Electronic seal stamping method, device, storage medium and server
By assessing risk levels through risk control models and dynamically adjusting authorization strategies, the low efficiency and security risk issues caused by frequent electronic seal verification are resolved, and an efficient and secure electronic seal stamping process is implemented, ensuring the authenticity and traceability of the seal.
Patent Information
- Application Number
- CN202411359325.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-09-27
AI Technical Summary
In the existing technology, the frequent identity verification process of electronic seals leads to low operational efficiency. At the same time, the loose authorization mechanism increases security risks and cannot effectively manage seal usage rights, threatening the authenticity and legal effectiveness of document content.
A pre-trained risk control model is used to assess the risk level of the stamped environment data, and the authorization strategy is dynamically adjusted according to the level. No authentication authorization is required under low risk, and identity authentication or physical key device verification is performed under medium and high risk, and an electronic seal is stamped through the blockchain system.
It simplifies the operation process while ensuring security, improves processing efficiency, reduces labor costs, ensures the authenticity and traceability of the seal, and reduces the risk of misoperation and illegal use.
Smart Images

Figure CN119293867B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security, and in particular to a method, device, storage medium and server for affixing an electronic seal. Background Art
[0002] With the accelerating pace of digitalization, the application of electronic seals is becoming increasingly widespread, demonstrating significant advantages in improving document processing efficiency and convenience. However, before officially applying an electronic seal to a document, the system's rigorous user identity verification process is crucial for ensuring the authenticity and legitimacy of the transaction. Faced with the need for large-scale document stamping, the frequent identity verification process undoubtedly becomes a major bottleneck restricting operational efficiency, increasing user time costs and system processing burdens.
[0003] To address this issue, simply adopting a one-time authorization mechanism, allowing users unlimited use of electronic seals within a specific time period, while improving operational efficiency to a certain extent, inevitably raises serious security concerns. This lax control approach may weaken the meticulous management of seal usage rights, increase the risk of unauthorized access or misuse, and thus threaten the authenticity and legal validity of document content. Summary of the Invention
[0004] The present invention provides a method, device, storage medium, and server for affixing an electronic seal, which can solve the problem of low accuracy of long-term prediction results of offline training models in the prior art. The technical solution is as follows:
[0005] In a first aspect, an embodiment of the present application provides a method for affixing an electronic seal, the method comprising:
[0006] When receiving a user's request for stamping a formatted document, collecting the user's stamping environment data; the stamping request carries the identification of the target electronic seal;
[0007] Using a pre-trained risk control model to process the stamping environment data to obtain a risk level;
[0008] When the risk level is a low risk level, determining whether the user has permission to use the target electronic seal according to the user's authentication-free authorization rules; if so, obtaining a pre-stored authorization code associated with the user, querying the target electronic seal in the blockchain system according to the authorization code, and stamping the queried target electronic seal on the format file;
[0009] When the risk level is a medium risk level, the user is authenticated, and after the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the format file;
[0010] When the risk level is high, the user is prompted to insert the physical key device. After establishing a communication connection with the physical key device, the user is authenticated. After the authentication is passed, the target electronic seal is read in the physical key device, and the read target electronic seal is stamped on the layout file.
[0011] In a second aspect, an embodiment of the present application provides a device for stamping an electronic seal, the device comprising:
[0012] The collecting unit is used to collect the user's seal environment data when receiving the user's seal request for the format document; the seal request carries the identification of the target electronic seal;
[0013] An evaluation unit, configured to process the stamping environment data using a pre-trained risk control model to obtain a risk level;
[0014] a stamping unit, configured to, when the risk level is a low risk level, determine, based on the user's authentication-free authorization rules, whether the user has permission to use the target electronic seal; if so, obtain a pre-stored authorization code associated with the user, query the target electronic seal in the blockchain system based on the authorization code, and stamp the queried target electronic seal on the format file;
[0015] When the risk level is a medium risk level, the user is authenticated, and after the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the format file;
[0016] When the risk level is high, the user is prompted to insert the physical key device. After establishing a communication connection with the physical key device, the user is authenticated. After the authentication is passed, the target electronic seal is read in the physical key device, and the read target electronic seal is stamped on the layout file.
