A security management system and method for archival information
By performing segmented processing and progressive transmission of archive information, combined with security assessment, the security and efficiency problems in the transmission of archive information are solved, and efficient and secure information transmission is achieved.
Patent Information
- Application Number
- CN202411454605.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-10-17
AI Technical Summary
In the prior art, the archive information has insufficient security during transmission and low transmission efficiency, especially when it is attacked.
The archive information is processed in segments, an information data transmission link is constructed, and a progressive transmission symbol is generated through the information data nodes. The management strategy is implemented in combination with the security evaluation results to ensure the security and efficiency of the transmission process.
It improves the security and efficiency of archive information transmission, can identify and deal with internal and external abnormalities, and ensures information integrity and security.
Smart Images

Figure CN119363408B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information interaction, and specifically to a security management system and method for archival information. Background Art
[0002] As the precipitation and accumulation of history, archives provide the most fundamental basis for the development of humanity. With the continuous update and development of modern technologies, the management of archival data has gradually tended towards digitization and informatization. Archives are often important information documents of some companies, enterprises or individuals, and the security management of archives is of crucial importance. The storage of electronic archives is related to the security of archival information.
[0003] In the prior art, the security management of archives mostly adopts storing the archives in the storage unit of an intelligent terminal and then setting permission passwords for the electronic archives. Although this security management of electronic archives is secure, once the system is attacked during the transmission of archival information and the document security permissions are changed, all the information in the electronic archives will be lost. How to improve the transmission security during the transmission of archival information and how to further improve the transmission efficiency of archives while improving security? For this reason, a security management method for archival information is provided herein. Summary of the Invention
[0004] In order to solve the above technical problems, the purpose of the present invention is to provide a security management method for archival information, including the following steps:
[0005] Step S1: Preprocess the archival information data to be transmitted to obtain corresponding archival information data segments;
[0006] Step S2: Construct an information data transmission link composed of several information data nodes, and sequentially transmit the archival information data segments through the information data nodes for progressive transmission;
[0007] Step S3: Perform information data security assessment on the archival information data segments that have completed progressive transmission, and execute corresponding management strategies on the archival information data according to the information data security assessment results.
[0008] The process of preprocessing the archival information data to be transmitted to obtain corresponding archival information data segments includes:
[0009] Classify the archival information data to be transmitted to obtain corresponding archival information data types, and the archival information data types include primary archival information data, secondary archival information data, and tertiary archival information data;
[0010] Segment different types of archival information data respectively to obtain corresponding archival information data segments, and number the archival information data segments.
[0011] Furthermore, the process of constructing an information data transmission link composed of several information data nodes includes:
[0012] Set up an archive management library;
[0013] The information data node is a transmission node in the process of a user uploading an archive information data segment to the archive management library;
[0014] Set the level of the information data node;
[0015] Classify all the information data nodes on all the information data transmission links;
[0016] The information data transmission link is a transmission path formed by a user uploading an archive information data segment to the archive management library through several information data nodes, and the information data nodes forming the transmission path are associated.
[0017] Furthermore, the process of sequentially transmitting an archive information data segment through information data nodes includes:
[0018] Perform progressive transmission according to the archive information data type of the archive information data segment;
[0019] Set the progressive transmission time;
[0020] Set the level transmission sequence of the archive information data segment;
[0021] Obtain the same-level interval transmission time and cross-level interval transmission time of the archive information data segment according to the progressive transmission time and the archive information data type of the archive information data segment;
[0022] Allocate the cross-level transmission queue of the archive information data according to the data type of the archive information data segment, set the corresponding same-level transmission queue according to the level transmission sequence of the archive information data segment, the archive information data segment waits for the same-level interval transmission time for transmission according to the same-level transmission queue, and after all the archive information data segments in the same-level transmission queue are uploaded, perform the transmission of archive information data of other levels according to the cross-level transmission queue and the cross-level interval transmission time;
[0023] For the archive information data segment passing through the information data node, generate a transmission symbol for the archive information data segment;
[0024] Insert the transmission symbol into the archive information data segment.
