Equipment and method for safely retrieving electronic archives
By using a controllable and separate sub-security device in the electronic file management system to store and manage electronic files, the problems of security risks and business correlation traceability of electronic file security offline borrowing in the prior art are solved, and a high security and flexible electronic file review method is realized.
Patent Information
- Application Number
- CN202510270179.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-24
AI Technical Summary
When the prior art realizes the secure offline borrowing of electronic files, there are risks of security risks and privacy leakage, and it is difficult to meet the needs of business correlation traceability during the audit process.
By controlling the separate sub-safety device to store the target file data packet and target constraint information, the user initiates a review download application through the offline review security device. The target file data packet and target constraint information directly enter the offline review security device from the electronic file management system, making it difficult for electronic files to be leaked and improving the security of retrieving electronic files.
It realizes the security of electronic files on demand under the electronic file management system deployed in the intranet. Users can easily obtain the required files through offline review of security devices, and improves the security and flexibility of data during use.
Smart Images

Figure CN120197212A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic file borrowing and transfer, and particularly to a device and method for securely accessing electronic files. Background Art
[0002] With the popularization and application of enterprise electronic file systems, more and more enterprises have shifted their business processing from offline to online, thus gradually eliminating the review and circulation of paper vouchers. Even more advanced enterprises (such as large group enterprises) have started to pilot the single-set system, where archival materials rely entirely on electronic materials. Usually, enterprise electronic files are deployed on the internal network to ensure the security of the files. The single-set system of electronic files refers to the process of converting traditional paper files into digital form and managing them through a set of standardized processes, methods, and systems.
[0003] However, in the case of isolation between the internal and external networks, the borrowing and transfer of electronic files cannot be carried out like paper files in the past, and there are many drawbacks. For example, it is impossible to submit for review as required by external review units such as the judiciary and tax authorities, which affects the normal audit work of accounting files.
[0004] The existing solution for offline borrowing of electronic files is to open the external network query permission and map or deploy the internal electronic file system to the Internet to achieve external network query. Although this method is convenient, it brings significant security risks and the risk of privacy leakage.
[0005] Another existing solution is to copy and package the files to be audited using a USB flash drive and copy them externally through the USB flash drive. Although this method can ensure a certain degree of physical security, due to the dispersion of the files, it is difficult to meet the requirements for tracing the business relevance during the audit process. In addition, the audit department cannot easily find relevant voucher materials according to the business line, and it is also impossible to completely prevent non-secure operations such as illegal stealing, spreading, tampering, or cutting of files. On this basis, some solutions use enterprise-level USB flash drives equipped with security measures for copying, thus improving partial security (such as preventing stealing), but still fail to solve the need of the audit unit to find the coherence of business data during external audits.
[0006] Another existing solution is to set up an electronic file management platform. When downloading from the electronic file management platform, the reading permission of the corresponding document is encrypted and controlled through a specific document encryption program, and the corresponding authorization information is written. Then, an encrypted offline data packet is generated. After the encrypted offline data packet is downloaded to the local, it is decrypted according to the borrower's certificate information for reading. However, after the borrower's certificate is leaked, the electronic files are prone to leakage, and the system still has relatively large security risks. Summary of the Invention
[0007] The first object of the present invention is to provide a device for securely accessing electronic files that improves the security of accessing electronic files.
[0008] The second object of the present invention is to provide a method for securely accessing electronic files with high security for accessing electronic files.
[0009] To achieve the above first object, the present invention provides a device for securely accessing electronic files, which includes: an offline access security device, and the offline access security device includes a plurality of controllable separable sub-security devices; the offline access security device is used for: obtaining an access and download application; allocating a target sub-security device to obtain a target file data packet and target constraint information corresponding to the access and download application from an external electronic file management system; releasing the target sub-security device; the target sub-security device is used for: determining the borrowing permission of the target file data packet according to the stored target constraint information; providing the content of the target file data packet according to the borrowing permission.
[0010] As can be seen from the above solution, the present invention stores the target file data packet and target constraint information through a controllable separable entity target sub-security device, so that the applicant of the electronic file can take away the target sub-security device, and the target sub-security device provides the content of the target file data packet according to the borrowing permission. The present invention obtains the required electronic files through an access and download application, so that the electronic file management system can still provide them on demand when deployed in the intranet, and the user needs to initiate an access and download application through the offline access security device, and the target file data packet and target constraint information directly enter the offline access security device from the electronic file management system, making it difficult for the electronic files to be leaked during this process and improving the security of accessing the electronic files. In addition, the sub-security device is plug-and-play, one-key viewable, extensible, and easy to carry, solving the problem of external audit file transfer caused by the isolation of the enterprise's internal and external networks and meeting the need to access specified topic files for mobile office (business trips, meetings).
[0011] A further solution is that after the access and download application passes the identity verification, the offline access security device allocates a target sub-security device to obtain a target file data packet and target constraint information corresponding to the access and download application from the electronic file management system.
