Multi-level file approval management method and system

By using two independent servers in a collaborative office system for file encryption, decryption and encryption search, the problems of file security and efficiency in the multi-level file approval process in the existing technology are solved, and efficient and secure file approval management is achieved.

CN120030575AActive Publication Date: 2025-05-23JIANGXI CHATAOMAO NETWORK TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510494998.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-05-23
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

In the multi-level document approval process in the collaborative office system, a large-capacity collaborative editing system is required, and the collaborative editing system needs to be fully trustworthy, otherwise the approval documents will be easily lost or tampered with.

Method used

Through two independent servers as data transfer stations, the target files and signature files are encrypted and decrypted separately, avoiding malicious approval after deciphering a single file. At the same time, files are extracted separately through encrypted searches, improving processing efficiency and data security.

Benefits of technology

It realizes the efficiency and security of multi-level document approval, avoids the risks brought about by single file decoding, and improves the efficiency and security of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030575A_ABST
    Figure CN120030575A_ABST
Patent Text Reader

Abstract

The invention discloses a multilevel file approval management method and system, and belongs to the technical field of data encryption. In the invention, an application end encrypts a target file through a first data server, generates a first ciphertext and a first encryption tree, and sends the first ciphertext and the first encryption tree to a cloud end; and the data end encrypts the signature file through a third data server, generates a second ciphertext and a second encryption tree and sends the second ciphertext and the second encryption tree to the cloud end. Two groups of independent servers are used as data transfer stations to respectively complete encryption and decryption of a target file and a signature file, so that malicious approval after decoding of a single file is avoided, meanwhile, the files are respectively extracted through encryption search, and the working efficiency and the data security are improved. And the approval end searches the first encryption tree and the second encryption tree based on the cloud to obtain a first ciphertext and a second ciphertext, and decrypts the first ciphertext and the second ciphertext through the second data server to obtain the target file and the signature file, thereby completing approval. Furthermore, the approval result is confirmed by checking the execution parameter, and a data processing closed loop is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular to a multi-level document approval management method and system. Background Art

[0002] In a collaborative office system, multi-level approval of documents requires the establishment of a special data transfer station. For example, Chinese patent publication number CN115115353A discloses a method for approval and approval content generation based on document content. This method obtains the file unique identifier of the approval document according to the application submission approval operation, and sends the file unique identifier and approval version identifier as additional content to the collaborative editing system through the approval file interface with the approval document. The approval end extracts the annotation content and the updated approval document from the collaborative editing file. This application uses the collaborative editing system as a transfer station to improve the work efficiency of document approval. This method requires a large-capacity collaborative editing system, and the collaborative editing system needs to be completely trustworthy, otherwise the approval document is easily lost or tampered with. In view of this, the existing technology needs further improvement. Summary of the Invention

[0003] In order to solve the defects of the above-mentioned existing technologies, the present invention proposes a multi-level file approval management method and system. The present invention uses two independent servers as data transfer stations to complete the encryption and decryption of target files and signature files respectively, avoiding malicious approval after a single file is deciphered. At the same time, files are extracted separately through encrypted search to improve processing efficiency and data security.

[0004] The technical solution of the present invention is achieved as follows: A multi-level document approval management method includes the following steps: Step 1: The applicant generates authentication parameters, and the supervision server generates security parameters, system public key, and system private key based on the authentication parameters; Step 2: The applicant sends the multiple target files and the first relationship table to the first data server and the supervision server, and the data end sends the signature file to the third data server; Step 3: The first data server generates a signature for the target file, encrypts the first relational table based on the system public key to generate an encryption table, encrypts the target file based on the security parameter to generate a first ciphertext and a first encrypted tree, and then uploads the signature, encryption table, first ciphertext, and first encrypted tree to the cloud; Step 4: The third data server encrypts the signature file based on the security parameters and authentication parameters, generates a second ciphertext and a second encrypted tree, and uploads them to the cloud; Step 5: The second data server downloads and decrypts the encrypted table to obtain the first relationship table, generates a third ciphertext based on the first relationship table, and uploads it to the cloud; Step 6: The cloud searches the first encryption tree based on the third ciphertext to obtain the first ciphertext, and sends the first ciphertext to the second data server; Step 7: The second data server decrypts the first ciphertext based on the security parameter to obtain the target file, and verifies the signature based on the target file. If the verification is successful, the target file is dispatched to the approval end according to the first relationship table, and the process proceeds to Step 8. Otherwise, the process ends. Step 8: The approval end generates a search term and uploads it to the second data server. The second data server encrypts the search term to generate a fourth ciphertext and uploads it to the cloud. Step 9: The cloud searches the second encryption tree based on the fourth ciphertext to obtain the second ciphertext, and sends the second ciphertext to the second data server. The second data server decrypts the second ciphertext to obtain the signature file and sends it to the approval end.

