of the document material is divided to obtain the target document material. Then, the data hierarchical encryption operation is performed based on the target document material to obtain the encrypted document material. The encryption processing of the document material is used to protect the confidentiality of the data and prevent the data from being tampered with, to ensure the integrity and authenticity of the data. At the same time, different encryption modes are used for data of different data levels, which means that sensitive information will be protected at a higher level, reducing the risk of data leakage or illegal access.

[0067] Further, in order to improve the security and integrity of the document, in the embodiments of the present application, watermark embedding analysis is performed based on the encrypted document material to determine the watermark embedding requirement, including:

[0068] The security requirement of the encrypted document material is acquired, the embedding mode analysis is performed based on the security requirement, and the watermark embedding mode is determined, wherein the watermark embedding mode includes visible watermark embedding and invisible watermark embedding.

[0069] For the visible watermark embedding, the position screening is performed based on the content distribution of the encrypted document material, and the watermark embedding position is determined.

[0070] For the invisible watermark embedding, the position screening is performed based on the data sensitivity distribution in the encrypted document material, and the watermark embedding position is determined.

[0071] The watermark embedding mode and the watermark embedding position are comprehensively determined, and the watermark embedding requirement is determined.

[0072] For the embodiments of the present application, different encrypted document materials have different security requirements, the visible watermark and the invisible watermark each have their own applicable scenarios, and the most suitable embedding mode needs to be selected by weighing the pros and cons according to the specific requirements and application scenarios of the encrypted document material. Therefore, the security requirement of the encrypted document material is acquired, the embedding mode analysis is performed based on the security requirement, and the watermark embedding mode is determined. For the embedding mode analysis, the embedding mode analysis is performed according to the corresponding relationship between the security requirement and the embedding mode stored in the electronic device in advance. For example, when the security requirement is explicit identification and warning, that is, the specific attribute (for example, copyright information, prohibition of copying, etc.) of the document needs to be explicitly displayed to the user, the visible watermark embedding mode is selected. The visible watermark embedding can clearly convey important information of the document, and plays a warning and informing role. When the security requirement is to prevent misuse, that is, for some documents that may be misused or abused (for example, drafts and internal materials, etc.), the visible watermark is added to explicitly identify the non-public or temporary nature, and to prevent improper use. When the security requirement is brand promotion, it represents that the enterprise wants to promote the brand while using the document material, so the visible watermark (for example, company logo, slogan, etc.) is added to the document material to improve the brand exposure during the dissemination of the document material. When the security requirement is copyright protection, the invisible watermark embedding mode is adopted. When the document material is distributed and copied, the copyright owner can track and prove the original source of the document by extracting the watermark information, thereby maintaining his own rights. When the security requirement is content authentication, the invisible watermark embedding mode is selected. In some scenarios that need to verify the authenticity of the document (for example, legal documents, contracts, etc.), the invisible watermark is used to verify the integrity and authenticity of the document.

[0073] Then, for visible watermark embedding, based on the content distribution of the encrypted document material, the location and layout of elements in the document material, including but not limited to text, pictures, tables, headers and footers, etc. can be clearly understood, the location screening principle is obtained, and the content analysis and location evaluation of the page are performed according to the location screening principle to determine the watermark embedding location. For the location screening principle, the influence of the visibility of the watermark on the content of the document material and the printing and display effect of the document material are considered, so the watermark is preferentially embedded in the location of the header and footer, blank area, picture background, etc. of the document material to minimize the interference of the watermark on the text content. For invisible watermark embedding, location screening is performed based on the data sensitivity distribution in the encrypted document material to determine the watermark embedding location, that is, the watermark embedding location corresponding to the invisible watermark embedding is the location where the high-sensitive data is located, and the watermark is embedded into the specific sensitive area, which helps to ensure that the information in these areas cannot be tampered with or copied without authorization, improving the security of watermark embedding. Finally, the watermark embedding mode and the watermark embedding location are combined to determine the watermark embedding requirement. Selecting appropriate watermark embedding requirements for the encrypted document material can provide personalized protection and management solutions for different types of document materials, thereby achieving the purposes of preventing misuse, brand promotion, copyright protection, etc., and improving the security and integrity of the document.