[0025] Furthermore, the generation process of the transmission symbol includes:
[0026] Obtain the data length of the archive information data passing through the information data node;
[0027] Divide the file information data passing through the information data node into n data segments, denoted as file information data sub-segments;
[0028] If there are inconsistent data lengths among the file information data sub-segments, then fill in blanks for the file information data sub-segments;
[0029] Perform radix conversion on the file information data sub-segments, and denote the file information data sub-segments obtained after radix conversion as file information matrix terms;
[0030] Obtain the number of file information matrix terms, and label each file information matrix term;
[0031] Construct a k*k blank matrix, and sequentially import the obtained file information matrix terms into the blank matrix to obtain the corresponding file information matrix;
[0032] Determine whether there are blank terms in the file information matrix. If there are blank terms in the file information matrix, fill in blanks for the file information matrix;
[0033] Perform iterative calculations on the obtained file information matrix terms to obtain iterative coefficients;
[0034] According to the iterative coefficients, the transmission time data, and the transmission start data of the file information data, convert the obtained combined data into binary data;
[0035] Divide the obtained binary data into several data blocks, perform displacement operations on the several data blocks respectively, and insert the obtained data blocks into each other to generate transmission symbols for the file information data segments.
[0036] Furthermore, the process of performing information data security assessment on the file information data segments that have completed progressive transmission includes:
[0037] Denote the file information data segments that have completed progressive transmission as file information data to be stored;
[0038] Denote the actual size of the data volume of the file information data to be stored as the file information quantity value;
[0039] Denote the actual time of the file information transmission process as the actual transmission time;
[0040] Decompose and analyze the transmission symbols to obtain the data volume size, transmission time data, and transmission start data of the file information data segments;
[0041] Denote the data volume size of the file information data as the file information assessment value;
[0042] Summarize the transmission time data of the file information data, and denote it as the total transmission time;
[0043] Evaluate the information data security of the file information data segment according to the transmission start data, the evaluation value of the file information, and the total transmission time to obtain the information data security evaluation result;
[0044] The information data security evaluation result includes the normal signal of the file transmission point, the normal signal of the file data, the normal signal of the file transmission, the abnormal signal of the file transmission point, the external abnormal signal, and the internal abnormal signal;
[0045] Execute the corresponding management strategy on the file information data according to the information data security evaluation result.
[0046] Further, the process of executing the corresponding management strategy on the file information data according to the information data security evaluation result includes:
[0047] Clear the file information data to be stored according to the internal abnormal transmission signal;
[0048] Send the internal abnormal transmission signal to the user and send a response signal to each information data transmission link;
[0049] Obtain the level of the information data node and obtain the information data node corresponding to the level of the data type of the file information data to be stored;
[0050] Record the node that receives the response signal fastest in the information data nodes as the transmission node, and re-upload the file information data segment to the file management library through the transmission node;
[0051] Clear the file information data to be stored according to the external abnormal transmission signal or the abnormal signal of the file transmission point;
[0052] Send the external abnormal transmission signal to the user and continuously send monitoring signals to each information data transmission link;
[0053] Send the external abnormal transmission signal to the user and continuously send monitoring signals to each information data transmission link;
[0054] When an abnormal behavior occurs during the transmission process, send the abnormal reaction generated by the monitoring signal to the management center. The management center detects the IP address that causes the alarm signal, sets the IP address as a blacklist, and re-upload the file information data segment to the file management library.
[0055] In another embodiment of the present invention, the present invention also discloses a security management system for file information, including a management center, and the management center is communicatively connected to a file information collection module, a file information transmission module, and a file information management module;
[0056] The file information collection module is used to preprocess the file information data to be transmitted to obtain the corresponding file information data segment;
[0057] The file information transmission module is used to construct an information data transmission link composed of a number of information data nodes, and sequentially transmit the file information data segments through the information data nodes for progressive transmission;
[0058] The file information management module is used to perform information data security evaluation on the file information data segments that have completed progressive transmission, and execute corresponding management strategies on the file information data according to the information data security evaluation results.