[0005] The present invention also includes step 10: the approval end generates execution parameters and sends them to the supervision server, the supervision server updates the target file and the first relationship table according to the execution parameters and sends them to the application end. If the first encryption tree is empty, the program ends, otherwise returns to step 6.

[0006] In the present invention, in step 2, the target file includes the number, name, content, signature of the applicant, and the target file issuance time. The name of the target file includes the name of at least one approval end, and the content of the target file includes the name of the signature file. The first relationship table is the mapping relationship between the number of the target file and the number of the approval end.

[0007] In the present invention, in step 3, the first data server uses a hash function to convert the name of the target file into a first hash value, encrypts the first hash value based on the system public key to generate a signature, H1=h(N1), h() is the hash function, N1 is the name of the target file, H1 is the first hash value, and uses a symmetric encryption algorithm to encrypt the target file based on the security parameters and the number of the approval end to generate a first ciphertext. The node D1 of the first encryption tree is D1={ID1, V, V1, V2, FID}, ID1 is the first identifier, V is the frequency vector of the node of the first encryption tree, V1 is a pointer to its left child node, V2 is a pointer to its right child node, FID is the target file identifier, and each leaf node of the first encryption tree uniquely corresponds to a target file.

[0008] In the present invention, in step 4, the authentication parameters include the target file issuance time, the names of all target files, the total number of target files, and the signature of the applicant. The aggregate key r3 is generated based on the security parameter r1 and the authentication parameter r2. The signature file is encrypted based on the aggregate key to generate a second ciphertext. The node D2 of the second encryption tree = {ID2, V3, V4, V5, SID}, ID2 is the second identifier, V3 is the frequency vector of the node of the second encryption tree, V4 is a pointer to its left child node, V5 is a pointer to its right child node, SID is the signature file identifier, and each leaf node of the second encryption tree uniquely corresponds to a signature file.

[0009] In the present invention, in step 5, the second data server decrypts the encryption table based on the system private key to obtain the first relationship table, extracts the number of the approval end in the first relationship table, sorts the number of the approval end, obtains the name of the approval end according to the number of the approval end, encrypts the name of the approval end based on the security parameters and the number of the approval end to generate a third ciphertext and inputs it into the cloud.

[0010] In the present invention, in step 7, the second data server decrypts the first ciphertext based on the security parameters and the number of the approval end to obtain the target file, decrypts the signature based on the system private key to generate a first hash value, and uses a hash function to convert the name of the target file into a second hash value. If the first hash value is equal to the second hash value, the verification is successful.

[0011] In the present invention, in step 8, the approval end extracts the name of the signature file in the target file to generate a search term and uploads it to the second data server. The second data server extracts the names of all target files and the total number of target files according to the first relationship table, generates authentication parameters, generates an aggregation key based on the security parameters and the authentication parameters, encrypts the search term based on the aggregation key to generate a fourth ciphertext and uploads it to the cloud.

[0012] In the present invention, in step 10, the execution parameters include the target file issuance time, the name of the target file, the signature of the applicant, the number of the applicant, and the target file execution time. The supervision server verifies the execution parameters based on the authentication parameters and the first relationship table. If the verification is successful, the target file and the first relationship table will be updated and sent to the applicant.