[0017] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.
[0018] In a fourth aspect, an embodiment of the present application provides a server, which may include: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.
[0019] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:
[0020] Using pre-trained risk control models, we analyze stamping environment data, assess risk levels in real time, and effectively identify and prevent potential security threats and non-compliant operations. This mechanism ensures that electronic seals are used under strict supervision, reducing the risk of misuse and illegal use.
[0021] Authorization policies are dynamically adjusted based on risk levels. In low-risk scenarios, stamping operations are quickly executed based on authentication-free authorization rules, greatly simplifying the process and improving processing efficiency. In medium- and high-risk scenarios, appropriate identity verification measures are implemented to ensure user authenticity, further ensuring operational security while avoiding unnecessary steps and maintaining a positive user experience.
[0022] By querying and stamping the target electronic seal through the blockchain system, not only the authenticity and non-tamperability of the seal are ensured, but also the traceability of operation records is achieved, providing strong technical support for subsequent audits and supervision.
[0023] Throughout the entire process, except for high-risk scenarios where users may be required to insert a physical key device, most operations are automated, reducing the need for manual review and intervention, lowering labor costs, and improving the level of automation in business processing. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0025] Figure 1 This is a schematic diagram of the network architecture provided by the embodiment of the present application;
[0026] Figure 2 1 is a flow chart of a method for affixing an electronic seal provided in an embodiment of the present application;
[0027] Figure 3 This is a structural diagram of an electronic seal stamping device provided by the present application;
[0028] Figure 4 This is a structural diagram of a server provided by this application. DETAILED DESCRIPTION
[0029] In order to make the objectives, technical solutions and advantages of the present application clearer, the embodiments of the present application will be described in further detail below with reference to the accompanying drawings.
[0030] It should be noted that the electronic seal stamping method provided in this application is generally executed by a server, and accordingly, the electronic seal stamping device is generally set in the server.
[0031] Figure 1 An exemplary system architecture that can be applied to the electronic seal affixing method or the electronic seal affixing device of the present application is shown.
[0032] like Figure 1 As shown, the system architecture may include: a terminal device 101 and a server 102. The terminal device 101 and the server 102 may communicate via a network, which is used as a medium for providing communication links between the above-mentioned units. The network may include various types of wired communication links or wireless communication links, for example: wired communication links include optical fibers, twisted pairs, or coaxial cables, and wireless communication links include Bluetooth communication links, wireless fidelity (Wi-Fi) communication links, or microwave communication links.
[0033] The terminal device 101 displays the layout file. When the layout file needs to be stamped with a target electronic seal, the terminal device 101 sends a stamping request to the server 102. The server 102 executes the stamping method of the present application in response to the stamping request.
[0034] It should be noted that the terminal device 101 and the server 102 can be hardware or software. When the terminal device 101 and the server 102 are hardware, they can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When the terminal device 101 and the server 102 are software, they can be implemented as multiple software or software modules (for example, to provide distributed services), or as a single software or software module, without specific limitation herein.
[0035] Various communication client applications can be installed on the terminal device of this application, such as: video recording applications, video playback applications, voice interaction applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0036] The terminal device can be either hardware or software. When the terminal device is hardware, it can be various terminal devices with a display screen, including but not limited to smartphones, tablet computers, laptop computers, and desktop computers. When the terminal device is software, it can be installed in the terminal devices listed above. It can be implemented as multiple software or software modules (for example, to provide distributed services), or it can be implemented as a single software or software module, which is not specifically limited here.
