A printing and burning system

By performing security level verification and identity authentication on the enterprise's internal printing and burning system, combined with whitelist program interception, the security vulnerability of lack of monitoring of printing and burning behavior was solved, and the security protection and leakage prevention of sensitive information were achieved.

CN119646835BActive Publication Date: 2026-04-17WUHAN SANJIANG SPACE NETWORK COMM CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WUHAN SANJIANG SPACE NETWORK COMM CO LTD
Filing Date
2024-09-30
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies lack effective monitoring of internal printing and burning activities within enterprises, posing significant security vulnerabilities and potential for data leaks.

Method used

A printing and burning system was designed, including user equipment, server, output device, printing device and burning device. By performing security level verification, identity verification and whitelisting of business documents, it ensures that only authorized users can perform printing or burning operations after going through the approval process.

Benefits of technology

It effectively reduces the probability of errors in human selection and approval, prevents leaks, enhances information security, ensures that sensitive information is only accessible to the user, and eliminates the leakage of classified documents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119646835B_ABST
    Figure CN119646835B_ABST
Patent Text Reader

Abstract

This invention provides a printing and burning system, comprising: a user device, a server, an output device, a printing device, and a burning device, wherein: the user device is used to log in to the burning software system based on identity information, create business documents based on business type on the burning software system, and initiate an approval process after the business documents pass security level verification; the server deploys the burning software system, which is used to perform security level verification on business documents, advance the approval process, and verify identity information; the output device deploys a whitelist program and authorized burning clients; the printing device is used to receive and execute printing instructions; and the burning device is used to receive and execute burning instructions. This invention provides a printing and burning system to solve the problems of existing technologies that lack effective monitoring of printing and burning activities and have significant security vulnerabilities and potential leakage risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer information security technology, and in particular to a printing and burning system. Background Technology

[0002] With the implementation and launch of various information systems within enterprises involving classified information, office printing and burning activities in various departments of the enterprise are becoming increasingly frequent. Although the document printing room is equipped with various printing and burning equipment, anyone can print or burn at any time. There is no effective monitoring of such activities, which poses a significant security vulnerability and risk of information leakage. Summary of the Invention

[0003] This invention provides a printing and burning system to solve the problems in the prior art that there is no effective monitoring of printing and burning activities and that there are significant security vulnerabilities and risks of information leakage.

[0004] In a first aspect, the present invention provides a printing and recording system, characterized in that it includes a user device, a server, an output device, a printing device, and a recording device, wherein:

[0005] The user equipment is used to log in to the stamping software system based on identity information, create business documents on the stamping software system based on business type, and initiate an approval process after the business document passes the security level verification. The business type includes printing and burning. Creating a business document includes selecting the document security level, setting business operations, uploading business files, and selecting file security levels. The security level verification includes performing a first verification on the file security level when the business file is received, and a second verification on the document security level after all file security levels have passed the first verification.

[0006] The server is equipped with the engraving software system, which is used to perform the security level verification on the business documents, advance the approval process, and verify the identity information, including the identity information sent by the user device and the identity information sent by the engraving client.

[0007] The output device is equipped with a whitelisting program and an authorized stamping client, wherein:

[0008] The whitelist program is used to verify whether the engraving client is in the whitelist. If it is, the business instructions sent by the engraving client are allowed; if it is not, the business instructions sent by the engraving client are discarded. The business instructions include printing instructions and burning instructions.

[0009] The stamping client is used to receive the identity information, send the identity information to the stamping software system for verification, obtain all business documents of the user to whom the identity information belongs that have passed the approval process after the user selects the required business document from all the business documents that have passed the approval process, and send a business instruction after the user selects the required business document from all the business documents that have passed the approval process.

[0010] The printing device is used to receive and execute the printing command;

[0011] The recording device is used to receive and execute the recording instructions.