[0013] A system for implementing the multi-level document approval management method includes: a supervision server, an application terminal, a data terminal, a first data server, a second data server, a third data server, a cloud, and an approval terminal, wherein: The supervision server generates security parameters, system public key and system private key; The applicant sends the multiple target files and the first relationship table to the first data server and the supervision server; The data terminal sends the signature file to the third data server; The first data server generates a first ciphertext based on the security parameter and an encryption table based on the system public key, and uploads the result to the cloud; The third data server generates a second ciphertext based on the security parameters and the authentication parameters and uploads it to the cloud; The approval end uploads the search term to the second data server; The second data server decrypts the encrypted table based on the system private key to obtain the first relationship table, then decrypts the first ciphertext to obtain the target file, decrypts the second ciphertext to obtain the signature file, and distributes the target file and the signature file to the approval end.

[0014] The implementation of the multi-level file approval management method and system of the present invention has the following beneficial effects: the application end of the present invention encrypts the target file through the first data server, generates a first ciphertext and a first encrypted tree, and sends them to the cloud. The data end encrypts the signature file through the third data server, generates a second ciphertext and a second encrypted tree, and sends them to the cloud. The approval end searches the first encrypted tree based on the cloud to obtain the first ciphertext, searches the second encrypted tree based on the cloud to obtain the second ciphertext, and extracts the target file by uploading and encrypting the search separately, thereby improving processing efficiency and data security. The present invention generates a signature through the first data server and uploads it to the cloud, and the second data server verifies the signature to ensure the integrity and correctness of the first ciphertext. By completing the encryption and decryption of the target file and the signature file separately, malicious approval is avoided after a single file is deciphered. Furthermore, after the approval is completed, the present invention confirms the approval result by verifying the execution parameters to achieve a closed loop of data processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a flow chart of the multi-level document approval management method of the present invention; Figure 2 A network topology diagram for data interaction between the supervisory server of the present invention; Figure 3 is a schematic diagram of the mapping relationship of the first relationship table of the present invention; Figure 4 Schematic diagram of generating and verifying signatures for the present invention; Figure 5 A schematic diagram of target file encryption and decryption according to the present invention; Figure 6 A schematic diagram of encryption and decryption of a signature document according to the present invention; Figure 7 A flow chart of verifying execution parameters of the present invention; Figure 8 A schematic diagram for generating security parameters for the present invention; Figure 9 is a schematic diagram of the first encryption tree of the present invention; Figure 10This is a network topology diagram of the system for implementing the multi-level document approval management method of the present invention. DETAILED DESCRIPTION

[0016] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.

[0017] In the existing multi-level document approval management process, the applicant stores the target file and signature file in distributed storage nodes. While this method can prevent data leakage, it increases the applicant's workload, makes it more difficult for other terminals to obtain data, and reduces work efficiency. By encrypting the target file and signature file and transmitting them to the cloud through different ports, malicious approval after a single file is decrypted is prevented. This also facilitates approval by the approval terminal, improves work efficiency through encrypted search, and ensures data security. Example 1

[0018] like Figures 1 to 9 As shown, a multi-level document approval management method includes the following steps.

[0019] Step 1: The applicant generates authentication parameters, and the supervision server generates security parameters, system public key and system private key based on the authentication parameters. The authentication parameters include the target file issuance time, the names of all target files, the total number of target files, and the signature of the applicant. The generation method of security parameters, system public key and system private key is as described in Example 2. Figure 2 During system initialization, the supervisory server sends the system public key and security parameters to the first data server, the security parameters and authentication parameters to the third data server, and the system private key and security parameters to the second data server. Security parameters are the keys of a symmetric encryption algorithm that can encrypt and decrypt plaintext.

[0020] Step 2: The applicant sends multiple target files and the first relationship table to the first data server and the supervisory server. The data server sends the signature file to the third data server. The target file includes its number, name, content, the applicant's signature, and the target file's issuance time. The target file's name includes the name of at least one approval party, and the target file's content includes the name of the signature file. The first relationship table maps target file numbers to approval party numbers, with the mapping consisting of multiple target file numbers mapped to one approval party number.

[0021] In this embodiment, if Figure 3 The target file numbers include: a1, a2, a3, a4, a5, a6, a7, the approval end numbers include: b1, b2, b3, the corresponding relationship of the first relationship table is represented by matrix A 7×3 Expressed as: 0 indicates no corresponding relationship, and 1 indicates a corresponding relationship. When storing the first relationship table, only the target file number, the approval end number, and the matrix need to be stored. The target file number, the approval end number, and the matrix are encrypted using the system public key to generate an encryption table. The encryption algorithm based on the system public key is, for example, the RSA algorithm.