[0037] When the terminal device is hardware, it may also be equipped with a display device and a camera. The display device can be any device capable of displaying a video, and the camera is used to capture video streams. For example, the display device may be a cathode ray tube display (CR), a light-emitting diode display (LED), an electronic ink screen, a liquid crystal display (LCD), or a plasma display panel (PDP). Users can use the display device on the terminal device to view displayed text, images, videos, and other information.
[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers in the embodiment is only illustrative. Any number of terminal devices, networks, and servers may be used as needed.
[0039] The following will be combined with the Figure 2 , the electronic seal stamping method provided by the embodiment of the present application is described in detail. Among them, the electronic seal stamping device in the embodiment of the present application can be Figure 1 The server shown.
[0040] See Figure 2 , provides a flow chart of a method for stamping an electronic seal according to an embodiment of the present application. Figure 2 As shown, the method of the embodiment of the present application may include the following steps:
[0041] S201. When receiving a user's request for stamping a format file, collecting the user's stamping environment data.
[0042] Among them, the data collection module built into or called by the server should be able to capture the network requests and related metadata issued by the user device in real time. These data include but are not limited to the User-Agent in the HTTP request header (used to identify the device type and operating system), X-Forwarded-For (used to identify the original IP address, if it passes through a proxy), Referer (used to track the source of the request), etc. If the user device supports GPS or network positioning, the server can obtain approximate geographic location information through IP address resolution services (such as IPinfo, MaxMind, etc.). For more precise positioning needs, the user device may need to provide location information directly. The server records the exact timestamp of the request arrival for subsequent analysis of user behavior patterns and operation frequencies. Although it is difficult to directly obtain the system environment parameters of the user device, the server can infer the browser type, version and operating system that the user may use by analyzing the User-Agent string.
[0043] In some embodiments of the present application, the stamping environment data includes: user behavior data, file content data of the format file, file type data and user history security data.
[0044] User behavior data records a series of user actions during operation, such as login time, operation frequency, and IP address changes. This data helps identify unusual behavior patterns, such as multiple stamp attempts within a short period of time or frequent logins from different locations, which may represent potential security risks. By analyzing user behavior data, the system can adjust the risk level in real time and require additional user authentication when necessary.
[0045] File content data is the core of a formatted document, encompassing the specific content and format of the document. During the stamping process, the system may need to check whether the document content meets specific requirements (such as file type, size limit, sensitive word detection, etc.) to ensure the legality and security of the document content. Furthermore, for certain sensitive documents, the system may need to use encryption, watermarking, and other technical means to protect the document content from illegal copying or tampering.
[0046] File type data refers to the file format and type information, such as PDF, Word, or images. Different file types may require different processing methods and security policies. Based on this file type data, the system automatically selects the appropriate stamping tool and method to ensure accuracy and consistency in stamping operations. Furthermore, for certain file types that don't support direct stamping, the system can prompt the user to convert them or take other measures.
[0047] User historical security data records past user operations and security behaviors, such as successful and failed login attempts, violations, and security training completion status. This data helps the system gain a comprehensive understanding of users' security awareness and behavioral habits. By analyzing historical user security data, the system can conduct risk assessments and categorize user management, providing differentiated security policies and permission settings for users of different risk levels. Furthermore, the system can dynamically adjust based on historical user performance to address potential security threats.
[0048] S202: Use a pre-trained risk control model to process the stamping environment data to obtain a risk level.
[0049] Among them, the risk control model used by the server may be built based on logistic regression, random forest, gradient boosting tree (GBDT) or deep learning algorithms (such as neural networks). The choice of model depends on the characteristics of the data and the expected accuracy and recall rate. Before inputting the environmental data into the model, feature engineering processing is required, including data cleaning (removing noise and outliers), feature selection (retaining features that contribute to risk assessment), feature scaling (such as normalization, standardization), etc. Model training uses a large amount of historical data, including known security incidents and normal operation data. By iteratively optimizing the algorithm and adjusting the model parameters, the model can accurately identify potential security threats. In order to improve the transparency and interpretability of the model, technologies such as LIME (Local Interpretability Model-agnostic Explanation) may be used to explain the model output to help understand which features contribute most to the risk assessment results.