[0074] As can be seen, in the embodiments of the present application, different encrypted document materials have different security requirements, and visible watermarks and invisible watermarks each have their own applicable scenarios, and the most suitable embedding mode needs to be selected by weighing the pros and cons according to the specific requirements and application scenarios of the encrypted document material. Therefore, based on the security requirements of the encrypted document material, the embedding mode is analyzed to determine the watermark embedding mode, wherein the watermark embedding mode includes visible watermark embedding and invisible watermark embedding. Then, for visible watermark embedding, location screening is performed based on the content distribution of the encrypted document material to determine the watermark embedding location; for invisible watermark embedding, location screening is performed based on the data sensitivity distribution in the encrypted document material to determine the watermark embedding location. Finally, the watermark embedding mode and the watermark embedding location are combined to determine the watermark embedding requirement.

[0075] Further, in order to be able to discover abnormal permission use behavior in a timely manner, in the embodiments of the present application, after the request permission analysis based on the request identity information and the embedded watermark information in the encrypted document material, it further includes:

[0076] Obtaining the request permission analysis result within the period, performing security evaluation based on the request permission analysis result to obtain a security evaluation result;

[0077] When the security evaluation result is abnormal, performing watermark analysis based on the encrypted watermark document to obtain document publishing information, so as to complete the traceability operation of the document material.

[0078] For the embodiments of the present application, by performing security evaluation on the request permission analysis result, abnormal permission use behavior can be found in time, which helps to prevent the occurrence of security problems such as unauthorized access and permission abuse. Therefore, the request permission analysis result in the acquisition period is obtained, security evaluation is performed based on the request permission analysis result, and a security evaluation result is obtained. The security rules are pre-stored in the electronic device, so the request permission analysis result is compared and evaluated with the security rules. When it is found that the threshold is exceeded or the rules are violated, it is determined that the security evaluation state is abnormal, for example, the request frequency of a certain user is too high, a certain IP address attempts to access unauthorized resources, etc. Otherwise, it is determined that the security evaluation state is normal. When the security evaluation result is abnormal, watermark analysis is performed based on the encrypted watermark document to obtain document publishing information, so as to complete the traceability operation of the document material. That is, based on the encrypted watermark document, the watermark extraction is performed to obtain the to-be-analyzed watermark, and based on the to-be-analyzed watermark, the watermark analysis is performed to obtain the to-be-matched watermark. The to-be-matched watermark is matched with the watermark database to determine the document publisher information, wherein the watermark database is a database storing all watermark information embedded in the document material, and the document publishing information includes but is not limited to: copyright personnel information, publishing time, compiling time, etc.

[0079] It can be seen that in the embodiments of the present application, based on the request permission analysis result in the period, the security evaluation result is obtained, and when the security evaluation result is abnormal, the watermark analysis is performed based on the encrypted watermark document to obtain the document publishing information, so as to complete the traceability operation of the document material. By performing security evaluation on the request permission analysis result, abnormal permission use behavior can be found in time, which helps to prevent the occurrence of security problems such as unauthorized access and permission abuse.

[0080] Further, in the embodiments of the present application, the watermark generation is performed based on the document identification information, the document generation device information and the document operation permission information to obtain the to-be-embedded watermark information, including:

[0081] The document identification information, the document generation device information and the document operation permission information are preprocessed, wherein the preprocessing is used to ensure the accuracy and consistency of the data;

[0082] The preprocessed document identification information, the document generation device information and the document operation permission information are encoded to obtain the to-be-embedded watermark information.