[0022] Step 3: The first data server generates a signature for the target file, encrypts the first relational table based on the system public key to generate an encryption table, encrypts the target file based on the security parameter to generate the first ciphertext and the first encrypted tree, and then uploads the signature, encryption table, first ciphertext and the first encrypted tree to the cloud. Figure 4 The first data server uses a hash function to convert the name of the target file into a first hash value, and encrypts the first hash value based on the system public key to generate a signature. H1=h(N1), SIGN(SK, H1)→sign, h() is the hash function, N1 is the name of the target file, H1 is the first hash value, SIGN() is the signature algorithm, SK is the system public key, and sign is the signature. Figure 5 First, the target file is encrypted using a symmetric encryption algorithm based on the security parameter to generate an intermediate ciphertext, and then the intermediate ciphertext is encrypted again using a symmetric encryption algorithm based on the approval terminal number to generate the first ciphertext. The method for generating the first encrypted tree is described in detail in Example 3.

[0023] Step 4: The third data server encrypts the signature file based on the security parameters and authentication parameters, generates the second ciphertext and the second encryption tree, and uploads them to the cloud. Figure 6 The aggregate key r3 is generated based on the security parameter r1 and the authentication parameter r2, KDF(r1, r2)→r3, where KDF() is a key derivation function. When using the key derivation function, the security parameter is set to a salt value. The authentication parameter includes multiple sub-parameters: the target file delivery time, the names of all target files, the total number of target files, and the signature of the applicant. Based on the key derivation function and the security parameter, the multiple sub-parameters included in the authentication parameter are aggregated to generate an aggregate key. The signature file is encrypted using the aggregate key to generate a second ciphertext. The method for generating the second encrypted tree is described in detail in Example 3.

[0024] Step 5: The second data server downloads and decrypts the encrypted table to obtain the first relationship table. Based on the first relationship table, it generates a third ciphertext and uploads it to the cloud. The second data server decrypts the encrypted table using the system private key to obtain the first relationship table. It extracts the approval endpoint numbers from the first relationship table, sorts the approval endpoint numbers, and obtains the approval endpoint names based on the approval endpoint numbers. Using the encryption method used for the first ciphertext, it encrypts the approval endpoint names based on the security parameters and the approval endpoint numbers to generate a third ciphertext, ensuring that the third ciphertext has the same format as the first ciphertext. The third ciphertext is then input into the cloud for easy searching within the first encrypted tree. The encrypted approval endpoint names are then searched within the first encrypted tree to prevent information leakage caused by cloud-based keyword extraction.

[0025] Step 6: The cloud searches the first encrypted tree based on the third ciphertext, obtains the first ciphertext, and sends the first ciphertext to the second data server. i 、...、w I},w i is the ith keyword in the keyword set, I is the number of keywords, and the third ciphertext is converted into the first target frequency vector [c 11 , c 12 ,...,c 1i ,...,c 1I ], c 1i The frequency vector of each node in the first encryption tree is searched based on the first target frequency vector and the greedy best-first search algorithm. The specific search process is described in detail in Example 3. The first target frequency vector represents the mapping of the third ciphertext to the keyword set.

[0026] Step 7: The second data server decrypts the first ciphertext based on the security parameter to obtain the target file, and verifies the signature based on the target file. If the verification is successful, the target file is sent to the approval end according to the first relationship table and the process goes to step 8. Otherwise, the process ends. Figure 5 As described above, since the encryption process of the first ciphertext uses a symmetric encryption algorithm, decrypting the first ciphertext is the reverse process of the encryption process. The second data server decrypts the first ciphertext based on the security parameter and the number of the approval end to obtain the target file. Figure 4 The first hash value is generated based on the signature decrypted by the system private key, and the name of the target file is converted into a second hash value using a hash function. If the first hash value is equal to the second hash value, the verification is successful.

