Electronic seal management method and system
By using the combination of user ID and timestamps to generate a unique key in a multi-user environment, and dynamically regulate permissions in real time, the problems of key duplication and permission failure are solved, and the integrity verification capabilities of audit data are improved.
Patent Information
- Application Number
- CN202510195368.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-02-21
AI Technical Summary
In a multi-user environment, the problem of duplicate generation of the same key may occur, the personnel changes lead to lag in permission failure, and the logging details and storage location control are difficult under audit requirements.
By combining unique user identifiers and timestamps in a multi-user environment, the unique key of the electronic seal is generated, the usage permissions are dynamically regulated in real time, the permission changes and seal usage operations are recorded in detail, and the log storage location is regulated according to the security level.
It effectively solves the problem of repeated key generation in multi-user environments, realizes real-time dynamic control of permissions, and improves the data integrity verification capabilities during the audit process.
Smart Images

Figure CN119696784B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of electronic seal management, and in particular to an electronic seal management method and system. Background Art
[0002] The electronic seal management method aims to ensure the legitimacy and security of document stamping through digital technology. The method first involves generating a unique key, which is to ensure the uniqueness and anti-counterfeiting of each electronic seal;
[0003] However, in a multi-user environment, the problem of repeatedly generating the same key may occur, which is a potential risk. In addition, in the event of personnel changes (such as resignation or transfer), the use permissions need to be dynamically adjusted in real time to avoid the problem of former employees still being able to access or use the seal system. This is called the permission expiration lag problem. Finally, in response to audit needs, it is particularly important to adjust the level of detail and storage location of log records to solve the problem of insufficient data integrity verification. For example, the operator, timestamp, content and other information of each seal should be recorded, and these sensitive data should be safely stored for future reference and verification.
[0004] To sum up, the above issues are key challenges to ensure the effective operation and secure management of the electronic seal system. Summary of the invention
[0005] The embodiments of the present disclosure provide an electronic seal management method and system, which at least partially solve the problems existing in the prior art.
[0006] An electronic seal management method, comprising:
[0007] S101, generating a unique key corresponding to the electronic seal based on a unique user identification and a timestamp combination in a multi-user environment;
[0008] S102. Use the monitoring system to dynamically control the use rights of electronic seals in real time to ensure that the rights of specific personnel will be immediately invalidated after they leave or change positions;
[0009] S103, generating detailed log records according to authority changes and seal usage operations;
[0010] S104. Regulate the storage location of log records according to security levels to ensure integrity verification of audit data.
[0011] By adopting the above technical solution, the step of generating a unique key corresponding to the electronic seal based on a unique user identification and a timestamp in a multi-user environment further includes:
[0012] Generate an initial hash value based on the unique user ID and the current timestamp to ensure the uniqueness of each key;
[0013] Use an asymmetric encryption algorithm to encrypt the initial hash value to form the final key, thus preventing key duplication caused by the same environmental parameters;
[0014] Introduce a random number factor R during the generation process to enhance the randomness and complexity of the key;
[0015] Detect whether the newly generated key is the same as all keys in the historical key library. If a same key is detected, trigger the key regeneration process.
[0016] By adopting the above technical solution, based on the initial hash value and the encryption step, it further includes:
[0017] Select the hash algorithm SHA256 as the basic hash function to ensure the stability and efficiency of the hash calculation result;
[0018] Use the RSA asymmetric encryption method to process the received original data to increase the cracking difficulty, where RSA is the standard of the public key encryption system to ensure the security and reliability of key transmission;
[0019] Set a formulaic conditional judgment statement: for each key generation operation, if the generation times Cn is greater than the critical value Cm (0 < Cm < the maximum threshold), that is, when the generation times exceed the limit, automatically optimize the range of the random number factor R to reduce the coincidence probability;
[0020] The meaning of the formula is: in the process of repeatedly attempting to generate a unique key, adjust the generation strategy in a timely manner by limiting the generation times to ensure that each generated key is unique. Here, Cn represents the actual number of generations that occur, and Cm is the preset maximum reasonable retry times;
[0021] Store the successfully generated and verified keys in the key database and attach a time tag for subsequent auditing.
[0022] By adopting the above technical solution, in the method based on introducing the random number factor R, the following specific operations are performed:
[0023] Randomly select a set of preset pseudo-random sequences P and map them through specific rules to obtain the random number factor R to ensure the unpredictability of the random number factor R;
[0024] When generating a new key using the same identifier ID, use different Ps within the same time period to ensure different results for different instances;
[0025] The corresponding relationship is formally described as follows: if the last random selection sequence index Ps is equal to the current selection sequence number Pt, and the time difference T is not greater than the minimum allowed value ΔT, then another pseudo-random sequence is replaced, where Ps and Pt refer to the order numbers before and after the two generation actions respectively; and ΔT refers to the minimum time interval between the two generation events;
[0026] The final random number factor R value is appended to the basic hash string to form an enhanced intermediate form.
[0027] By adopting the above technical solution, the following process is further clarified based on the selection and mapping operation of the pseudo-random sequence:
[0028] Initialize several different high-density seed sequences Seeds as candidate sets;
[0029] Add a weight factor W to evaluate the advantages or disadvantages of each candidate seed sequence, and select the most suitable Seeds as the core component of this generation according to a certain scoring mechanism;
[0030] Apply the logical expression: If the weight W is less than the minimum qualified line Wl, then force a refresh of the available option pool to find seeds with better quality;
[0031] Perform a fast transformation operation to convert the selected Seed and generate the corresponding P for reference in the next step.