[0083] For the embodiment of the present application, in order to ensure the accuracy and consistency of the data used in the watermark embedding process, preprocessing is performed based on the document identification information, document generation device information and document operation permission information, wherein the preprocessing includes but is not limited to: data cleaning, data verification and data standardization. Data cleaning is used to remove duplicate, erroneous or irrelevant data; data verification is used to verify the integrity and accuracy of the data, for example, checking the uniqueness of the document identification information, the authenticity of the device information, etc.; data standardization is used to convert data from different sources into a unified format and standard. Then, data encoding is performed based on the preprocessed document identification information, document generation device information and document operation permission information to obtain the watermark information to be embedded. For data encoding, a hash function or binary encoding can be selected. For example, SHA-256 or MD5 is used to generate the hash values ​​corresponding to the preprocessed document identification information, document generation device information and document operation permission information, and use them as part of the watermark information to be embedded. The data is encoded using a hash function. Even if the watermark is tampered with, its integrity can be verified by recalculating the hash value. For binary encoding, directly converting the preprocessed document identification information, document generation device information, and document operation permission information into binary data to obtain embedded watermark information offers high flexibility and scalability. Encoding the preprocessed data to obtain the embedded watermark ensures that the document identification information, document generation device information, and document operation permission information contained in the watermark are complete and reliable, which is of great significance for subsequent document traceability, copyright protection, and access control.

[0084] As can be seen, in the embodiments of the present application, preprocessing is performed based on document identification information, document generation device information, and document operation permission information, where preprocessing is used to ensure data accuracy and consistency. Data encoding is then performed based on the preprocessed document identification information, document generation device information, and document operation permission information to obtain the watermark information to be embedded, which is of great significance for subsequent document tracing, copyright protection, and access control.

[0085] Furthermore, to improve the security of the document, in an embodiment of the present application, request authority analysis is performed based on the request identity information and the embedded watermark information in the encrypted document, including:

[0086] Perform role matching based on the request identity information to determine the target role, and perform watermark parsing based on the embedded watermark information to obtain document operation permission information;

[0087] Perform permission matching based on the target role and document operation permission information to obtain the target operation permission;

[0088] The target operation permission is analyzed based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role.

[0089] For the embodiments of the present application, in user permission management, users with similar permission requirements are classified by role allocation, and a unified permission is configured for each role, without the need to separately configure resource authorization for each user, thereby reducing the complexity of permission management. Therefore, role matching is performed based on the request identity information to determine the target role, that is, a role allocation table is pre-set in the electronic device, and the target role is determined based on matching between the role allocation table and the request identity information. At the same time, watermark analysis is performed based on the embedded watermark information to obtain document operation permission information, which records in detail the user permissions possessed by different user roles, so as to avoid illegal access of users without operation permission to the document materials. Then, permission matching is performed based on the target role and the document operation permission information to obtain the target operation permission, wherein the target operation permission is the operation permission of the target role on the document materials. Further, request permission analysis is performed based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role. If the operation request is within the permission range of the target role, the operation is allowed to be performed, and corresponding log information is recorded; if the operation request is beyond the permission range of the target role, the operation is refused to be performed, and a corresponding error prompt or refusal reason is returned. The request permission analysis is performed based on the request identity information corresponding to the operation request and the embedded watermark information in the encrypted document materials, so that only users with operation permission can perform related operations on the encrypted watermark document, thereby improving the security of the document materials.

[0090] It can be seen that in the embodiments of the present application, role matching is performed based on the request identity information to determine the target role, and watermark analysis is performed based on the embedded watermark information to obtain the document operation permission information. Then, permission matching is performed based on the target role and the document operation permission information to obtain the target operation permission. Further, request permission analysis is performed based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role. The request permission analysis is performed based on the request identity information corresponding to the operation request and the embedded watermark information in the encrypted document materials, so that only users with operation permission can perform related operations on the encrypted watermark document, thereby improving the security of the document materials.

[0091] The above embodiments introduce a data processing method of document materials from the perspective of method flow, and the following embodiments introduce a data processing device of document materials from the perspective of virtual module or virtual unit, which will be described in detail below.