[0027] Step 8: The approval end generates a search term and uploads it to the second data server. The second data server encrypts the search term to generate a fourth ciphertext and uploads it to the cloud. The approval end extracts the name of the signature file from the target file to generate a search term and uploads it to the second data server. The second data server extracts the target file numbers and the total number of target files from the first relationship table, searches for the name of the applicant based on the target file numbers, extracts the target file issuance time and the applicant's signature from the target file, generates authentication parameters, generates an aggregate key based on the security parameters and authentication parameters, encrypts the search term using the aggregate key to generate a fourth ciphertext, and uploads it to the cloud.

[0028] Step 9: The cloud searches the second encrypted tree based on the fourth ciphertext to obtain the second ciphertext, and sends the second ciphertext to the second data server. The second data server decrypts the second ciphertext to obtain the signature file and sends it to the approval end. Key data set {v1, v2, ..., v j ,...,v J}, v j is the jth key data in the key data set, J is the number of key data, and the fourth ciphertext is converted into the second target frequency vector [c 21 , c 22 ,...,c 2j ,...,c 2J ], c 2j The frequency vector of each node in the second encrypted tree is searched based on the second target frequency vector and the greedy best-first search algorithm. The specific search process is similar to the search for the third ciphertext in the first encrypted tree. The second target frequency vector represents the mapping of the third ciphertext to the key data set. Because the aggregate key is the secret key of the symmetric encryption algorithm, the second data server decrypts the second ciphertext using the aggregate key to obtain the signed document and sends it to the approval end.

[0029] Step 10: The approval end generates execution parameters and sends them to the supervisory server. The supervisory server updates the target file and the first relationship table based on the execution parameters and sends them to the applicant. If the first encrypted tree is empty, the process ends; otherwise, it returns to step 6. The approval end executes the target file based on the signature file to generate execution parameters. These execution parameters include the target file's issuance time, the target file's name, the applicant's signature, the applicant's serial number, and the target file's execution time. The supervisory server obtains authentication parameters and the first relationship table from the applicant and verifies the execution parameters based on the authentication parameters and the first relationship table. If verification is successful, the target file and the first relationship table are updated and sent to the applicant.

[0030] like Figure 7The supervision server first verifies whether the target file issuance time, target file name, and application end signature in the execution parameters are consistent with the target file issuance time, target file name, and application end signature in the authentication parameters. If they are consistent, the mapping relationship between the target file name and the target file number is obtained from the first data server, and the application end number in the execution parameters is verified to match the target file name according to the first relationship table and the mapping relationship. If they match, the supervision server verifies whether the sequence of the target file execution time and the target file issuance time in the execution parameters is correct. If correct, the number of all execution parameters is finally counted to verify whether the number of execution parameters exceeds the total number of target files in the authentication parameters. If not, the verification is successful, otherwise the verification fails. Example 2

[0031] like Figure 8 As shown, this embodiment further discloses a method for generating the security parameters, the system public key, and the system private key in step 1.

[0032] The method of generating security parameters based on authentication parameters can be: the character string of the target file delivery time is {m 11 、m 12 、m 13 、m 14 、m 15}, the string of the name of all target files is {m 21 、m 22 、m 23 、......、m 2K}, the total number of target files is a string of {m 31 、m 32 、m 33 、m 34 、m 35}, K is the number of characters in the names of all target files. First, concatenate the above three strings and convert them into a binary vector. Then, select a symmetric encryption algorithm, such as the AES-128 algorithm. The key length specified by the AES-128 algorithm is 128 bits. Determine whether the length of the binary vector exceeds 128 bits. Then, extract the first 128 bits of the binary sub-vector from the binary vector as the security parameter. If the length of the binary vector is less than 128 bits, fill it with the value 0.

[0033] The method for generating the system public key and the system private key can be: according to the elliptic curve key generation algorithm, the general equation of the elliptic curve is y 2 =x 3+ax+b, where x is the abscissa of the elliptic curve, y is the ordinate of the elliptic curve, a is the coefficient of the linear term, and b is the constant term. Two values ​​a and b are randomly selected from the target file delivery time to determine the base point G of the elliptic curve. The total number of target files is set as the system private key. The system public key = G × system private key. Example 3

[0034] like Figure 9 As shown, this embodiment further discloses a method for generating the first encrypted tree in step 3 and a search process for searching the first encrypted tree according to the third ciphertext.