[0059] Compared with the prior art, the beneficial effects of the present invention are as follows: The file information data is segmented and encrypted to ensure the basic security of the file information. An information data node and an information data transmission link between the user and the file management library are constructed. According to the level and progressive transmission time of the file information data segments, a transmission queue of the file information data segments is set. The file information data segments are progressively transmitted through the information data nodes and a transmission symbol is generated to further improve the security of file information transmission. When the file information data segments are transmitted to the file management library, the transmission process is evaluated by the transmission evaluation value to determine whether there is an abnormality. If there is an abnormality, the abnormal process is further analyzed by the node evaluation value to determine whether it is an internal factor or an external factor, and the file information data is securely managed according to the analysis results to improve the security of the file information data. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 It is a schematic diagram of a method for securely managing file information according to an embodiment of the present application.
[0061] Figure 2 It is a flowchart of a system for securely managing file information according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0062] As Figure 1 shown, a method for securely managing file information includes the following steps:
[0063] Step S1: Preprocess the file information data to be transmitted to obtain corresponding file information data segments;
[0064] Step S2: Construct an information data transmission link composed of a number of information data nodes, and sequentially transmit the file information data segments through the information data nodes for progressive transmission;
[0065] Step S3: Perform information data security evaluation on the file information data segments that have completed progressive transmission, and execute corresponding management strategies on the file information data according to the information data security evaluation results.
[0066] It should be further noted that in the specific implementation process, the specific process of preprocessing the file information data to be transmitted to obtain the corresponding file information data segments includes:
[0067] Classify the file information data to be transmitted, then the file information data is divided into first-level file information data, second-level file information data, and third-level file information data. Denote the level of the file information data as i and associate it with the corresponding file information data.
[0068] The first-level file information data refers to the general information data in the file information data to be transmitted.
[0069] The second-level file information data refers to the sensitive information data in the file information data to be transmitted.
[0070] The third-level file information data refers to the confidential information data in the file information data to be transmitted.
[0071] Segment different types of file information data respectively, divide each level of file information data into several file information data segments with the same length, obtain the corresponding file information data segments, and number the file information data segments in sequence according to the arrangement order of the file information, denoted as j, where j = 1, 2,..., n, n > 0 and n is an integer, and associate it with the corresponding file information data segment.
[0072] It should be further noted that in the specific implementation process, the specific process of constructing an information data transmission link composed of several information data nodes and sequentially transmitting the file information data segments through the information data nodes includes:
[0073] Set up a file management library.
[0074] The information data node is the transmission node in the process of the user uploading the file information data to the file management library, and each information data node is interconnected.
[0075] The information data transmission link is the transmission path formed by the user uploading the file information data to the file management library through several information data nodes, obtain the transmission time data and transmission start data of the file information data, and associate the transmission time data and transmission start data with the information data node.
[0076] Associate the information data nodes forming the transmission path, and associate the information data node with each information data node.
[0077] Perform progressive transmission according to the file information data classification of the file information data segment.
[0078] Set the progressive transmission time, denoted as t.
[0079] Set the hierarchical transmission sequence of the archival information data segment;
[0080] Obtain the interval transmission time of the archival information data segment according to the progressive transmission time and the archival information data type of the archival information data segment;
[0081] Obtain the same-level interval transmission time and cross-level interval transmission time of the archival information data segment according to the progressive transmission time and the level of the archival information data segment;
[0082] Allocate the cross-level transmission queue of the archival information data according to the data type of the archival information data segment, and allocate the same-level transmission queue of each level of archival information data segment according to the hierarchical transmission sequence of the archival information data segment. The archival information data segment waits for the corresponding same-level interval transmission time for transmission according to the same-level transmission queue. After all the same-level archival information data segments are uploaded, the transmission of archival information data of other levels is carried out according to the cross-level transmission queue and the cross-level interval transmission time;
[0083] The progressive transmission queue of the archival information data segment is a fixed transmission queue, and the queue transmission is carried out according to the number of the segment. The transmission queues of each level of archival information data segment are different, and the higher the level, the higher the level of the corresponding hierarchical transmission sequence.