[0012] In the above solution, by performing confidentiality level verification on business documents, the probability of errors in human selection and approval is effectively reduced, preventing the occurrence of leakage incidents; by verifying the identity information sent by the printing client, security protection measures can be improved, ensuring that business documents are only obtained by the user, effectively avoiding the leakage of sensitive information; by setting a whitelist program on the output device for interception, the leakage of confidential documents caused by users sending business instructions using output devices connected to printing or burning devices can be effectively avoided.

[0013] Optionally, the first verification of the file security level upon receiving the business file includes:

[0014] Upon receiving the business file, it is determined whether the business file contains keywords from the keyword list, where the keyword list is pre-set and each keyword is mapped to a corresponding security level.

[0015] If not included, the file security level passes the first verification.

[0016] If it is included, the highest security level among the security levels mapped by the keywords contained in the business file is taken as the identification security level, and it is determined whether the identification security level is higher than the file security level;

[0017] If the level is higher, then the file security level has failed the first verification.

[0018] If the security level is not higher than the first check, then the file security level passes the first check.

[0019] Optionally, determining whether the business document contains keywords from the keyword list includes:

[0020] Iterate through each page of the business file and extract the first text characters and images from each page;

[0021] For the first text character, determine whether the first text character contains a keyword from the keyword list;

[0022] For the image, optical character recognition technology is used to extract the second text characters from the image and perform special character filtering to determine whether the second text characters after special character filtering contain keywords from the keyword list.

[0023] Optionally, the second verification of the document's security level after all document security levels have passed the first verification includes:

[0024] After all file security levels have passed the first verification, it is determined whether the highest file security level among all file security levels is higher than the document security level;

[0025] If the level is higher, then the document's security classification has failed the second verification.

[0026] If it is not higher, then the document's security level passes the second verification.

[0027] Optionally, verifying the identity information includes:

[0028] Determine whether the identity information is the identity information set by the engraving software system;

[0029] If so, the verification passes;

[0030] If not, the verification fails.

[0031] Optionally, verifying whether the engraving client is in the whitelist includes:

[0032] The process name of the stamping client is verified to be in the whitelist by text comparison.

[0033] Optional, also includes:

[0034] The user equipment is equipped with a virtual printer, which is pre-loaded with the identity information. The virtual printer is used for:

[0035] When the user equipment is directly connected to the printing device, it receives the printing instruction sent by the third-party software, creates the business document in the stamping software system based on the identity information and the printing instruction, and initiates the approval process after the business document passes the security level verification.

[0036] In the above solution, the virtual printer will automatically upload print files and initiate the approval process to the printing software system, eliminating the need for users to log in to the printing software system to upload print files and initiate the approval process, thus avoiding the lack of management of printing activities.

[0037] Optional, also includes:

[0038] For the case where the business type is printing, the printing client generates a two-dimensional barcode corresponding to the page number for each page of the business document, and displays the two-dimensional barcode on the page corresponding to the page number.

[0039] In the above solution, by generating a two-dimensional barcode corresponding to the page number for each page of the printed document, verification can be performed by scanning the two-dimensional barcode page by page according to the page number when performing business such as clearing and destruction, thus preventing the partial extraction of printed documents.

[0040] Optional, also includes:

[0041] When the file security level passes the first verification, the business file is converted into a unified format.

[0042] In the above solution, by converting business documents into a unified format, the need to be compatible with and adapt to all document formats available on the market when attaching two-dimensional barcodes is effectively avoided.

[0043] Optional, also includes:

[0044] The same checksum is set in the print driver of the output device and on the print device.

[0045] In the above solution, by setting the same checksum on the print driver and printer of the output device for interception, the leakage of confidential documents caused by users sending print commands using user devices connected to the print device can be effectively avoided. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is a schematic diagram of the structure of a printing and recording system provided in an embodiment of the present invention;

[0048] Figure 2 A schematic diagram of the hook code provided in an embodiment of the present invention;

[0049] Figure 3 This is a schematic diagram of the file filtering driver code provided in an embodiment of the present invention. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0051] Figure 1 A detailed schematic diagram of a printing and recording system provided by an embodiment of the present invention is shown, including a user device, a server, an output device, a printing device, and a recording device.