[0035] The node D1 of the first encrypted tree is {ID1, V, V1, V2, FID}, where ID1 is the first identifier used to distinguish different nodes, V is the frequency vector of the node of the first encrypted tree, V1 is a pointer to its left child node, V2 is a pointer to its right child node, and FID is the target file identifier, which is also a pointer to the storage address of the file. Each leaf node of the first encrypted tree uniquely corresponds to a target file.

[0036] In this embodiment, the keyword set is {w1, w2, ..., w5}, the total number of target files is 6, and the target files are numbered 01, 02, 03, 04, 05, 06. The corresponding first encryption tree is as follows: Figure 9 As shown, the first encrypted tree contains a total of 10 nodes, where R is the root node, R 11 、R 12 、R 21 、R 22 is an internal node, R 23 、R 24 、R 31 、R 32 、R 33 、R 34 It is a leaf node.

[0037] First, determine the frequency vector, first identifier, and target file identifier of the leaf node. Since the leaf node has no left child node and right child node, V1 and V2 of the leaf node are null pointers. 31 ={31,[2,0,0,1,0],null,null,01},R 32 ={32,[0,0,0,1,0],null,null,02},R 33 ={33,[0,1,0,0,0],null,null,03},R 34 ={34,[0,0,1,1,0],null,null,04},R 23 ={23,[0,0,0,1,1],null,null,05},R24 ={24, [1, 0, 0, 1, 0], null, null, 06}, null represents a null pointer.

[0038] Then determine the pointer to the left child node, the pointer to the right child node, the first identifier, and the frequency vector of the internal node. Since the internal node does not point to a specific target file, the target file identifier of the internal node is a null pointer, and the frequency vector of the internal node is equal to the sum of the frequency vector of its left child node and the frequency vector of its right child node. 21 ={21,[2,0,0,2,0],31,32,null},R 22 ={22,[0,1,1,1,0],33,34,null},R 11 ={11,[2,1,1,3,0],21,22,null},R 12 ={12,[1,0,0,2,1],23,24,null}.

[0039] Finally, determine the root node's pointer to its left child, pointer to its right child, first identifier, and frequency vector. Because the root node doesn't point to a specific target file, the target file identifier for the root node is a null pointer. R = {00, [3, 1, 1, 5, 1], 11, 12, null}, completing the construction of the first encryption tree.

[0040] Node D2 of the second encrypted tree = {ID2, V3, V4, V5, SID}, where ID2 is the second identifier, which is unique for each node. V3 is the frequency vector of the node in the second encrypted tree. V4 is a pointer to its left child node. V5 is a pointer to its right child node. SID is the signature file identifier. The signature file identifier is unique, and signature files are distinguished by SID. Each leaf node of the second encrypted tree uniquely corresponds to a signature file. The construction method of the second encrypted tree refers to the construction method of the first encrypted tree.

[0041] Search process of searching the first encrypted tree according to the third ciphertext: When the first target frequency vector of the third ciphertext is [0,1,0,1,0], the cloud starts searching from the root node of the first encrypted tree according to the first target frequency vector, compares the size of the first target frequency vector with the frequency vector of the root node, and the frequency vector of the root node [3,1,1,5,1]> the first target frequency vector [0,1,0,1,0], then compares the first target frequency vector with R 11 The frequency vector of [2,1,1,3,0]>[0,1,0,1,0] is compared with the first target frequency vector R 12The frequency vector of [1,0,0,2,1]≯[0,1,0,1,0] does not need to be compared with R 12 The left child node and the right child node of R are compared to reduce the search time and speed up the search. Then the first target frequency vector is compared with R 21 The frequency vector of [2,0,0,2,0]≯[0,1,0,1,0] does not need to be compared with R 21 Compare the left child node and the right child node of , and further compare the first target frequency vector with R 22 The frequency vector of [0,1,1,1,0]>[0,1,0,1,0], then compare the first target frequency vector with R 33 The frequency vector of [0,1,0,0,0]≯[0,1,0,1,0] is finally compared with the first target frequency vector and R 34 The frequency vector of , that is, [0,0,1,1,0]≯[0,1,0,1,0], the search fails and returns an empty set. Example 4