[0050] In some embodiments of the present application, multiple data points are collected and clustered into K clusters using the K-means clustering algorithm. The distance between each data point and the center of its cluster is calculated. Data points with a distance greater than a threshold are marked as abnormal. A logistic regression model is then used to generate a sample dataset using the clustered data points with the abnormality mark. The sample dataset is then used to train a risk control model. The threshold is equal to the mean of the distance plus twice the standard deviation.
[0051] Collect user behavior (login location, IP address, device type, login time, etc.), file content (confidentiality, seal holder, seal type, etc.), business type (important financial documents, ordinary documents, etc.), and historical data (user's historical seal behavior, historical security events, etc.). Remove duplicate data, process missing values, outliers, etc. to ensure data quality. Extract labels for working hours and non-working hours from login time. Convert file content data (such as confidentiality, seal type) into numerical or categorical labels. Count the frequency of behaviors, number of events, etc. in historical data and convert them into features that the model can understand.
[0052] Use business knowledge, the Elbow Method, or the Silhouette Score to determine the number of clusters (K value). The choice of K value should be based on the characteristics of the data and business needs. Apply the K-means clustering algorithm to cluster the data and assign the data points to K clusters so that the similarity of data points within the same cluster is high, while the similarity of data points between different clusters is low. Calculate the distance from each data point to the center of the cluster to which it belongs. Set a threshold (such as the mean of all distances plus twice the standard deviation) and mark data points whose distance exceeds this threshold as abnormal. Identify a subset of abnormal features from the clustering algorithm, use this subset as an additional feature, input it into the logistic regression model, and train the logistic regression model.
[0053] Model training:
[0054] A. Perform data splitting to divide the dataset into training set and test set to evaluate model performance.
[0055] B. Feature scaling, standardize the features.
[0056] C. Select the logistic regression model and use the training dataset to train the model.
[0057] Model evaluation and validation:
[0058] A. Use the test dataset to evaluate model performance. Common indicators include accuracy, AUC, etc.
[0059] Model deployment:
[0060] A. Deploy the trained model to the electronic signature processing system to assess the transaction risk of electronic signatures in real time. Set risk score thresholds and implement corresponding signature authorization policies based on the risk scores.
[0061] B. Update the model regularly and continuously optimize it to ensure that the model can adapt to new business data changes.
[0062] When a signature request occurs, the intelligent risk control model analyzes the risk level of the signature request and outputs the probability of an abnormal transaction. An example is shown below:
[0063] fraud: 0-normal transaction, 1-abnormal transaction
[0064] fraud_probability: predicted probability
[0065] Based on the output abnormal transaction probability, use the formula: Risk score = abnormal transaction predicted probability * 100 to obtain the risk control model score.
[0066] Through the above steps, we can effectively use the K-means clustering algorithm and logistic regression classification model to train the risk model to improve the risk assessment ability of trading behavior.
[0067] S203. When the risk level is low, determine whether the user has the right to use the target electronic seal according to the user's authentication-free authorization rules. If yes, obtain the pre-stored authorization code associated with the user, query the target electronic seal in the blockchain system according to the authorization code, and stamp the queried target electronic seal on the layout file.
[0068] When the risk control model determines the risk level is low, the server first retrieves and parses the current user's authorization-free authentication rules from the database. These rules should clearly specify conditions such as the validity period, business type, approval process, and unit type. The server then checks whether the current time falls within the validity period specified in the user's authorization-free authentication rules. If the current time is not within this range, the stamping request is rejected and the user is notified that the authorization-free authentication rule has expired.