[0052] The user equipment is used to log in to the stamping software system based on identity information, create business documents on the stamping software system based on business type, and initiate the approval process after the business documents pass the security level verification.

[0053] In one example, the user device and server adopt a B / S architecture. The user logs into the engraving software system on the server through a browser on the user device (e.g., a personal computer), and the login method can be a personal account or a USB key, etc.

[0054] Specifically, the business types include printing and burning.

[0055] Business types may also include photocopying, registration of incoming documents, import, internal transmission, external transmission, confidential external transmission, codebook, archiving, filing, return, destruction, auditing, and barcode generation.

[0056] Auditing refers to the recording and statistical analysis of all business documents and media files generated within the printing and recording software system. It allows for filtering and viewing of all business documents and media files, providing a clear view of the closed-loop management of each document and media file, and enabling refined management of each user's print volume. Media files include paper printouts from printing devices and CD / DVD burners from burning devices. Auditing records at each stage of the file lifecycle ensure secure file transfer, end-to-end monitoring, and traceability.

[0057] Barcode generation refers to the two-dimensional barcode section, where users can fill in form information and generate a two-dimensional barcode for use in services such as photocopying. These services require affixing the two-dimensional barcode to the cover of a new carrier and scanning it for confirmation to complete the business loop.

[0058] Specifically, creating a business document includes selecting the document security level, setting business operations, uploading business files, and selecting the file security level.

[0059] It's important to note that, aside from printing and burning discs, not all business types require uploading business files. The business document can also display information such as the file size and upload progress. For printing transactions, the operations include setting the number of copies and printing method (e.g., single-sided / double-sided / color printing).

[0060] When a user uploads a confidential document to the document printing software system, the document's security level is mistakenly selected as non-confidential. Simultaneously, due to negligence on the part of the approver, the error is not detected in time, resulting in the document being transmitted with high security information but not confidential, leading to the leakage of highly confidential information. By performing security level verification on business documents, the probability of errors in human selection and approval is effectively reduced, preventing the occurrence of leaks.

[0061] Specifically, security level verification includes performing a first security level verification on the received business documents and a second security level verification on the document after all documents have passed the first security level verification.

[0062] It should be noted that the security classification verification is performed by the engraving software system.

[0063] In one example, the first verification of the file security level upon receiving a business file includes:

[0064] Upon receiving a business file, it is determined whether the business file contains keywords from the keyword list. The keyword list is pre-set and each keyword is mapped to a corresponding security level.

[0065] If not included, the file security level passes the first check.

[0066] If it is included, the highest security level among the security levels mapped by the keywords included in the business file is taken as the identification security level, and it is determined whether the identification security level is higher than the file security level.

[0067] If the level is higher, the file security level has failed the first verification.

[0068] If the security level is not higher than the required level, the file security level passes the first check.

[0069] Furthermore, determining whether a business document contains keywords from the keyword list includes:

[0070] Iterate through each page of the business file and extract the first text character and image from each page;

[0071] For the first character string, determine whether it contains a keyword from the keyword list;

[0072] For images, optical character recognition (OCR) technology is used to extract second text characters from the images and perform special character filtering. It is then determined whether the second text characters after special character filtering contain keywords from the keyword list.

[0073] In one example, performing a second security check on a document after all documents have passed the first security check includes:

[0074] After all file security levels have passed the first check, determine whether the highest file security level is higher than the document security level.

[0075] If the level is higher, the document's security classification has failed the second verification.

[0076] If it is not higher, the document's security level passes the second verification.

[0077] It should be noted that the security classification verification applies to the following business types: printing, burning, and importing. For these business types, the approval process can only be initiated after the security classification verification is passed.

[0078] The server is equipped with a stamping software system, which is used to perform security level verification on business documents, advance approval processes, and verify identity information.

[0079] The approval process can include first-level, second-level, or third-level approval. In one example, the stamping system advances the approval process by pushing approval messages to approvers. These messages include the serial number, title, initiator, document status, business type, description, and initiation date. Document statuses include: temporarily stored, under review, pending printing, printed, pending burning, and burned.