[0032] By adopting the above technical solution, the selection and application details based on the seed sequence are more precise as follows:
[0033] Define a set of evaluation indicators to measure the quality level of each candidate sequence;
[0034] The Dscore of each candidate is calculated based on the existing historical performance statistics, and an additional bonus is given based on the current scenario requirements;
[0035] If the comprehensive score Σ=Scorei+Bonusi reaches or exceeds the set threshold Sth, the sequence is locked, otherwise the search is iterated until a satisfactory candidate sequence is found;
[0036] The linear congruential method is implemented on the selected high-quality Seeds to generate P, preparing for the next step.
[0037] By adopting the above technical solution, the newly added steps in the process of generating a unique key are as follows:
[0038] Enhanced hash algorithm selection process to ensure higher anti-collision capability;
[0039] The time window limitation mechanism Wt is introduced to limit the validity period of the random number factor R within a specified range to prevent the key from being cracked within a long validity period;
[0040] Establish a periodic checkpoint Tk to verify the validity and security of the new key being generated or just generated in real time;
[0041] The following formula is used for control: Assuming that the number of consecutive failed verifications Fk exceeds the predetermined upper limit Fl, the current workflow is stopped immediately and a diagnosis and analysis of possible problems is performed;
[0042] The formula here aims to establish a complete fault-tolerant recovery mechanism. Fk refers to the cumulative number of errors, and Fl refers to the maximum acceptable fault-tolerant limit.
[0043] By adopting the above technical solution, based on the improved timestamp and hash generation solution, the new content includes:
[0044] The time axis is divided into multiple sub-periods, so that the events in each period can obtain relatively independent but globally ordered time information;
[0045] Allocate fixed-length binary bits L to represent the position of each subparagraph, and use its encoding characteristics to accelerate matching searches;
[0046] In order to balance the relationship between fine time granularity and system load, a dynamic trade-off model is proposed, which is described by the mathematical formula Y=a*T^2+b*T+c, (T represents the average transaction interval time);
[0047] Verify the consistency of the generated results and confirm that there is only a unique positive integer representing the time scale position N in each segment that satisfies the above polynomial equation constraints.
[0048] By adopting the above technical solution, the specific measures for optimizing the timeline and sub-segment time management are as follows:
[0049] Formulate flexible segmentation rules based on the natural daily activity level changes;
[0050] Implement a recursive search algorithm to determine the closest adjacent point Adj as a reference point to speed up positioning;
[0051] Formula expression logic: Whenever the difference Dti between two time points Ti, Tj exceeds the tolerance Toler and is located in the adjacent interval, the time position mark Pl, Pr is reallocated, where Dti=TjTi represents the absolute distance between two adjacent points;
[0052] After assembling the complete chain consisting of all fragments, perform the end verification task to ensure that there are no abnormal breakpoints.
[0053] By adopting the above technical solution, the dynamic timeline and resource allocation are further described in detail as follows:
[0054] Construct a multi-level index tree structure TreeIndex to efficiently organize and manage data entities in different time zones;
[0055] Designing the regional adaptation strategy AreaScheme based on the impact range of geospatial factors improves efficiency and accuracy;
[0056] Establish threshold judgment criteria: If the number of visits to a node Afreq has always remained high (higher than the normal expected value Exp) during the past window Win, that is, Avg>α*Afreq, then the branch path will be optimized and adjusted first, where Avg is the average frequency in the window and α is the amplification factor;
[0057] The final round of comprehensive review of the overall process layout ensures that the entire system architecture is scientific, reasonable and scalable.
[0058] An electronic seal management system, the system is executed by the electronic seal management method, and the system comprises:
[0059] A data generation module, wherein the data generation module is used to generate a unique key based on the user identity and usage context to prevent duplicate key generation;
[0060] A data mobilization module that allocates real-time and dynamically regulated usage rights based on the unique key and synchronizes the status to all relevant nodes;
[0061] The processing module collects the operation data with timestamps and sets the detail level of the electronic seal log records;
[0062] The storage module distributes detailed logs to multiple pre-configured storage locations according to security policies to ensure data integrity.
[0063] To sum up, the present application has beneficial technical effects: through the scheme of the embodiments of the present disclosure, it is possible to regulate the unique key generated by the electronic seal to solve the problem of repeated generation of the same key in a multi-user environment; it is possible to solve the problem of real-time dynamic regulation of the electronic seal usage rights to solve the problem of delayed expiration of rights after the resignation or transfer of specific personnel; it is possible to regulate the detail and storage location of the log records of the electronic seal to solve the problem of insufficient data integrity verification during the audit process. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Figure 1 It is a flow chart of the electronic seal management method of the present invention;
[0065] Figure 2 It is a flow chart of the electronic seal management system of the present invention. DETAILED DESCRIPTION
[0066] Embodiments of the present application are described in detail below, examples of which are shown in the accompanying drawings.
[0067] In the description of this specification, the description with reference to the terms "certain embodiments", "one embodiment", "some embodiments", "illustrative embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiments or examples are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0068] The embodiment of the present application discloses an electronic seal management method of the present invention, which includes multiple important steps to cope with various challenges in the use of electronic seals, especially the uniqueness of key generation, dynamic control of permissions, and the details and storage control of logs.
[0069] First, consider generating a unique key for the corresponding electronic seal based on a unique user ID and timestamp combination in a multi-user environment. This step ensures that even when multiple people operate in parallel in a large enterprise or organization, each generated key is unique and cannot be easily copied. To achieve this goal, the specific operation is: whenever a new electronic seal needs to be generated, the system calculates a random and unique string of characters based on the initiator's user ID (this is a unique identity code for each user) and the timestamp data of the application time accurate to the second as the basic value of the secret key for this electronic seal; then this string of basic information will be processed through a highly encrypted algorithm to form an actual key that is difficult to reverse and analyze the original text; this This mechanism prevents two different people from accidentally generating the same key in the same time period due to system response delays and other issues, thereby effectively solving the risk of repeatedly generating the same key in a highly active environment; for example, in one embodiment, a company has many departments and branches, and all employees have the right to request the system to create their own exclusive electronic impressions required for document issuance. In this process, everyone's account is their unique personal mark. Once they want to create a new electronic mark, they must enter the current precise date and minute, and the time period above the level. This ensures that each employee obtains his or her own unique password, and even if everyone makes the same request almost at the same time, they can get different results.