[0069] The server then verifies whether the business type in the current stamp request matches the business type specified in the user's authorization exemption rules. It also checks whether the approval process in the request also meets the approval process requirements specified in the rules. The server also verifies whether the unit type involved in the request is consistent with the unit type specified in the user's authorization exemption rules.
[0070] If all of the above conditions are met—that is, the current time is within the valid time range, and the business type, approval process, and organization type all match the user's authorization-free rules—the server deems the user authorized to use the electronic seal without authentication. The server then obtains the authorization code from the user's initial authentication screen and uses it to query the blockchain for the target electronic seal's details. Once the seal information is verified, the server performs the stamping operation, affixing the electronic seal to the layout document as a digital signature.
[0071] In some embodiments of the present application, the authorization-free authentication rules are refined to include multiple specific conditions, which together determine whether the user can perform the stamping operation without additional identity verification. The following is a detailed explanation of these authorization-free authentication rules:
[0072] The current date is within the preset effective date range:
[0073] This condition requires the system to check whether the current date falls within the effective date range specified in the rule. For example, a rule might specify that the user has authorization-free access from a certain date to another date. If the current date is not within this range, the user will be required to authenticate.
[0074] Whether the current approval link is the preset approval link:
[0075] Approval processes typically consist of multiple steps, each with specific responsible individuals and permissions. This condition requires the system to verify whether the current approval step is one of the steps defined in the rules that allow unauthorized access. If the current step is not within the specified range, the user will need to follow the normal approval process for identity verification.
[0076] The current business type is the preset business type:
[0077] Different business types may involve different security requirements and operational procedures. This condition ensures that only certain types of business are allowed to perform unauthorized operations. The system needs to verify whether the business type currently being requested matches the business type preset in the rule.
[0078] The current unit is the preset unit:
[0079] In some cases, authorization-free permissions may be limited to users in a specific organization or department. This condition requires the system to check whether the user initiating the request belongs to the organization or department specified in the rule. If the user's organization does not meet the requirements, identity verification is required.
[0080] The application ID currently used by the user's device is the preset application ID:
[0081] To ensure operational security, the system may restrict authorization-free access to requests initiated through specific apps or channels. This condition requires the system to verify that the app ID currently used by the user's device matches the app ID specified in the rule. This helps prevent unauthorized third-party apps or scripts from impersonating user operations.
[0082] In practice, these authorization-free authentication rules can be flexibly configured based on an organization's specific needs and security policies. When a user initiates a stamping request, the system automatically checks to see if all these rules are met. Only when all conditions are met will the system allow the user to proceed with the authorization-free stamping operation and record the corresponding operation log for subsequent audit and tracking.
[0083] In addition, to further improve the security and flexibility of the system, users can also regularly review and update authorization-free authentication rules to adapt to business changes and new trends in security threats.
[0084] S204. When the risk level is medium, the user's identity is authenticated. After the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the layout file.
[0085] Among them, the server supports multi-factor authentication mechanisms, such as combining username and password, SMS verification code, email verification or biometric technology (such as fingerprint, facial recognition) for authentication. During the verification process, the server should ensure that all sensitive information is transmitted through an encrypted channel. The server creates a unique session identifier (Session ID) for each authenticated user and verifies the validity of the identifier in subsequent requests. The session identifier should be updated regularly or expire to prevent session hijacking attacks. After the identity authentication is passed, the server stamps the electronic seal on the layout file according to the process in S203
[0086] S205. When the risk level is high, the user is prompted to insert the physical key device. After the communication connection with the physical key device is established, the user's identity is authenticated. After the authentication is passed, the target electronic seal is read from the physical key device, and the read target electronic seal is stamped on the layout file.