[0092] The embodiments of the present application provide a data processing device of document materials, as shown in Fig. 2As shown, the data processing apparatus of the document material can specifically include:

[0093] The watermark generation module 210 is configured to acquire document identification information, document generation device information and document operation permission information, and generate a watermark based on the document identification information, the document generation device information and the document operation permission information to obtain watermark information to be embedded;

[0094] The watermark embedding analysis module 220 is configured to acquire encrypted document material, and perform watermark embedding analysis based on the encrypted document material to determine watermark embedding requirements, wherein the watermark embedding requirements include a watermark embedding position and a watermark embedding manner.

[0095] The embedding module 230 is configured to embed the watermark information to be embedded into the encrypted document material according to the watermark embedding requirements to obtain encrypted watermark document.

[0096] The request permission analysis module 240 is configured to, when detecting an operation request for the encrypted watermark document, acquire request identity information corresponding to the operation request, and perform request permission analysis based on the request identity information and the embedded watermark information in the encrypted document material.

[0097] The operation execution module 250 is configured to, when the operation request does not have operation permission, prohibit the operation request from performing an operation on the encrypted watermark document; and when the operation request has operation permission, perform the operation on the encrypted watermark document according to the operation request.

[0098] For the embodiment of the present application, watermark information to be embedded is obtained based on document identification information, document generation device information and document operation permission information, watermark embedding requirements are determined based on encrypted document material, wherein the watermark embedding requirements include a watermark embedding position and a watermark embedding manner. Then, the watermark information to be embedded is embedded into the encrypted document material according to the watermark embedding requirements to obtain encrypted watermark document. When detecting an operation request for the encrypted watermark document, request permission analysis is performed based on request identity information and the embedded watermark information in the encrypted document material. When the operation request does not have operation permission, the operation request is prohibited from performing an operation on the encrypted watermark document; and when the operation request has operation permission, the operation is performed on the encrypted watermark document according to the operation request. In the watermark generation process, three factors of document, device and permission are comprehensively considered, so that the watermark information to be embedded can control access permission in the propagation process of the document material, prevent unauthorized users from performing illegal operations on the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0099] In one possible implementation of the embodiment of the present application, the data processing apparatus of the document material further includes:

[0100] The hierarchical encryption module is configured to obtain a content distribution of the document material and a data level division strategy, and divide data sensitivity of the document material based on the content distribution and the data level division strategy to obtain target document material, wherein the content of the target document material is divided into different data levels.

[0101] The data hierarchical encryption operation is performed based on the target document material to obtain encrypted document material, wherein the data hierarchical encryption operation uses corresponding encryption modes for data of different data levels.

[0102] In one possible implementation of the embodiment, the watermark embedding analysis module 220 is configured to perform watermark embedding analysis based on the encrypted document material to determine watermark embedding requirements when the watermark embedding analysis is performed.

[0103] The security requirements of the encrypted document material are obtained, and embedding mode analysis is performed based on the security requirements to determine a watermark embedding mode, wherein the watermark embedding mode includes visible watermark embedding and invisible watermark embedding.

[0104] For visible watermark embedding, position screening is performed based on the content distribution of the encrypted document material to determine a watermark embedding position.

[0105] For invisible watermark embedding, position screening is performed based on the data sensitivity distribution in the encrypted document material to determine a watermark embedding position.

[0106] The watermark embedding mode and the watermark embedding position are combined to determine watermark embedding requirements.

[0107] In one possible implementation of the embodiment, the data processing apparatus of the document material further includes:

[0108] The security evaluation module is configured to obtain a request permission analysis result in a period, perform security evaluation based on the request permission analysis result, and obtain a security evaluation result.

[0109] When the security evaluation result is abnormal, watermark analysis is performed based on the encrypted watermark document to obtain document publishing information, so as to complete the traceability operation of the document material.

[0110] In one possible implementation of the embodiment, the watermark generation module 210 is configured to perform watermark generation based on the document identification information, the document generation device information, and the document operation permission information to obtain to-be-embedded watermark information when the watermark generation is performed.