[0080] After the approval process is completed, the status of the business document will be updated to "approved".

[0081] In one example, verifying identity information includes:

[0082] Determine whether the identity information matches the identity information set by the stamping software system;

[0083] If so, the verification passes;

[0084] If not, the verification fails.

[0085] Specifically, the identity information includes the identity information sent by the user device and the identity information sent by the stamping client.

[0086] Normally, after the approval process is completed, business instructions can be sent through an authorized stamping client. However, this can lead to situations where business files are accessed by anyone operating the stamping client, resulting in the leakage of sensitive information. Verifying the identity information sent by the stamping client can enhance security measures, ensuring that business files are only accessed by the user and effectively preventing the leakage of sensitive information.

[0087] In one example, the identity information sent by the stamping client is obtained by swiping a card, scanning a face, scanning a fingerprint, or entering an account password. Swiping a card is achieved through a card reader installed on the output device.

[0088] The services that need to be implemented through the stamping client include printing, burning, copying, external transmission, password book, archiving, filing, clearing and destruction.

[0089] The output device is equipped with a whitelist program and authorized printing clients, including:

[0090] The whitelist program is used to verify whether the stamping client is in the whitelist. If it is, the business instructions sent by the stamping client are allowed; otherwise, the business instructions sent by the stamping client are discarded.

[0091] The stamping client is used to receive identity information, send the identity information to the stamping software system for verification, obtain all business documents of the user whose identity information has passed the approval process after the user selects the required business document from all the business documents that have passed the approval process, and send business instructions.

[0092] The output device can be the output computer in the printing room, and the printing client is deployed on the output computer in the printing room.

[0093] For particularly sensitive documents, some users, in order to avoid leaving a trace, deliberately bypass the printing software system and printing client, and send business instructions directly using the output device connected to the printing or burning device without going through the approval process, resulting in the leakage of classified documents. Setting up a whitelist program on the output device to intercept these actions can effectively prevent the above situations.

[0094] In one example, verifying whether the stamping client is in the whitelist includes verifying whether the process name of the stamping client is in the whitelist by comparing text.

[0095] In one example, the whitelist is a document file configured outside the whitelisting program, and the whitelist is configured through the whitelisting program.

[0096] For printing operations, the whitelist settings are based on Microsoft's open-source Detours library. Detours is a library for intercepting Windows API calls and can be used for various purposes, such as monitoring and modifying system calls and creating hooks. The steps for using the Detours library to intercept binary functions on ARM, ARM64, x86, x64, and IA64 machines are as follows:

[0097] After opening the source code and compiling it, the detours.lib library will be generated;

[0098] The detours.lib library was introduced for printing operations, which allows operations that originally used system APIs to "bypass" and use rewritten APIs, thus intercepting printing-related system APIs.

[0099] Determine if the target process is in the whitelist. If it is, do not inject the hook using DLL injection. If it is not, inject the hook using DLL injection to intercept the printing task.

[0100] Hook code as follows Figure 2 As shown, it is actually a "bypass" code segment that works in the whitelist program. The code lists the system API functions for printing operations to ensure that processes not on the whitelist will use this "bypass" code segment when they need to print, thereby achieving the purpose of intercepting printing.

[0101] In Windows systems, the file system is one of the most common and powerful locations for insert filter drivers. File system filter drivers can intercept I / O operations (from applications and the system itself) before they reach the file system. This allows file filter drivers to monitor, track, manage, manipulate, and even allow or deny I / O operations before the file system captures system I / O operations during the burning process. Therefore, for burning operations, the core logic of whitelist interception is: the data is intercepted by the filter before it is written to the disc, and a file write protection exception is returned. This way, after the user performs the burning operation, a disk write protection pop-up will appear, thus blocking burning operations from non-whitelisted processes.

[0102] Figure 3 This is a piece of file filtering driver code. `FsFilterlPreOperation` is a callback function that is entered after every system I / O operation. The code first filters programs requesting I / O using a whitelist configured in the registry. Then, it declares four filters related to burning operations to filter I / O operations from processes not on the whitelist, achieving the goal of processing only burning operations without affecting system stability.