[0084] It should be further noted that in the specific implementation process, the same-level transmission queue and the cross-level transmission queue of the archival information data segment are specifically the transmission queues of the archival information data allocated according to the level size of the archival information data. First, transmit the first-level archival information data segment, and transmit it through the information data transmission link according to the transmission sequence of the first-level archival information data segment. And the transmission interval time of each first-level archival information data segment is t. After the last segment of the first-level archival information data is transmitted, after an interval transmission time of t, transmit the second-level archival information data segment, and repeat the above transmission behavior until all the archival information data segments are transmitted;
[0085] Obtain the data length of the archival information data segment passing through the information data node, denoted as cd;
[0086] Divide the archival information data passing through the information data node into n data segments, denoted as archival information data sub-segments, where the data length of each archival information data sub-segment is the same, denoted as ;
[0087] When is not an integer, then fill in the blank for the archival information data segment;
[0088] Label each archival information data sub-segment, denoted as p;
[0089] Then, perform a radix conversion on the archival information data sub - segment with label p. Denote the archival information data sub - segment obtained after the radix conversion as an archival information matrix term, and denote the number of the obtained archival information matrix terms as m;
[0090] Label each archival information matrix term, denoted as f, where f = 1, 2, 3..., h, and f is an integer;
[0091] Denote the archival information matrix term with label f as [Q f ;
[0092] Construct a k*k blank matrix, and sequentially import the obtained archival information matrix terms into the blank matrix to obtain the corresponding archival information matrix;
[0093] Determine whether there are blank terms in the archival information matrix. If there are blank terms in the archival information matrix, fill in the blanks in the archival information matrix by filling the binary unit code 1 into the blank terms of the archival information matrix;
[0094] Perform iterative calculations on the obtained archival information matrix terms to obtain an iterative coefficient, denoted as Qx T ;
[0095] Qx T =[Q j *[Q j+1 ;
[0096] where T is the number of iterations;
[0097] Combine the iterative coefficient Qx T with the transmission time data and the transmission start data of the archival information data in parallel, and convert the obtained combined data into binary data;
[0098] Divide the obtained binary data into several data blocks, perform multiple displacement operations on each of the several data blocks respectively, and insert the obtained data blocks into each other to generate transmission symbols;
[0099] And insert the generated transmission symbols into the archival information data.
[0100] It should be further noted that in the specific implementation process, the specific process of performing information data security assessment on the archival information data segment that has completed progressive transmission and executing the corresponding management strategy on the archival information data according to the information data security assessment result includes:
[0101] Denote the archival information data segment that has completed progressive transmission as the archival information data to be stored;
[0102] Decompose and analyze the transmission symbols to obtain the data volume size of the archival information data, the transmission time data of the archival information data, and the transmission start data;
[0103] Record the data volume size of the file information data as the file information evaluation value PG;
[0104] Summarize the transmission time data of the file information data to generate the total transmission time, denoted as SJ;
[0105] It should be further noted that in the specific implementation process, the process of disassembling and analyzing the transmission symbols is as follows: Split the transmission symbols of the file information data segment from the file information data to be stored, further disassemble the obtained transmission symbols to obtain the transmission symbols generated by each information data node passed by the file information data, and restore each transmission symbol to obtain the original data of the file information data segment;
[0106] Compare the transmission start data of the file information data with the node uploaded by the user;
[0107] When the transmission start data of the file information data is consistent with the node uploaded by the user, a normal file transmission point signal is generated;
[0108] When the transmission start data of the file information data is inconsistent with the node uploaded by the user, it means that the position of the uploaded data has changed, and there may be a risk of file information data, so an abnormal file transmission point signal is generated;
[0109] Obtain the data volume size of the file information data to be stored, denoted as the file information quantity value fe;
[0110] Compare the file information evaluation value PG with the file information quantity value fe;
[0111] When the file information evaluation value PG is equal to the file information quantity value fe, the data content of the file information data is complete, and a normal file data signal is generated;
[0112] When the file information evaluation value PG is not equal to the file information quantity value fe, it means that there are missing or redundant parts in the data content of the file information data, and an external abnormal signal is generated;
[0113] Obtain the actual time of the file information transmission process, denoted as the actual transmission time st;
[0114] Compare the actual time of the file information transmission process with the total transmission time;
[0115] When the actual time of the file information transmission process is equal to the total transmission time, the file information data transmission has no delay, and a normal file transmission signal is generated;
[0116] When the actual time of the file information transmission process is not equal to the total transmission time, it means that there is an abnormality in the file information data transmission process, and an internal abnormal signal is generated;
[0117] It should be further noted that, in the specific implementation process, internal exceptions refer to problems such as network congestion, router failures, and delays during the data transmission of the file information to be stored;
[0118] It should be further noted that, in the specific implementation process, external exceptions refer to data content leakage problems such as data interception, data tampering, and data theft during the data transmission of the file information to be stored;