[0070] Then, a powerful monitoring platform is established to dynamically regulate the permission of each participant to use the electronic seal in real time to ensure that the holder can quickly lose the relevant ability after leaving the original position or changing functions, without causing security vulnerabilities during the transition period; the operations mentioned here include pre-setting the executable action range corresponding to each position, saving and updating it in the database, and promptly feeding back the latest personnel changes to the control center, so that it can automatically determine which user accounts should stop accessing sensitive functions such as signature authentication and other services, and immediately change the status when receiving a notification to prevent violations from occurring and prevent the expansion of potential risks; greatly reducing the possibility of economic losses caused by misoperation, maintaining consistency in internal organizational rules, reducing confusion, improving efficiency and ensuring safety.
[0071] Finally, a detailed activity diary is generated based on the changes in permissions and actual usage, and the storage location is adjusted according to different protection levels to improve the data integrity inspection in the later audit work; at this stage, the system will closely monitor who performed what type of command, such as printing output or editing mode switching, and then combine the changes in personnel role information discussed earlier to produce a complete and accurate log document that not only records the main body of the event but also covers the background content of the event, which is convenient for the reader to understand the causal relationship before and after. At the same time, considering the importance of different types of events, different treatments are given, and appropriate locations are selected to ensure that key evidence can be preserved for a long time, while taking into account privacy protection requirements to achieve both openness and confidentiality to support the smooth progress of subsequent review work; specifically, the core decision-making process related information involved in certain high-risk projects should be placed in a safer and more controlled place, and only authorized personnel have the opportunity to keep and view it for a long time. For daily affairs diaries, ordinary servers can be used to meet the needs, which helps to concentrate on handling major cases without dispersing too many resources due to trivial details, which is conducive to quickly locating key links and efficiently completing investigation and evidence collection tasks.
[0072] The above method provides a reliable mechanism for solving the problem of how to regulate the unique key generated by the electronic seal to solve the problem of repeated generation of the same key in a multi-user environment; by establishing a complete monitoring system, the real-time effect of the invalidation of the use authority of a specific person after resignation or change of position is achieved, thereby improving the quality of security management; and through the scientific design of the log record content and its archiving location, the problem of insufficient data authenticity during the review of the log is solved, the effectiveness and transparency of the audit are improved, and a more complete security framework is brought to the electronic document management system.
[0073] Next, the step of generating a unique key corresponding to the electronic seal based on a combination of a unique user identifier and a timestamp in a multi-user environment is further described; a unique key corresponding to the electronic seal can be generated based on a combination of a unique user identifier and a timestamp in a multi-user environment.
[0074] First, in the first step, an initial hash value is generated based on a unique user identifier and a current timestamp. For example, in one embodiment, each user has a unique identifier, which may be a user ID or other parameters that can identify the user, and the timestamp is accurate to the nanosecond level to ensure high granularity, which ensures that even two operations by the same user can generate different initial hash values due to different times, thereby ensuring that each generated key has a highly unique property.
[0075] Subsequently, the initial hash value obtained previously is encrypted by an asymmetric encryption algorithm. This process forms the final key. In this scenario, a common method in public key cryptography, such as the RSA algorithm, is selected for operation. It relies on a pair of mathematically related keys for encryption and decryption, one of which is used for public encryption and the other is used for private decryption. This method ensures that even under the same environmental factors, the two keys will not be repeated; for the formula, e is one of the public keys and its selection must ensure that e and phi (φ) are mutually prime, d is the private key, and n is the product of two large prime numbers. In the RSA encryption process, ciphertext = (plaintext^e) mod n needs to be solved. The ciphertext in the formula refers to the encrypted text, that is, the encrypted hash value; plaintext represents the information to be encrypted, which is the hash value here; for security reasons, larger e and d are usually selected and n must be long enough to make it unrealistic to crack.
[0076] Another point worth noting is that the random number factor R is introduced into the key generation process to improve the overall randomness and complexity of the key, such as by adding or XORing it to the hash input string; in an example, suppose an organization is creating an important electronic contract and intends to use the above method to obtain secure and effective signature verification. At this time, the string formed by the UID of the specific user (such as Zhang San’s work ID: EMP123) plus the current exact date and time will be used as the main component, and the random number R will be added to form the source string, which is then processed according to the steps described above to obtain a valid and unique signature key that belongs only to this operation.
[0077] The last step is to compare the newly constructed key with all the past keys in the historical records. Specifically, if there is any overlap, the key regeneration program will be started to go through the above series of processes again. This eliminates any potential risk of key reuse from a mechanism perspective.
[0078] The entire mechanism not only enhances the level of identity authentication during internal data exchange within the system, but also greatly guarantees the authenticity, reliability, and anti-tampering features of electronic document transmission. In summary, this improvement measure effectively improves the ability to provide precise services for different subjects and occasions and protect information security.
[0079] Next, the initial hash value and encryption steps of the present invention are described, which further;
[0080] Select the SHA256 hash algorithm as the basic hash function. SHA256 is a widely used and verified secure hash algorithm that can provide high efficiency and stability of calculation results. By performing a hash conversion on the electronic document data, SHA256 outputs a fixed-length and uniquely corresponding hash value, ensuring the consistency and integrity of the original data in the electronic seal management system without being interfered by the outside world. For example, when a user submits a file containing a signature application form to the server, the system uses SHA256 to process the file for the first time to ensure that any subsequent changes can be detected.