[0103] Specifically, the business instructions include printing instructions and burning instructions.

[0104] It's important to note that unauthorized stamping clients, even when deployed on the output device, cannot communicate with the stamping software system. Authorizing stamping clients avoids a situation where there are too many clients and they become uncontrollable, thus facilitating client management. Stamping clients can be authorized using a license.

[0105] In one example, communication between the stamping client and the stamping software system is implemented based on WebService.

[0106] The printing device is used to receive and execute printing instructions.

[0107] The burning device is used to receive and execute burning instructions.

[0108] In cases where third-party software (such as Winchll, CAD, etc.) sends print commands directly without applying for and approving through the printing software system, the printing software system cannot obtain the print file, resulting in the inability to record and leave traces of such prints in the printing software system, thus causing a lack of control over printing behavior.

[0109] In one example, a printing and burning system provided by an embodiment of the present invention further includes:

[0110] The user equipment is equipped with a virtual printer, which has pre-set identity information. The virtual printer is used for:

[0111] When the user device is directly connected to the printing device, it receives printing instructions sent by third-party software, creates business documents in the printing software system based on the user's identity information and printing instructions, and initiates the approval process after the business documents pass the security level verification.

[0112] The virtual printer will automatically upload print files and initiate the approval process to the printing software system, eliminating the need for users to log in to the printing software system to upload print files and initiate the approval process, thus avoiding a lack of management over printing activities.

[0113] Currently, only the first page of the printed documents has a unique two-dimensional barcode for identification, while the inner pages lack this unique barcode. This makes it easy for critical and sensitive information pages to be extracted during the clearing and destruction of printed documents, leading to data leaks.

[0114] In one example, a printing and burning system provided by an embodiment of the present invention further includes:

[0115] For printing-related business scenarios, the printing client generates a two-dimensional barcode corresponding to each page number of the business document and displays the two-dimensional barcode on the corresponding page.

[0116] By generating a two-dimensional barcode corresponding to each page number of the printed document, verification can be performed by scanning the two-dimensional barcode page by page during operations such as clearing and destruction, thus preventing the partial extraction of printed documents.

[0117] Users typically submit files in various formats such as DOC, DOCX, PPT, EXCEL, .cd, .ps, and .rp. This necessitates ensuring compatibility and adaptability with all available document formats when attaching 2D barcodes, which is virtually impossible. Therefore, it is necessary to convert the various file formats to output a file with a unified format.

[0118] In one example, a printing and burning system provided by an embodiment of the present invention further includes:

[0119] When the file security level passes the first verification, the business file is converted into a unified format.

[0120] In the above solution, each business file is converted individually after passing the first verification, which effectively avoids the server load or even freezing that may occur when multiple business files in the same business document are converted in batches at the same time.

[0121] In one example, the uniform format is PDF.

[0122] For particularly sensitive documents, some users, in order to avoid leaving a trace, deliberately bypass the printing software system and printing client, and send print commands directly from the user device connected to the printing equipment without going through the approval process, resulting in the leakage of classified documents. This situation can be effectively avoided by setting the same checksum on the print driver and printer of the output device.

[0123] In one example, a printing and burning system provided by an embodiment of the present invention further includes:

[0124] Set the same checksum on the output device's print driver and on the print device.

[0125] The checksum in the print driver is added to the print command and sent to the printing device. The printing device verifies whether its own checksum matches the checksum in the print driver. If they match, the print command is executed and a paper document is output. The checksum verification process is silent and imperceptible to the user.

[0126] In one example, the verification code includes the username and password.

[0127] Taking Windows as an example, the printer's verification code is set by going to System Management -> Input -> User Authentication -> Set Account Password. The printer driver's verification code is set by right-clicking My Computer -> Properties -> Bluetooth and other devices -> Printers and scanners -> Select the actual printer being used -> Printer Preferences -> Basic Settings -> User Authentication -> Set Account Password -> Verify.