[0119] According to the internal exception transmission signal, the file information data to be stored is cleared, an internal exception transmission signal is sent to the user, and a response signal is sent to each information data transmission link;
[0120] Set the level of the information data nodes;
[0121] The first node of the information data transmission link is recorded as a first-level information data node, the second node of the information data transmission link is recorded as a second-level information data node, and so on, and all information data nodes on all information data transmission links are classified by level;
[0122] The response signal that reaches the first-level information data node fastest is recorded as the first-level transmission node, and the first-level information data node sends the response signal to the second-level information data node on the same information data transmission link. The second-level information data node that receives the response signal fastest is recorded as the second-level transmission node, and the second-level information data node sends the response signal to the third-level information data node on the same information data transmission link, and so on. The file information data segment is re-uploaded to the file management library through the transmission node;
[0123] According to the external exception transmission signal or the file transmission point exception signal, the file information data to be stored is cleared, an external exception transmission signal is sent to the user, the user re-uploads the file information data, and before the user re-uploads the file information data, monitoring signals are continuously sent to each information data transmission link;
[0124] When problems such as data interception, data tampering, and data theft occur during the transmission process, the monitoring signal will generate an alarm signal and send it to the management center. The management center detects the IP address that causes the alarm signal and sets the IP address as a blacklist, and re-uploads the file information data segment to the file management library.
[0125] As Figure 2 shown, in another embodiment of the present invention, the present invention also discloses a security management system for file information, including a management center, and the management center is communicatively connected to a file information collection module, a file information transmission module, and a file information management module;
[0126] The file information collection module is used to preprocess the file information data to be transmitted, and obtain the corresponding file information data segments;
[0127] The file information transmission module is used to construct an information data transmission link composed of several information data nodes, and sequentially transmit the file information data segments through the information data nodes in a progressive manner;
[0128] The file information management module is used to perform information data security evaluation on the file information data segments that have completed progressive transmission, and execute corresponding management strategies on the file information data according to the information data security evaluation results.
[0129] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A security management method for archival information, characterized in that, Including the following steps: Step S1: Preprocess the file information data to be transmitted to obtain corresponding file information data segments; Step S2: Construct an information data transmission link composed of several information data nodes, and sequentially transmit the file information data segments through the information data nodes for progressive transmission; specifically, perform progressive transmission according to the file information data type of the file information data segments; set the progressive transmission time; set the hierarchical transmission sequence of the file information data segments; obtain the same-level interval transmission time and cross-level interval transmission time of the file information data segments according to the progressive transmission time and the file information data type of the file information data segments; Allocate the cross-level transmission queue of the file information data according to the data type of the file information data segments, set the corresponding same-level transmission queue according to the hierarchical transmission sequence of the file information data segments, the file information data segments wait for the same-level interval transmission time for transmission according to the same-level transmission queue, and after all the file information data segments in the same-level transmission queue are uploaded, perform the transmission of file information data of other levels according to the cross-level transmission queue and the cross-level interval transmission time; For the file information data segments passing through the information data nodes, generate transmission symbols for the file information data segments; insert the transmission symbols into the file information data segments; Step S3: Perform information data security assessment on the file information data segments that have completed progressive transmission, and execute corresponding management policies on the file information data according to the information data security assessment results; The generation process of the transmission symbol includes: Obtain the data length of the file information data passing through the information data node; Divide the file information data passing through the information data node into n data segments, denoted as file information data sub-segments; If there are inconsistent data lengths of the file information data sub-segments, fill in the blanks for the file information data sub-segments; Perform base conversion on the file information data sub-segments, and denote the file information data sub-segments obtained after base conversion as file information matrix items; Obtain the number of file information matrix items, and label each file information matrix item; Construct a k*k blank matrix, and sequentially import the obtained file information matrix items into the blank matrix to obtain the corresponding file information matrix; Determine whether there are blank items in the file information matrix. If there are blank items in the file information matrix, fill in the blanks for the file information matrix; Perform iterative calculation on the obtained file information matrix items to obtain iterative coefficients; According to the iterative coefficients, the transmission time data and the transmission start data of the file information data, convert the obtained combined data into binary data; Divide the obtained binary data into several data blocks, perform displacement operations on the several data blocks respectively, and insert the obtained data blocks into each other to generate the transmission symbol of the file information data segment.