[0081] Subsequently, the result obtained from the hash algorithm and the entire original information to be processed are encrypted using the RSA asymmetric encryption method. This technology involves two independently used secret keys - a pair of public and private keys. The public key can be publicly distributed for encrypting the transmitted content. Only the corresponding private key can decode it to restore the original plaintext state. This method greatly increases the risk of being cracked during data transmission and ensures the authenticity and credibility of both parties through a strict authentication process. Specifically, in one embodiment, when an enterprise wants to use an electronic signature service, it first uses the public key in the legal authorization certificate (such as a digital certificate) provided by the customer, and then encrypts the document to be stamped according to the established protocol and sends it to the server.
[0082] Set a conditional judgment formula to regulate the behavior during the process of generating random keys: Whenever the number of attempts exceeds the critical value, the range of the random number factor R is adjusted to ensure that each newly generated key has a high degree of uniqueness. Here, the Cn parameter represents the round counter of the actual occurrence of creating a new password that has occurred cumulatively. Cm is an integer constant under a predefined upper threshold. 0 < Cm < the maximum threshold indicates that the maximum number of allowed retry generations must be between a positive value but lower than the specified security upper limit standard, thereby restricting the resource consumption caused by excessive unnecessary repeated attempts. The optimized degree of randomization aims to reduce the possible collision rate between keys. For example, specifically, after more than 15 consecutive attempts fail to generate a satisfactory new key, this logical rule will prompt the system to reduce the scale of the random number seed set or expand the boundary of the existing numerical fluctuation space.
[0083] The keys that have been successfully stored and have passed the inspection phase are stored in a specially established secure storage area - the key database, and are attached with a timestamp label to ensure that the action traces of each important node can be traced back, so as to facilitate the subsequent follow-up investigation and audit needs to be met and the work can be carried out smoothly; for example, in actual application scenarios, each newly created key with verified validity will be marked with the current exact generation date and time point, so that once a potential dispute occurs, the corresponding file details can be quickly located and viewed to assist in the analysis and determination of the truth of the incident.
[0084] Next, the following operations are specifically performed in the method based on introducing the random number factor R of the present invention: first, a group of pseudo-random sequences are randomly selected from a preset pseudo-random sequence library P, and the random number factor R is generated by conversion through a set mapping rule; this process utilizes complex transformation algorithms and non-repeatable characteristics to enhance the security and randomness of the generation; the purpose of random selection is to avoid predicting possible random number factors and to prevent any potential patterns from being exploited by attackers.
[0085] In one embodiment, assuming there is an electronic seal management system, when a user requests to generate a document with a digital signature, the system will select a set of preset pseudo-random sequences P according to the current configuration; these sequences are stored in a secure environment and updated periodically to improve confidentiality. Then, the selected P is mapped to the required random number factor R through a specific formula.
[0086] When creating a new key for the same ID, even if it is initiated at a similar time, it is necessary to ensure that the pseudo-random sequence P used is unique, that is, each instance should produce a different output result; for example, if two seal applications with the same name are made consecutively in a short period of time, although the interval between the two requests is very short, by adjusting the use of different pseudo-random sequences, it is ensured that the same random number factor R will not appear between the two, thereby enhancing uniqueness and security.
[0087] The formula for the corresponding relationship can be expressed as: if Ps (the previous random number sequence table number) is equal to Pt (the newly selected sequence number this time), and the time span between these two points is less than the minimum allowed value ΔT, then another sequence must be replaced as the basic data source for this operation; here ΔT is usually set to a few seconds to a few minutes, and the specific optimal value depends on the needs of the application scenario. For example, the application of electronic seals requires high efficiency while ensuring strong enough security, and a smaller value may be selected to prevent the risk of collision; if there is no extremely high requirement for speed, a larger ΔT can be selected to balance resource utilization efficiency; this design is intended to ensure that different generated instances within the same time period can produce completely different outputs even with the same input.
[0088] The final random number factor R is appended to the basic hash string to form a new string form; in this new composite form, not only the original characteristics are maintained but also an additional level of information protection is added, such as the timestamp or other variable attribute information in the stamping action of a document; specifically, this means that each issuance process not only contains the identification of the original data, but also includes a dynamically changing part, which is composed of random components generated in real time, thereby greatly improving the anti-tampering ability.
[0089] Next, the selection and mapping operations based on pseudo-random sequences of the present invention are described to further clarify the following process: first, in step 1, several different high-density seed sequences Seeds are initialized as alternative sets; these Seeds are generated by a specific algorithm or pattern, ensuring that each Seed has a high degree of security and randomness; the alternative set is used to provide a basis for diverse selection; specifically, in electronic seal management, for example, Seeds can be extracted from the output generated by a preset hash algorithm or historical encryption log records.
[0090] Next, in step 2, a weight factor W is added to evaluate the advantages or disadvantages of each candidate seed sequence; the weight calculation formula involves the internal characteristics of the parameter Seeds, such as length, displacement complexity and other attributes, and a comprehensive score is given through a scoring mechanism. The weight value W is between (0, 1), and the default minimum threshold Wl is set to 0.7. In this range, the closer W is to 1, the better the characteristic match is, and the more likely it is to become the selected element of the target system. In one embodiment, if a seed sequence has a higher compatibility and confidentiality level with the security policy of the existing system, the weight will be higher.
[0091] In the third step, the following logical expression is applied: When the weight W is less than the minimum qualified line Wl, the action of refreshing the available option pool is initiated. Here, Wl is set to ensure that the screened Seeds meet the minimum acceptable standard to avoid safety problems in subsequent processing due to poor quality. For example, when it is detected that the score of a candidate sequence is lower than the critical point, other more promising options will be reconsidered until a qualified one is found.