[0087] The server establishes a communication connection with the physical key device via a USB interface or network protocol (such as PC / SC, FIDO2, etc.). During the communication process, the server should verify the authenticity and legitimacy of the device to prevent man-in-the-middle attacks. The physical key device has a built-in private key for signing the electronic seal. The server sends the data to be signed (such as the hash value of the layout file) to the device, which uses the private key to sign and return the signature result to the server. The server verifies the signature result using the public key stored in the blockchain to ensure the authenticity and integrity of the signature. After verification, the server stamps the electronic seal on the layout file in the form of a digital signature.
[0088] In some embodiments of the present application, before S201, the method further includes:
[0089] Authenticate the user for the first time;
[0090] After the first verification is passed, the authorization code of the target electronic seal is queried in the blockchain system;
[0091] Configure authorization-free authentication rules for the user.
[0092] The user submits a login request, providing a username and password (or other authentication methods, such as biometrics, dynamic tokens, and SMS). The system verifies that the identity information submitted by the user is valid and accurate. If authentication fails, the user is denied access and prompted accordingly. If authentication succeeds, the system proceeds to the next steps.
[0093] After identity authentication is passed, the system needs to confirm whether the user has the right to use the target electronic seal. This can be achieved by querying the authorization code of the target electronic seal in the blockchain system, because the blockchain is tamper-proof and transparent, and is suitable for storing and verifying such sensitive information. The system initiates a query request in the blockchain system based on the target electronic seal ID requested by the user. The blockchain system returns the authorization code of the target electronic seal and its related information (such as authorization time, authorized user, etc.). The system verifies whether the user matches the authorization information recorded in the blockchain. If it matches, the user is allowed to perform subsequent operations; if it does not match, the user access is denied and a corresponding prompt is given. In order to improve user experience and efficiency, this application configures authorization-free authentication rules for specific users or specific scenarios to ensure that these users or scenarios can skip the above-mentioned identity authentication and authorization code query steps when specific conditions are met.
[0094] System administrators configure authorization-free authentication rules for users or scenarios based on business needs and security policies. These rules may include factors such as user level, operation time, operation location, and operation type. When a user initiates a request, the system first checks whether the authorization-free authentication rules are met. If so, the identity verification and authorization code query steps are skipped. If not, the normal verification and query process continues.
[0095] In some embodiments of the present application, the risk level is represented by a risk score. When the risk score output by the risk control model is less than a preset first threshold, the business or transaction is considered low risk. When the risk score is between the first threshold and the second threshold, the business or transaction is classified as medium risk. When the risk score is greater than the second threshold, the business or transaction is considered high risk. For example, the first threshold is 60 points and the second threshold is 80 points.
[0096] The embodiments of the present application have the following beneficial effects when affixing an electronic seal to a format document:
[0097] Using pre-trained risk control models, we analyze stamping environment data, assess risk levels in real time, and effectively identify and prevent potential security threats and non-compliant operations. This mechanism ensures that electronic seals are used under strict supervision, reducing the risk of misuse and illegal use.
[0098] Authorization policies are dynamically adjusted based on risk levels. In low-risk scenarios, stamping operations are quickly executed based on authentication-free authorization rules, greatly simplifying the process and improving processing efficiency. In medium- and high-risk scenarios, appropriate identity verification measures are implemented to ensure user authenticity, further ensuring operational security while avoiding unnecessary steps and maintaining a positive user experience.
[0099] By querying and stamping the target electronic seal through the blockchain system, not only the authenticity and non-tamperability of the seal are ensured, but also the traceability of operation records is achieved, providing strong technical support for subsequent audits and supervision.
[0100] Throughout the entire process, except for high-risk scenarios where users may be required to insert a physical key device, most operations are automated, reducing the need for manual review and intervention, lowering labor costs, and improving the level of automation in business processing.
[0101] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0102] See Figure 3, which shows a schematic diagram of the structure of an electronic seal affixing device provided by an exemplary embodiment of the present application, hereinafter referred to as device 3. Device 3 can be implemented as all or part of a server through software, hardware, or a combination of both. Device 3 includes: a collection unit 301, an evaluation unit 302, and a stamping unit 303.