[0128] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the invention.

[0129] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A printing and burning system, characterized in that, This includes user equipment, servers, output devices, printing devices, and burning devices, among which: The user equipment is used to log in to the stamping software system based on identity information, create business documents on the stamping software system based on business type, and initiate an approval process after the business document passes the security level verification. The business type includes printing and burning. Creating a business document includes selecting the document security level, setting business operations, uploading business files, and selecting file security levels. The security level verification includes performing a first verification on the file security level when the business file is received, and a second verification on the document security level after all file security levels have passed the first verification. The server is equipped with the engraving software system, which is used to perform the security level verification on the business documents, advance the approval process, and verify the identity information, including the identity information sent by the user device and the identity information sent by the engraving client. The output device is equipped with a whitelisting program and an authorized stamping client, wherein: The whitelist program is used to verify whether the engraving client is in the whitelist. If it is, the business instructions sent by the engraving client are allowed; if it is not, the business instructions sent by the engraving client are discarded. The business instructions include printing instructions and burning instructions. The engraving client is used to receive the identity information, send the identity information to the engraving software system for verification, obtain all business documents of the user to whom the identity information belongs that have passed the approval process after the user selects the required business document from all the business documents that have passed the approval process, and send a business instruction after the user selects the required business document from all the business documents that have passed the approval process. The printing device is used to receive and execute the printing command; The recording device is used to receive and execute the recording instructions.

2. The system according to claim 1, characterized in that, The first verification of the security level of the file upon receiving the service file includes: Upon receiving the business file, it is determined whether the business file contains keywords from the keyword list, where the keyword list is pre-set and each keyword is mapped to a corresponding security level. If not included, the file security level passes the first verification. If it is included, the highest security level among the security levels mapped by the keywords contained in the business file is taken as the identification security level, and it is determined whether the identification security level is higher than the file security level; If the level is higher, then the file security level has failed the first verification. If the security level is not higher than the first check, then the file security level passes the first check.

3. The system according to claim 2, characterized in that, The determination of whether the business document contains keywords from the keyword list includes: Iterate through each page of the business file and extract the first text characters and images from each page; For the first text character, determine whether the first text character contains a keyword from the keyword list; For the image, optical character recognition technology is used to extract the second text characters from the image and perform special character filtering to determine whether the second text characters after special character filtering contain keywords from the keyword list.

4. The system according to claim 1, characterized in that, The second verification of the document's security level after all documents have passed the first verification includes: After all file security levels have passed the first verification, it is determined whether the highest file security level among all file security levels is higher than the document security level; If the level is higher, then the document's security classification has failed the second verification. If it is not higher, then the document's security level passes the second verification.

5. The system according to claim 1, characterized in that, The verification of the identity information includes: Determine whether the identity information is the identity information set by the engraving software system; If so, the verification passes; If not, the verification fails.

6. The system according to claim 1, characterized in that, The verification of whether the engraving client is in the whitelist includes: The process name of the stamping client is verified to be in the whitelist by text comparison.

7. The system according to claim 1, characterized in that, Also includes: The user equipment is equipped with a virtual printer, which is pre-loaded with the identity information. The virtual printer is used for: When the user equipment is directly connected to the printing device, it receives the printing instruction sent by the third-party software, creates the business document in the stamping software system based on the identity information and the printing instruction, and initiates the approval process after the business document passes the security level verification.

8. The system according to claim 1, characterized in that, Also includes: For the case where the business type is printing, the printing client generates a two-dimensional barcode corresponding to the page number for each page of the business document, and displays the two-dimensional barcode on the page corresponding to the page number.

9. The system according to claim 8, characterized in that, Also includes: When the file security level passes the first verification, the business file is converted into a unified format.

10. The system according to claim 1, characterized in that, Also includes: The same checksum is set in the print driver of the output device and on the print device.

Citation Information

Patent Citations

  • Document hierarchical desensitization encryption method

    CN109740363A

  • File burning method, device and equipment and computer readable storage medium

    CN115062294A