[0092] For the fourth step, a fast transformation operation is performed to transform the selected Seed to generate a new object P for use in the next step. This stage can include a variety of mathematical transformation methodologies such as permutation cryptography and other operations, the purpose of which is to enhance the concealment of the original data and the ability to resist predictive attacks. In specific implementation, the selected seed may be transformed through a specific function f(S) to generate a one-time key material for verifying the integrity or legitimacy of the electronic file.
[0093] Next, the selection and application details based on the seed sequence of the present invention are described more precisely as follows: a set of evaluation indicators are defined to measure the quality level Level of each candidate sequence. At this stage, the applicability of different seed sequences is evaluated through a series of clear standards. For example, in the electronic seal management method, these indicators include factors such as security, uniqueness, and compatibility with existing encryption systems. By considering multiple dimensions, a good foundation is laid for subsequent selection.
[0094] The score Dscore of each candidate is calculated based on the existing historical performance statistics, and an additional bonus is given in combination with the current scenario requirements. Specifically, information will be extracted from past data to understand the performance of each candidate in similar situations. For example, the number of times a certain type of seed has been successfully used to sign files without forgery in the past is used as an important reference point. At the same time, certain features will be weighted based on current special needs to ensure that the final decision is close to the actual application scenario.
[0095] If the comprehensive score Σ=Scorei+Bonusi reaches or exceeds the set threshold Sth, the sequence is locked, otherwise the search is iterated until a satisfactory candidate sequence is found; the comprehensive score mentioned here is composed of the above two parts, the parameter Scorei refers to the basic score for each candidate sequence, and its range depends on the initial designer's requirements for the entire system framework, while Bonusi represents the bonus points obtained for meeting specific circumstances; the purpose of setting up this mechanism is that only seeds that meet strict conditions are considered reliable choices; when there is no suitable match, the search range will continue to be optimized until the best result is obtained.
[0096] The linear congruential method is applied to the selected high-quality Seeds to generate P, preparing for the next step; in this process, the best candidate sequence will be selected and mathematical operations will be applied to generate a new random number P; this step ensures that the electronic seal is unique and unpredictable in each verification process; in one embodiment, assuming that after the first few rounds of strict screening, the candidate solution numbered Seed_012 is determined to have the highest Level value, so a linear congruential calculation is applied to the sample to obtain a new pseudo-random number P for the next stage of operation. In this way, a safe and efficient electronic seal management system is implemented.
[0097] Next, the newly added steps in the process of generating a unique key described above of the present invention are as follows;
[0098] First, an enhanced hash algorithm selection link is added. This link ensures that the hash function used has a higher anti-collision capability, effectively preventing attackers from trying to construct different inputs with the same hash value. This means that for any given input X1 and another different input X2, it is almost impossible to produce the same output Y. For example, when creating a unique electronic seal identification, an enhanced secure hash algorithm is used to process data strings containing timestamps, user IDs and other information, thereby greatly increasing the cost of counterfeiting and ensuring uniqueness.
[0099] Secondly, a time window restriction mechanism Wt is introduced to limit the validity period of the random number factor R to prevent the key from being vulnerable to cracking due to a long validity period. The random number is usually generated by the system in real time and is not permanently valid. Its validity is only maintained within a specific time. In one embodiment, before a government agency issues a digital certificate and stamps it, it first determines the current time as T0. The randomly generated verification code is only valid within the next hour (T1 = T0 + 1 hour). After this period, the verification code will automatically become invalid.
[0100] Then, a periodic checkpoint Tk is set up. Through this mechanism, it is possible to confirm in real time at any time whether the status of new or in-production keys is reliable, has not been tampered with, and is within expectations. Assuming that an enterprise-level application regularly performs a large amount of sensitive data transmission business every day, the new password string to be used in this transaction will be subject to compliance review at the beginning of each round of tasks and every few minutes; if it is detected that it does not meet the preset policy requirements, the related operation process will be immediately interrupted to prevent the situation from escalating.
[0101] In addition, control logic is set to deal with the situation where there are consecutive verification errors: if the number of consecutive verification errors Fk exceeds the set threshold Fl, the workflow should be immediately stopped and the abnormality troubleshooting process should be started to find the cause of the fault; in this context, the parameters are explained as follows:
[0102] - Fk is the number of accumulated errors;
[0103] - Fl represents the upper limit of the fault tolerance rate.
[0104] In terms of scope, Fk is a non-negative integer counter used to accumulate and record non-compliance situations; the specific value of Fl is determined according to different scenarios and actual security considerations. It is generally neither too low nor too high, so as not to affect normal operations and have strong enough security protection performance. A typical empirical value is selected between 0 and 5; this design aims to build a sound and stable error correction and recovery system to ensure that even if a small probability of unexpected problems occurs, it can be quickly adjusted back on track to ensure the stability and reliability of the overall service; for example, for an online financial service platform, when setting up the key verification mechanism, the maximum number of consecutive errors allowed is set to 3 times (Fl=3). Once this number is exceeded, it will be forced to stop, and then professional operation and maintenance personnel will intervene to evaluate the potential threat source until the danger signal is eliminated and the normal working mode is restored;
[0105] This series of measures combined together strengthens the security level of each link in the entire key creation and usage life cycle.
[0106] Next, the improved timestamp and hash generation scheme of the present invention is described, and new contents are added;
[0107] First, divide the 24 hours of a day into multiple sub-periods, so that the events in each period can obtain relatively independent and globally ordered time information. The time stamp in each sub-period is not only unique, but also can maintain the overall time continuity. This method is suitable for the time management of electronic seal usage records, ensuring that each use of the seal can be accurately traced back to a specific time interval.
[0108] In specific implementation, for example, when a document needs to be stamped, the system can divide it into a certain time period according to the specific time of affixing the electronic seal, accurate to minutes or shorter intervals, thereby giving this operation a unique time code. This can effectively prevent the problem of duplicate issuance, because even in high-frequency operations, each electronic issuance behavior will be accurately located and recorded, while retaining the time series relationship with other operations.