[0042] like Figure 10 As shown, a system for implementing the multi-level document approval management method includes: a supervision server, an application terminal, a data terminal, a first data server, a second data server, a third data server, a cloud, and an approval terminal. The supervision server generates security parameters, a system public key, and a system private key, sends the system public key and security parameters to the first data server, sends the security parameters and authentication parameters to the third data server, and sends the system private key and security parameters to the second data server. The application terminal sends multiple target files and a first relationship table to the first data server and the supervision server. The data terminal sends a signed file to the third data server. The first data server generates a first ciphertext and a first encrypted tree based on the security parameters, and generates a signature and an encryption table based on the system public key, and uploads them to the cloud. The third data server generates a second ciphertext and a second encrypted tree based on the security parameters and authentication parameters, and uploads them to the cloud. The approval terminal uploads the search term to the second data server. The second data server decrypts the encrypted table using the system private key to obtain the first relationship table, generates the third ciphertext based on the first relationship table, encrypts the search term to generate the fourth ciphertext, and uploads it to the cloud. It then decrypts the first ciphertext to obtain the target file, decrypts the second ciphertext to obtain the signature file, and sends the target file and signature file to the approval end. The cloud stores the first ciphertext, the first encrypted tree, the signature, the encrypted table, the second ciphertext, the second encrypted tree, the third ciphertext, and the fourth ciphertext.

[0043] When executing the storage process, data transmission is completed through the data link. The first data server is linked to the application end, the second data server is linked to the approval end, and the third data server is linked to the data end. The first data server, the second data server, the third data server, and the supervision server are respectively linked to the router, and data is transmitted to each other through the link. The router is responsible for transmitting data from the first data server, the second data server, and the third data server to the supervision server and the cloud. In addition, the router is linked to the firewall to ensure that the data is not modified during the transmission process, avoid signature verification failure due to insecure data transmission, and improve the reliability of data transmission.

[0044] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A multi-level document approval management method, characterized in that: The following steps are involved: Step 1: The applicant generates authentication parameters, and the supervision server generates security parameters, system public key and system private key based on the authentication parameters; Step 2: The applicant sends the multiple target files and the first relationship table to the first data server and the supervision server, and the data end sends the signature file to the third data server; Step 3: The first data server generates a signature of the target file, generates an encryption table by encrypting the first relationship table based on the system public key, generates a first ciphertext and a first encrypted tree after encrypting the target file based on the security parameter, and then uploads the signature, encryption table, first ciphertext and first encrypted tree to the cloud; Step 4: The third data server encrypts the signature file based on the security parameters and authentication parameters, generates a second ciphertext and a second encrypted tree, and uploads them to the cloud; Step 5: The second data server downloads and decrypts the encrypted table to obtain the first relationship table, generates a third ciphertext based on the first relationship table, and uploads it to the cloud; Step 6: The cloud searches the first encryption tree based on the third ciphertext, obtains the first ciphertext, and sends the first ciphertext to the second data server; Step 7: The second data server decrypts the first ciphertext based on the security parameter to obtain the target file, verifies the signature based on the target file, and if the verification is successful, sends the target file to the approval end according to the first relationship table and goes to step 8, otherwise the program ends; Step 8: The approval end generates a search term and uploads it to the second data server. The second data server encrypts the search term to generate a fourth ciphertext and uploads it to the cloud. Step 9: The cloud searches the second encryption tree based on the fourth ciphertext to obtain the second ciphertext, and sends the second ciphertext to the second data server. The second data server decrypts the second ciphertext to obtain the signature file and sends it to the approval end.

2. The multi-level document approval management method according to claim 1 is characterized in that: It also includes step 10: the approval end generates execution parameters and sends them to the supervision server, the supervision server updates the target file and the first relationship table according to the execution parameters and sends them to the application end, if the first encryption tree is empty, the program ends, otherwise returns to step 6.

3. The multi-level document approval management method according to claim 1 is characterized in that: In step 2, the target file includes the number, name, content, signature of the applicant, and the time when the target file was issued. The name of the target file includes the name of at least one approval end, and the content of the target file includes the name of the signature file. The first relationship table is the mapping relationship between the number of the target file and the number of the approval end.