[0111] The document identification information, the document generation device information, and the document operation permission information are preprocessed to ensure the accuracy and consistency of the data.

[0112] Data encoding is performed based on the preprocessed document identification information, document generation device information and document operation permission information, to obtain watermark information to be embedded.

[0113] In one possible implementation of the embodiments of the present application, the request permission analysis module 240 is configured to perform request permission analysis based on the request identity information and the embedded watermark information in the encrypted document material.

[0114] Role matching is performed based on the request identity information to determine a target role, and watermark analysis is performed based on the embedded watermark information to obtain document operation permission information.

[0115] Permission matching is performed based on the target role and the document operation permission information to obtain target operation permission.

[0116] Request permission analysis is performed based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role.

[0117] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described data processing apparatus for document material can refer to the corresponding process in the foregoing method embodiments, which will not be described herein.

[0118] In the embodiments of the present application, an electronic device is provided, as shown in Fig. 3 As shown in Fig. 3 The electronic device 300 shown in the figure includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, such as through a bus 302. Optionally, the electronic device 300 can also include a transceiver 304. It should be noted that in actual applications, the transceiver 304 is not limited to one, and the structure of the electronic device 300 does not constitute a limitation on the embodiments of the present application.

[0119] The processor 301 can be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure content of the present application. The processor 301 can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of DSP and microprocessor, etc.

[0120] The bus 302 can include a path that transmits information between the above-described components. The bus 302 can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 302 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Fig. 3 In the figure, only one thick line is used, but this does not mean that there is only one bus or one type of bus.

[0121] The memory 303 can be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0122] The memory 303 is used to store application program codes for implementing the scheme of the present application, and is controlled by the processor 301 to perform. The processor 301 is used to execute the application program codes stored in the memory 303 to realize the content shown in the foregoing method embodiments.

[0123] The electronic device includes, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (for example, a car navigation terminal), etc., and a fixed terminal such as a digital TV, a desktop computer, etc. It can also be a server, etc. Fig. 3 The electronic device shown is only an example, and should not bring any limitation to the function and use range of the embodiments of the present application.

[0124] The embodiments of the present application provide a computer readable storage medium, which stores a computer program, and when the computer program runs on a computer, the computer can execute the corresponding content in the foregoing method embodiments.

[0125] The embodiment of the application provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to realize the method in any of the above embodiments. Compared with the related art, the embodiment of the application generates a watermark based on document identification information, document generation device information and document operation permission information, obtains to-be-embedded watermark information, and performs watermark embedding analysis based on the encrypted document material to determine watermark embedding requirements, wherein the watermark embedding requirements comprise a watermark embedding position and a watermark embedding mode. Then, the to-be-embedded watermark information is embedded into the encrypted document material according to the watermark embedding requirements, and the encrypted watermark document is obtained. When detecting an operation request for the encrypted watermark document, request permission analysis is performed based on request identity information and the embedded watermark information in the encrypted document material, when the operation request does not have operation permission, the operation request is prohibited to perform operation on the encrypted watermark document, and when the operation request has operation permission, the operation request is performed on the encrypted watermark document. In the watermark generation process, the three factors of the document, the device and the permission are comprehensively considered, so that the to-be-embedded watermark information can control the access permission in the document material propagation process, prevent unauthorized users from performing illegal operation on the document material, improve the security of the document material, and effectively reduce the risk of sensitive information leakage.

[0126] It should be understood that, although each step in the flowchart of the accompanying drawings is displayed in sequence according to the indication of the arrow, these steps are not necessarily executed in sequence according to the indication of the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and they can be executed in other sequences. Moreover, at least part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence is not necessarily sequential, but can be alternately executed with other steps or sub-steps or stages of other steps.

[0127] The above is only some embodiments of the application, and it should be pointed out that, for those skilled in the art, without departing from the principles of the application, some improvements and refinements can be made, which should also be regarded as the protection scope of the application.