[0109] Next, a fixed-length binary bit L is used to represent the position of each sub-period, and the efficient query characteristics provided by these bit patterns are used to speed up the time point search speed; this method ensures the clear distinction of the time sequence and optimizes the retrieval process by mapping the time information in different partitions into unique binary strings; in one embodiment, in the electronic seal application scenario, when the user wants to view the specific time and situation of the last stamp on a specific file, this encoding mechanism allows the database to quickly locate the relevant data row; specifically, assuming that 12 bits are selected to represent the time period within a day, this means that a day can be cut into 2^12, or 4096 possible segments at most; this not only makes the system have good support for fine-grained time segments, but also can show excellent performance when facing large-scale data retrieval;
[0110] Then a mathematical model Y=a*T^2+b*T+c was introduced, where T is the average transaction interval, and a, b, and c are all constants. The parameters a, b, and c adjust their value ranges according to the specific network environment; when the goal is to set the formula from the perspective of balancing time and system pressure, in order to calculate an ideal transaction interval; the output Y of the expression reflects the expected response rate under the optimal ratio of time accuracy and system resource consumption; for example, when the electronic seal service requests in the business scenario become abnormally frequent and the server burden increases or response delays occur, the new T (average transaction waiting time) can be found by adjusting the parameters of the above formula in order to achieve a more reasonable resource allocation.
[0111] In addition, to verify the validity of this model, the verification rules require that in each time period, there must be only one N that satisfies the above quadratic function formula and the result falls within the predetermined range; in other words, it is to ensure that any single transaction occurring in each time period has a unique identity authentication tag, and to confirm the exact duration of each electronic signature operation accordingly; this step is crucial to maintaining the reliability of the system and preventing potential conflicts, because only in this way can the activity history of all users be clear and transparent. For example, when two adjacent documents complete the stamping process in different sub-periods and obtain different timestamps, the order of the two can be clearly defined, thereby avoiding trust issues caused by timestamp conflicts.
[0112] Next, the present invention is described in detail around the optimization of the time axis and sub-segment time management measures. First, a flexible segmentation rule is formulated according to the law of changes in the activity level within a natural day; that is, the most appropriate division of different segments is determined based on the daily activity distribution characteristics of users or systems; taking the electronic seal system as an example, in a working day, the early morning work period and the working time period from lunch break to the evening are often the most active stages; while in the early morning and late night, it is relatively low; accordingly, 24 hours can be divided into several time periods, such as 07:00 - 11:59, 12:00 - 18:59 and the rest are treated as special non-peak intervals, thereby achieving effective resource allocation and task scheduling optimization.
[0113] Secondly, a recursive search algorithm is implemented to determine the most similar adjacent point Adj as a reference base point to speed up positioning. This step aims to reduce the search range and speed up the target location confirmation process to improve efficiency. In one embodiment, for a time point of a request for stamping a document to be reviewed, the adjacent time node that is most similar to its activity pattern can be quickly found in the known active data set. This is done by comparing the behavioral characteristics in each adjacent time interval before and after the new request, and selecting the moment with the highest matching degree as the basic starting point.
[0114] Whenever the difference Dti between two time points Ti, Tj exceeds the preset tolerance Toler (tolerance refers to the upper and lower limits of the allowed error), and the pair of time points are in the same or continuous interval, the position markers Pl and Pr at the left and right ends need to be reallocated to ensure logical consistency; where the formula Dti = |Tj-Ti| represents the absolute distance from time i to time j, where Ti and Tj are a pair of ordered pairs randomly selected from the event sequence; Dti is the difference between the two nodes; when setting parameters, it should be ensured that the range of Toler is reasonable, that is, it can reflect normal business operation fluctuations without being overly sensitive; for example, when processing electronic document stamping business under high concurrency requests, the tolerance Toler may be set slightly larger to prevent frequent unnecessary adjustments; on the contrary, in important operations such as key approvals, a lower but more accurate tolerance will be more appropriate.
[0115] After all sub-segments are assembled to form a complete chain, a final inspection task needs to be performed to ensure that no abnormal disconnection occurs. This is a key step to verify whether the integration of all previous time segments has achieved a seamless connection state.
[0116] Next, the dynamic timeline and resource allocation of the present invention are further described in detail as follows:
[0117] First, a multi-level index tree structure TreeIndex is constructed to efficiently organize and manage data entities in different time zones. This structure can ensure time synchronization in the system and improve the efficiency of data search. Specifically, under a global distributed deployment, different branches may be located in different time zones. Therefore, building an index tree can enable each node to be stored in order according to the time zone information corresponding to its location. For example, in one embodiment, if the electronic seal management center is located in Beijing, Frankfurt and New York, a clearly hierarchical TreeIndex model will be established based on the time difference between the three regions to quickly locate relevant records within a specified time period.
[0118] Secondly, the regional adaptation strategy AreaScheme is designed in combination with the influence range of geospatial factors to further improve efficiency and accuracy. This means taking the influence of geographical location and surrounding environment into consideration to formulate the most appropriate service plan, thereby reducing latency and improving performance. For example, in one embodiment, if a user is located in an area where the network connection is not stable (such as a remote area or near the passage point of an international submarine optical cable), by enabling AreaScheme with specific parameters, the electronic seal verification system can give priority to using a more stable and fast method to complete the verification while ensuring security.