4. The multi-level document approval management method according to claim 3 is characterized in that: In step 3, the first data server uses a hash function to convert the name of the target file into a first hash value, encrypts the first hash value based on the system public key to generate a signature, H1=h(N1), h() is the hash function, N1 is the name of the target file, H1 is the first hash value, and uses a symmetric encryption algorithm to encrypt the target file based on the security parameters and the number of the approval end to generate a first ciphertext. The node D1={ID1, V, V1, V2, FID} of the first encrypted tree, ID1 is the first identifier, V is the frequency vector of the node of the first encrypted tree, V1 is a pointer to its left child node, V2 is a pointer to its right child node, FID is the target file identifier, and each leaf node of the first encrypted tree uniquely corresponds to a target file.

5. The multi-level document approval management method according to claim 4 is characterized in that: In step 4, the authentication parameters include the target file issuance time, the names of all target files, the total number of target files, and the signature of the applicant. The aggregate key r3 is generated based on the security parameter r1 and the authentication parameter r2. The signature file is encrypted based on the aggregate key to generate a second ciphertext. The node D2 of the second encrypted tree is {ID2, V3, V4, V5, SID}, ID2 is the second identifier, V3 is the frequency vector of the node of the second encrypted tree, V4 is a pointer to its left child node, V5 is a pointer to its right child node, SID is the signature file identifier, and each leaf node of the second encrypted tree uniquely corresponds to a signature file.

6. The multi-level document approval management method according to claim 5 is characterized in that: In step 5, the second data server obtains the first relationship table by decrypting the encryption table based on the system private key, extracts the number of the approval end in the first relationship table, sorts the number of the approval end, obtains the name of the approval end according to the number of the approval end, encrypts the name of the approval end based on the security parameters and the number of the approval end to generate a third ciphertext and inputs it into the cloud.

7. The multi-level document approval management method according to claim 6 is characterized in that: In step 7, the second data server decrypts the first ciphertext based on the security parameters and the number of the approval end to obtain the target file, decrypts the signature based on the system private key to generate a first hash value, and uses a hash function to convert the name of the target file into a second hash value. If the first hash value is equal to the second hash value, the verification is successful.

8. The multi-level document approval management method according to claim 7 is characterized in that: In step 8, the approval end extracts the name of the signature file in the target file to generate a search term and uploads it to the second data server. The second data server extracts the names of all target files and the total number of target files according to the first relationship table, generates authentication parameters, generates an aggregation key based on the security parameters and authentication parameters, encrypts the search term based on the aggregation key to generate a fourth ciphertext and uploads it to the cloud.

9. The multi-level document approval management method according to claim 2 is characterized in that: In step 10, the execution parameters include the target file issuance time, the target file name, the applicant's signature, the applicant's number, and the target file execution time. The supervision server verifies the execution parameters based on the authentication parameters and the first relationship table. If the verification is successful, the target file and the first relationship table will be updated and sent to the applicant.

10. A system for implementing the multi-level document approval management method of claim 1, characterized in that: include: A supervision server, an application terminal, a data terminal, a first data server, a second data server, a third data server, a cloud, and an approval terminal, wherein: The supervision server generates security parameters, system public key and system private key; The applicant sends the multiple target files and the first relationship table to the first data server and the supervision server; The data terminal sends the signature file to the third data server; The first data server generates a first ciphertext based on the security parameter and an encryption table based on the system public key, and uploads the result to the cloud; The third data server generates a second ciphertext based on the security parameter and the authentication parameter and uploads it to the cloud; The approval end uploads the search term to the second data server; The second data server decrypts the encryption table based on the system private key to obtain the first relationship table, then decrypts the first ciphertext to obtain the target file, decrypts the second ciphertext to obtain the signature file, and distributes the target file and the signature file to the approval end.

Citation Information

Patent Citations

  • Examination and approval method and device based on file content and approval content generation method and device

    CN115115353A

  • Symmetric searchable encryption method, device, equipment and medium

    CN112182630A

  • Searchable encryption method and system capable of flexibly replacing ciphertexts, and computer equipment

    CN113626484A

  • Lightweight forward and backward security public key authentication encryption keyword search method and system

    CN118509262A

  • Automated method and device for authentication and verification of documents

    EP3447716A1