[0103] The collecting unit is used to collect the user's seal environment data when receiving the user's seal request for the format document; the seal request carries the identification of the target electronic seal;
[0104] An evaluation unit, configured to process the stamping environment data using a pre-trained risk control model to obtain a risk level;
[0105] a stamping unit, configured to, when the risk level is a low risk level, determine, based on the user's authentication-free authorization rules, whether the user has permission to use the target electronic seal; if so, obtain a pre-stored authorization code associated with the user, query the target electronic seal in the blockchain system based on the authorization code, and stamp the queried target electronic seal on the format file;
[0106] When the risk level is a medium risk level, the user is authenticated, and after the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the format file;
[0107] When the risk level is high, the user is prompted to insert the physical key device. After establishing a communication connection with the physical key device, the user is authenticated. After the authentication is passed, the target electronic seal is read in the physical key device, and the read target electronic seal is stamped on the layout file.
[0108] In one or more possible embodiments, it further includes:
[0109] Configuration unit, used to authenticate the user for the first time;
[0110] When the initial identity verification is passed, the authorization code of the target electronic seal is queried in the blockchain system;
[0111] Configure authorization-free authentication rules for the user.
[0112] In one or more possible embodiments, it further includes:
[0113] The training unit is used to train the above risk model using the K-mean clustering algorithm and the logistic regression classification model.
[0114] In one or more possible embodiments, the authentication-free authorization rule includes:
[0115] The current date is within the preset effective date range;
[0116] Whether the current approval link is the preset approval link;
[0117] The current business type is the preset business type;
[0118] The current unit is the preset unit; and
[0119] The application ID currently used by the user device is the preset application ID.
[0120] In one or more possible embodiments, the stamping environment data includes: user behavior data, file content data of the format file, file type data, and user history security data.
[0121] In one or more possible embodiments, the risk control model outputs a risk score;
[0122] When the risk score is less than the first threshold, it is determined to be a low risk level;
[0123] When the risk score is between the first threshold and the second threshold, it is determined to be a medium risk level;
[0124] When the risk score is greater than the second threshold, it is determined to be a high risk level.
[0125] In one or more possible embodiments, the user identity is verified through SMS verification.
[0126] It should be noted that the device 3 provided in the above embodiment, when performing the electronic seal affixing method, is only illustrated by the division of the above functional modules. In actual application, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the above functions. In addition, the electronic seal affixing device provided in the above embodiment and the electronic seal affixing method embodiment are based on the same concept. The implementation process is detailed in the method embodiment and will not be repeated here.
[0127] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0128] The present application also provides a computer storage medium that can store multiple instructions, which are suitable for being loaded and executed by a processor as described above. Figure 2 The method steps of the embodiment shown, the specific execution process can be found in Figure 2 The detailed description of the illustrated embodiment will not be repeated here.
[0129] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the electronic seal affixing method as described in the above embodiments.
[0130] See Figure 4 , provides a structural diagram of a server according to an embodiment of the present application. Figure 4 As shown, the server 400 may include: at least one processor 401 , at least one network interface 404 , a user interface 403 , a memory 405 , and at least one communication bus 402 .
[0131] The communication bus 402 is used to implement the connection and communication between these components.
[0132] The user interface 403 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 403 may also include a standard wired interface and a wireless interface.
[0133] The network interface 404 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0134] The processor 401 may include one or more processing cores. The processor 401 utilizes various interfaces and lines to connect the various components within the server 400. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 405, and calling data stored in the memory 405, the processor 401 performs various functions of the server 400 and processes data. Optionally, the processor 401 may be implemented in the form of at least one hardware component selected from the group consisting of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 401 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; and the modem is used to handle wireless communications. It is understood that the modem may not be integrated into the processor 401 and may be implemented separately on a single chip.