[0119] Then, a threshold judgment criterion is established: if the access volume Afreq of a certain node continues to maintain a high state (higher than the normal expected value Exp) during the past window Win, that is, if the calculated average frequency Avg is greater than or equal to α times Afreq, the branch path will be optimized and adjusted first. Among them, the parameters are defined as follows: Win is the preset time interval; Afreq represents the actual access frequency of the current node; Exp represents the maximum load level estimated in theory; α is an empirical coefficient used to amplify or reduce the critical value (usually 0.8 ≤ α ≤ 1.2, the optimal value depends on the specific business load characteristics). In practice, for example, when a company's headquarters server is under great pressure during working days (because it needs to frequently process electronic signature transactions on a large number of documents) and exceeds the usual empirical threshold, measures will be taken immediately to improve the relevant processes to prevent the overload problem from worsening and keep the system running smoothly.
[0120] Finally, the last round of comprehensive review of the overall process layout ensures that the architecture is reasonable and scalable. This work is an in-depth review to check whether there are potential risks or deficiencies. It covers all aspects and emphasizes the possibility of long-term development. In this process, it not only focuses on solving existing challenges, but also foresees possible new situations and plans corresponding response mechanisms in advance.
[0121] An electronic seal management method of the present invention comprises: effectively coping with the main technical challenges faced in electronic seal management through multiple steps and technical means, thereby providing a safer and more efficient management method;
[0122] Steps to generate a unique key:
[0123] The management method first involves generating a unique key for each electronic seal based on a unique user identification and timestamp combination in a multi-user environment. Specifically, the system captures the user's unique identity information, such as work number, name, role and other non-replicable biometrics (such as fingerprint or iris recognition results), and combines it with a timestamp obtained in real time. The timestamp not only ensures the uniqueness of the key, but also adds a security factor that changes over time, making it difficult to generate two identical keys even in a very short period of time. This method of constructing keys based on composite attributes can prevent the phenomenon of duplicate keys due to random probability in a multi-user environment, thereby ensuring the exclusivity and security of the key and avoiding the problem of consistency conflicts from the root. In addition, additional factors such as MAC addresses or other hardware information can be introduced to increase the complexity of the key.
[0124] Real-time dynamic control of usage rights:
[0125] As for the control of the use rights of electronic seals, the present invention adopts a monitoring system to achieve highly sensitive tracking and adjustment of authorization status. When a personnel change within the organization is triggered - that is, when a person leaves or is transferred - the system will respond immediately, and immediately update the identity verification information corresponding to the staff member through predetermined rules, and automatically cut off all access channels they previously held. This ensures that any change in authority can be quickly reflected in the actual operation, eliminating potential risk points caused by slow approval processes. The entire process can seamlessly transition to the new authority allocation system without human intervention, greatly improving the efficiency of authority management and execution. This is not just a simple revocation of old rights, but also the construction of a new environment that can flexibly respond to rapidly changing business scenarios, optimizing the user experience while protecting corporate interests from infringement.
[0126] Logging detail and storage location adjustment mechanism:
[0127] Finally, all operations related to the electronic seal are tracked and recorded in detail, and their sensitivity levels are assessed according to the set standards and then placed in designated storage areas. This strategy ensures that all information related to the use is retained, including but not limited to: When and by whom did which activity? Has any violation occurred to try to use the official seal? The answers to these questions will form a complete audit clue chain; and it is important to ensure that key information is always stored in a controlled environment, which is convenient for future inquiries, reviews, and even as a basis for legal liability. For example, low-level public operations may be stored directly in the local database, but high-level confidential actions need to be synchronized to cloud cold storage or dedicated facilities with stricter physical isolation protection, thus forming a multi-level protection framework to improve data reliability and anti-tampering capabilities. This method solves the problem of loopholes in audits due to scattered logs or missing details, and provides highly reliable data integrity guarantees, further enhancing the credibility and transparency of the overall system.
[0128] In summary, the combination of the above three core technologies constitutes the core content of the electronic seal management method described in this patent, which effectively solves the various requirements for digital asset security management in the context of complex enterprise informatization. This method is not only suitable for current enterprise management needs, but also has the potential for expansion to larger-scale systems in the future.
[0129] In one embodiment, an electronic seal management system is also disclosed. The evaluation system is executed by the above-mentioned electronic seal management method. Figure 2 As shown, the system includes:
[0130] A data generation module, wherein the data generation module is used to generate a unique key based on the user identity and usage context to prevent duplicate key generation;
[0131] A data mobilization module that allocates real-time and dynamically regulated usage rights based on the unique key and synchronizes the status to all relevant nodes;
[0132] The processing module collects the operation data with timestamps and sets the detail level of the electronic seal log records;
[0133] The storage module distributes detailed logs to multiple pre-configured storage locations according to security policies to ensure data integrity.
[0134] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. An electronic seal management method, characterized in that: include: S101, generating a unique key corresponding to the electronic seal based on a unique user identification and a timestamp combination in a multi-user environment; S102. Use the monitoring system to dynamically control the electronic seal usage rights in real time to ensure that the electronic seal usage rights of the personnel who leave the company or change positions become invalid immediately; S103, generating detailed log records according to authority changes and seal usage operations; S104, regulating the storage location of log records according to security levels to ensure integrity verification of audit data; The step of generating a unique key corresponding to the electronic seal based on a unique user identification and a timestamp in a multi-user environment further includes: Generate an initial hash value based on the unique user ID and the current timestamp to ensure the uniqueness of each key; The initial hash value is encrypted using an asymmetric encryption algorithm to form a final key, thereby preventing key duplication caused by the same environmental parameters; Introducing a random number factor R during the generation process to enhance the randomness and complexity of the key; Check whether the newly generated key is the same as all the keys in the historical key library. If the same key is detected, the key regeneration process is triggered; Based on the initial hash value and encryption steps, it further includes: The hash algorithm SHA256 is selected as the basic hash function to ensure the stability and efficiency of the hash calculation results; Use RSA asymmetric encryption to process the received raw data to increase the difficulty of cracking. RSA is a public key encryption system standard to ensure the security and reliability of key transmission; Set a formulaic conditional judgment statement: For each key generation operation, if the number of generation times Cn is greater than the critical value Cm, the range of the random number factor R is adjusted. That is, when the number of generation times exceeds the limit, the distribution of the random number factor R will be automatically optimized to reduce the probability of overlap; The meaning of the formula is: in the process of multiple attempts to generate a unique key, the generation strategy is adjusted in time by limiting the number of generation times to ensure that each generated key is unique; here Cn represents the actual number of generation times, and Cm is the maximum reasonable number of retries set in advance; Store successfully generated and verified keys in the key database and add a time stamp for subsequent auditing.