2. The security management method for archival information according to claim 1, wherein, The process of preprocessing the file information data to be transmitted to obtain corresponding file information data segments includes: Classify the file information data to be transmitted to obtain corresponding file information data types, and the file information data types include first-level file information data, second-level file information data, and third-level file information data; Segment different types of archival information data respectively to obtain corresponding archival information data segments, and number the archival information data segments.
3. The security management method for archival information according to claim 2, wherein, The process of constructing an information data transmission link composed of several information data nodes includes: Set up an archival management library; The information data node is a transmission node in the process of a user uploading an archival information data segment to the archival management library; Set the level of the information data node; Classify all information data nodes on all information data transmission links; The information data transmission link is a transmission path formed by a user uploading an archival information data segment to the archival management library through several information data nodes, and associate the information data nodes forming the transmission path.
4. The security management method for file information according to claim 3, characterized in that, The process of performing information data security assessment on the archival information data segment that has completed progressive transmission includes: Record the archival information data segment that has completed progressive transmission as the archival information data to be stored; Record the actual size of the data volume of the archival information data to be stored as the archival information quantity value; Record the actual time of the archival information transmission process as the actual transmission time; Decompose and analyze the transmission symbols to obtain the data volume size, transmission time data, and transmission start data of the archival information data segment; Record the data volume size of the archival information data as the archival information assessment value; Summarize the transmission time data of the archival information data and record it as the total transmission time; Perform information data security assessment on the archival information data segment according to the transmission start data, archival information assessment value, and total transmission time to obtain the information data security assessment result; The information data security assessment result includes an archival transmission point normal signal, an archival data normal signal, an archival transmission normal signal, an archival transmission point abnormal signal, an external abnormal transmission signal, and an internal abnormal transmission signal; Execute corresponding management strategies on the archival information data according to the information data security assessment result.
5. The security management method for archival information according to claim 4, wherein The process of executing corresponding management strategies on the archival information data according to the information data security assessment result includes: Delete the archival information data to be stored according to the internal abnormal transmission signal; Send an internal abnormal transmission signal to the user and send a response signal to each information data transmission link; Obtain the level of the information data node and obtain the information data node corresponding to the data type level of the archival information data to be stored; Record the node that receives the response signal fastest among the information data nodes as the transmission node, and re-upload the archival information data segment to the archival management library through the transmission node; Delete the archival information data to be stored according to the external abnormal transmission signal or the archival transmission point abnormal signal; Send an external abnormal transmission signal to the user and continuously send monitoring signals to each information data transmission link; When an abnormal behavior occurs during the transmission process, send the abnormal reaction generated by the monitoring signal to the management center. The management center detects the IP address that causes the alarm signal, sets the IP address as a blacklist, and re-uploads the archival information data segment to the archival management library.
6. A security management system for file information, specifically applied to a security management method for file information described in any one of claims 1 to 5, including a management center, characterized in that, The management center is communicatively connected to an archival information collection module, an archival information transmission module, and an archival information management module; The file information collection module is used to preprocess the file information data to be transmitted, and obtain the corresponding file information data segments; The file information transmission module is used to construct an information data transmission link composed of several information data nodes, and sequentially transmit the file information data segments through the information data nodes for progressive transmission; The file information management module is used to perform information data security evaluation on the file information data segments that have completed progressive transmission, and execute corresponding management strategies on the file information data according to the information data security evaluation results.
Citation Information
Patent Citations
Block chain-based archive sharing management platform
CN114005499A
Data transmission priority scheduling method
CN118509387A