[0135] Among them, the memory 405 may include a random access memory (Random Access Memory, RAM) and may also include a read-only memory (Read-Only Memory). Optionally, the memory 405 includes a non-transitory computer-readable storage medium. The memory 405 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 405 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 405 may also be optionally at least one storage device located away from the aforementioned processor 401. As Figure 4 As shown, the memory 405 as a computer storage medium may include an operating system, a network communication module, a user interface module, and an application program.
[0136] exist Figure 4 In the server 400 shown, the user interface 403 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 401 can be used to call the application stored in the memory 405 and specifically execute the following Figure 2 The specific process can be referred to the method shown in Figure 2 As shown, no further details are given here.
[0137] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory, or a random access memory.
[0138] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A method for stamping an electronic seal, characterized in that: include: When receiving a user's request for stamping a format file, collecting the user's stamping environment data; The stamping request carries the identification of the target electronic seal; Using a pre-trained risk control model to process the stamping environment data to obtain a risk level; When the risk level is a low risk level, determining whether the user has permission to use the target electronic seal according to the user's authentication-free authorization rules; if so, obtaining a pre-stored authorization code associated with the user, querying the target electronic seal in the blockchain system according to the authorization code, and stamping the queried target electronic seal on the layout file; When the risk level is a medium risk level, the user is authenticated, and after the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the format file; When the risk level is high, the user is prompted to insert the physical key device. After establishing a communication connection with the physical key device, the user is authenticated. After the authentication is passed, the target electronic seal is read in the physical key device, and the read target electronic seal is stamped on the layout file.
2. The method according to claim 1, characterized in that When receiving a user's request for stamping a format file, before collecting the user's stamping environment data, the method further includes: Authenticate the user for the first time; When the initial identity verification is passed, the authorization code of the target electronic seal is queried in the blockchain system; Configure authorization-free authentication rules for the user.
3. The method according to claim 1, characterized in that Also includes: The above risk model is trained using K-mean clustering algorithm and logistic regression classification model.
4. The method according to claim 1, wherein The authentication-free authorization rules include: The current date is within the preset effective date range; Whether the current approval link is the preset approval link; The current business type is the preset business type; The current unit is the preset unit; and The application ID currently used by the user device is the preset application ID.
5. The method according to claim 1, wherein The stamping environment data includes: user behavior data, file content data of the format file, file type data and user history security data.
6. The method according to claim 1, characterized in that The risk control model outputs a risk score; When the risk score is less than the first threshold, it is determined to be a low risk level; When the risk score is between the first threshold and the second threshold, it is determined to be a medium risk level; When the risk score is greater than the second threshold, it is determined to be a high risk level.
7. The method according to claim 1, characterized in that Verify user identity through SMS verification.
8. An electronic seal stamping device, characterized in that: include: A collection unit, configured to collect the user's seal environment data upon receiving a user's seal request for a format file; The stamping request carries the identification of the target electronic seal; An evaluation unit, configured to process the stamping environment data using a pre-trained risk control model to obtain a risk level; a stamping unit, configured to, when the risk level is a low risk level, determine, based on the user's authentication-free authorization rules, whether the user has permission to use the target electronic seal; if so, obtain a pre-stored authorization code associated with the user, query the target electronic seal in the blockchain system based on the authorization code, and stamp the queried target electronic seal on the format file; When the risk level is a medium risk level, the user is authenticated, and after the authentication is passed, the target electronic seal is searched in the blockchain system, and the searched target electronic seal is stamped on the format file; When the risk level is high, the user is prompted to insert the physical key device. After establishing a communication connection with the physical key device, the user is authenticated. After the authentication is passed, the target electronic seal is read in the physical key device, and the read target electronic seal is stamped on the layout file.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 7.
10. A server, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method steps according to any one of claims 1 to 7.
Citation Information
Patent Citations
User identity verification method and device, electronic equipment and computer storage medium
CN117688539A
Smart home remote monitoring data sharing authentication system with multi-level verification
CN118590245A