2. The electronic seal management method according to claim 1, characterized in that: The method based on introducing the random number factor R specifically performs the following operations: A set of preset pseudo-random sequences P is randomly selected, and a random number factor R is obtained through mapping to ensure the unpredictability of the random number factor R; When a new key is generated using the same identifier ID, different Ps are used within the same time period to ensure that different instances produce different results; The corresponding relationship is formally described as follows: if the last random selection sequence index Ps is equal to the current selection sequence number Pt, and the time difference T is not greater than the minimum allowed value ΔT, then another pseudo-random sequence is replaced, where Ps and Pt refer to the order numbers before and after the two generation actions respectively; and ΔT refers to the minimum time interval between the two generation events; The final random number factor R value is appended to the basic hash string to form an enhanced intermediate form.
3. The electronic seal management method according to claim 2, characterized in that: The selection and mapping operations based on the pseudo-random sequence further clarify the following process: Initialize several different high-density seed sequences Seeds as candidate sets; Add a weight factor W to evaluate the advantages or disadvantages of each candidate seed sequence, and select the most suitable Seeds as the core component of this generation according to a certain scoring mechanism; Apply the logical expression: If the weight W is less than the minimum qualified line Wl, then force a refresh of the available option pool to find seeds with better quality; Perform a fast transformation operation to convert the selected Seed and generate the corresponding P for reference in the next step.
4. The electronic seal management method according to claim 3, characterized in that: The selection and application details based on the seed sequence are more precise: Define a set of evaluation indicators to measure the quality level of each candidate sequence; The Dscore of each candidate is calculated based on the existing historical performance statistics, and an additional bonus is given based on the current scenario requirements; If the comprehensive score Σ=Scorei+Bonusi reaches or exceeds the set threshold Sth, the sequence is locked, otherwise the search is iterated until a satisfactory candidate sequence is found; The linear congruential method is implemented on the selected high-quality Seeds to generate P, preparing for the next step.
5. The electronic seal management method according to claim 4, characterized in that: The newly added steps in the above process of generating a unique key are as follows: Enhanced hash algorithm selection process to ensure higher anti-collision capability; The time window limitation mechanism Wt is introduced to limit the validity period of the random number factor R within a specified range to prevent the key from being cracked within a long validity period; Establish a periodic checkpoint Tk to verify the validity and security of the new key being generated or just generated in real time; The following formula is used for control: Assuming that the number of consecutive failed verifications Fk exceeds the predetermined upper limit Fl, the current workflow is stopped immediately and a diagnosis and analysis of possible problems is performed; The formula here aims to establish a complete fault-tolerant recovery mechanism. Fk refers to the cumulative number of errors, and Fl refers to the maximum acceptable fault-tolerant limit.
6. The electronic seal management method according to claim 5, characterized in that: Based on the improved timestamp and hash generation scheme, new additions include: The time axis is divided into multiple sub-periods, so that the events in each period can obtain relatively independent but globally ordered time information; Allocate fixed-length binary bits L to represent the position of each subparagraph, and use its encoding characteristics to accelerate matching searches; In order to balance the relationship between fine time granularity and system load, a dynamic trade-off model is proposed, which is described by the mathematical formula Y=a*T^2+b*T+c; Verify the consistency of the generated results and confirm that only a unique positive integer represents the time scale position N in each segment.
7. An electronic seal management method according to claim 6, characterized in that: The specific measures for optimizing the timeline and sub-segment time management are as follows: Formulate flexible segmentation rules based on the natural daily activity level changes; Implement a recursive search algorithm to determine the closest adjacent point Adj as a reference point to speed up positioning; Formula expression logic: Whenever the difference Dti between two time points Ti, Tj exceeds the tolerance Toler and is located in the adjacent interval, the time position mark Pl, Pr is reallocated, where Dti=TjTi represents the absolute distance between two adjacent points; After assembling the complete chain consisting of all fragments, perform the end inspection task to ensure that there are no abnormal breakpoints; The dynamic timeline and resource allocation are further described in detail as follows: Construct a multi-level index tree structure TreeIndex to efficiently organize and manage data entities in different time zones; Designing the regional adaptation strategy AreaScheme based on the impact range of geospatial factors improves efficiency and accuracy; Establish threshold judgment criteria: If the number of visits to a node Afreq has always remained high during the window Win for a period of time, that is, Avg>α*Afreq, then the branch path will be optimized and adjusted first, where Avg is the average frequency in the window and α is the amplification factor; The final round of comprehensive review of the overall process layout ensures that the entire system architecture is scientific, reasonable and scalable.
8. An electronic seal management system, characterized in that: The system is executed by an electronic seal management method according to claim 7, and the system comprises: A data generation module, wherein the data generation module is used to generate a unique key based on the user identity and timestamp to prevent duplicate key generation; A data mobilization module that allocates real-time and dynamically regulated usage rights based on the unique key and synchronizes the status to all relevant nodes; The processing module collects the operation data with timestamps and sets the detail level of the electronic seal log records; The storage module distributes detailed logs to multiple pre-configured storage locations according to security policies to ensure data integrity.
Citation Information
Patent Citations
Mobile office data security access system based on encrypted mirror image transmission
CN118433704A
Block chain-based aviation equipment purchasing electronic seal generation method and system
CN119477332A