Claims

1. A data processing method for stationery, characterized by, The method comprises the following steps: obtaining document identification information, document generation device information and document operation permission information, and generating a watermark based on the document identification information, the document generation device information and the document operation permission information to obtain watermark information to be embedded; obtaining encrypted document materials and performing watermark embedding analysis based on the encrypted document materials to determine watermark embedding requirements, wherein the watermark embedding requirements include watermark embedding positions and watermark embedding methods; embedding the watermark information to be embedded into the encrypted document materials according to the watermark embedding requirements to obtain encrypted watermark documents; when an operation request for the encrypted watermark document is detected, obtaining request identity information corresponding to the operation request, and performing request permission analysis based on the request identity information and the embedded watermark information in the encrypted document materials; when the operation request does not have operation permission, the operation request is prohibited from performing operation on the encrypted watermark document; when the operation request has operation permission, the operation request is performed on the encrypted watermark document according to the operation request; Before the encrypted document materials are obtained, the following steps are further included: obtaining content distribution and data level division strategy of the document materials, and dividing the data sensitivity of the document materials based on the content distribution and the data level division strategy to obtain target document materials, wherein the content of the target document materials is divided into different data levels; performing data hierarchical encryption operation based on the target document materials to obtain encrypted document materials, wherein the data hierarchical encryption operation uses corresponding encryption methods for data of different data levels; The watermark embedding analysis based on the encrypted document materials to determine the watermark embedding requirements comprises the following steps: obtaining security requirements of the encrypted document materials, and performing embedding method analysis based on the security requirements to determine the watermark embedding method, wherein the watermark embedding method includes visible watermark embedding and invisible watermark embedding; for the visible watermark embedding, the position is selected based on the content distribution of the encrypted document materials to determine the watermark embedding position; for the invisible watermark embedding, the position is selected based on the data sensitivity distribution in the encrypted document materials to determine the watermark embedding position; The watermark embedding requirements are determined by comprehensively considering the watermark embedding method and the watermark embedding position.

2. The data processing method for office materials according to claim 1, characterized by, After the request permission analysis based on the request identity information and the embedded watermark information in the encrypted document materials, the following steps are further included: obtaining request permission analysis results within a period, performing security evaluation based on the request permission analysis results to obtain security evaluation results; when the security evaluation result is abnormal, performing watermark analysis based on the encrypted watermark document to obtain document publishing information, so as to complete the traceability operation of the document materials.

3. The data processing method for office materials according to claim 1, characterized by, The watermark generation based on the document identification information, the document generation device information and the document operation permission information to obtain the watermark information to be embedded comprises the following steps: Preprocessing based on the document identification information, the document generation device information and the document operation permission information, wherein the preprocessing is used to ensure the accuracy and consistency of the data; Data encoding based on the preprocessed document identification information, document generation device information and document operation permission information, to obtain the to-be-embedded watermark information.

4. The data processing method for office materials according to claim 1, characterized by, The request permission analysis based on the request identity information and the embedded watermark information in the encrypted document material includes: Role matching based on the request identity information to determine a target role, and watermark analysis based on the embedded watermark information to obtain the document operation permission information; Permission matching based on the target role and the document operation permission information to obtain a target operation permission; Request permission analysis based on the target operation permission and the operation request to determine whether the operation request is within the permission range corresponding to the target role.

5. An electronic device, comprising: Comprise: At least one processor; Memory; At least one application program, wherein the at least one application program is stored in the memory and is configured to be executed by the at least one processor, and the at least one application program is configured to execute the data processing method of the document material according to any one of claims 1-4.

6. A computer-readable storage medium, characterized in that, A computer program is stored thereon, which makes the computer execute the data processing method of the document material according to any one of claims 1-4 when the computer program is executed in the computer.

7. A computer program product, characterised in that, A computer program is stored thereon, which makes the computer execute the data processing method of the document material according to any one of claims 1-4 when the computer program is executed in the computer.

Citation Information

Patent Citations

  • Method for identifying watermarks in PDF document

    CN107194390A

  • Electronic file management method and device, electronic equipment and storage medium

    CN117874316A