[0012] Thus, only the access and download application that passes the identity verification can request to obtain the target file data packet and target constraint information, further improving the security of accessing the electronic files.
[0013] A further solution is that before the offline access security device receives the access and download application, the electronic file management system obtains an access request matching the access and download application, and audits the access request to determine the target file data packet and target constraint information.
[0014] It can be seen that only after the user submits a retrieval request in the electronic file management system and passes it, can the offline retrieval security device obtain the corresponding target file data packet and target constraint information when initiating a retrieval and download application, further improving the security of electronic file retrieval.
[0015] A further solution is that when the target sub-security device obtains the target file data packet and target constraint information from the electronic file management system, it includes: the target sub-security device downloads the target file data packet and target constraint information from the electronic file management system; or, the target sub-security device requests the target file data packet and target constraint information corresponding to the retrieval and download application from the electronic file management system, and downloads and stores the target file data packet and target constraint information in the target sub-security device.
[0016] It can be seen that the target file data packet and target constraint information can be stored in the target sub-security device in different ways.
[0017] A further solution is that when the target sub-security device downloads the target file data packet and target constraint information from the electronic file management system, it includes: the target file data packet and target constraint information are encrypted in the electronic file management system, the electronic file management system transmits the target file data packet and target constraint information to the target sub-security device through an encrypted channel, and the target sub-security device decrypts the target file data packet and target constraint information.
[0018] It can be seen that the security during the process of storing the target file data packet and target constraint information in the target sub-security device can be further improved.
[0019] A further solution is that the target constraint information includes one or any combination of the following: expiration date, geographical location range, MAC address.
[0020] It can be seen that the target constraint information can be determined according to the retrieval request, and the target constraint information can be jointly determined by the user and the reviewer, improving the security and flexibility of electronic file retrieval.
[0021] A further solution is that when the target constraint information includes the expiration date, when the target sub-security device detects a situation beyond the expiration date, it deletes the target file data packet.
[0022] It can be seen that the security of electronic file retrieval is further improved.
[0023] A further solution is that after the electronic file management system receives an extension request corresponding to the retrieval and download application, it generates a corresponding target extension verification code; the target sub-security device is also used to: obtain the input extension verification code and extend the expiration date according to the extension verification code.
[0024] Thus, a convenient online extension method is provided, which improves the flexibility of accessing electronic files.
[0025] A further solution is that when the target sub - security device provides the content of the file data packet according to the borrowing permission, it includes: connecting to an external terminal device through a data cable, and the file screen provided to the terminal device has visible watermarks and / or invisible watermarks.
[0026] Thus, it can be traced in time when leakage occurs.
[0027] To achieve the above - mentioned second object, a method for securely accessing electronic files provided by the present invention includes the following steps: The electronic file management system obtains a access request and reviews the access request to determine the target file data packet and target constraint information; The offline access security device obtains a access download application; The access download application matches the access request; The offline access security device allocates a target sub - security device to obtain the target file data packet and target constraint information corresponding to the access download application from an external electronic file management system; The offline access security device releases the target sub - security device; The target sub - security device determines the borrowing permission of the target file data packet according to the stored target constraint information; The target sub - security device provides the content of the file data packet according to the borrowing permission.
[0028] As can be seen from the above solution, after the electronic file management system of the present invention receives the access request from the applicant, it determines the corresponding target file data packet and target constraint information according to the access request. Then the applicant sends an access download application to the offline access security device to obtain the target file data packet and target constraint information and store them in the target sub - security device, and then takes away the target sub - security device, and realizes the access of the electronic file by viewing the content provided by the target sub - security device, which improves the security of accessing the electronic file. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 is a schematic structural diagram of an embodiment of the device for securely accessing electronic files of the present invention.
[0030] Figure 2 is a schematic structural diagram of the offline access security device in the embodiment of the device for securely accessing electronic files of the present invention.
[0031] Figure 3 is a schematic diagram of the use of the sub - security device in the embodiment of the device for securely accessing electronic files of the present invention.
[0032] Figure 4 is a system framework diagram of the electronic file management system and the offline access security system in the embodiment of the device for securely accessing electronic files of the present invention.
[0033] Figure 5It is the system framework diagram of the offline access subsystem in the device embodiment for securely accessing electronic files of the present invention.
[0034] Figure 6 It is the specific framework diagram of the data security management module in the device embodiment for securely accessing electronic files of the present invention.
[0035] Figure 7 It is the specific framework diagram of the file storage module in the device embodiment for securely accessing electronic files of the present invention.
[0036] Figure 8 It is the specific framework diagram of the validity period management module in the device embodiment for securely accessing electronic files of the present invention.
[0037] Figure 9 It is the flowchart executed by the electronic file management device in the method embodiment for securely accessing electronic files of the present invention.
[0038] Figure 10 It is the flowchart executed by the offline access security device in the method embodiment for securely accessing electronic files of the present invention.
[0039] Figure 11 It is the flowchart executed by the target sub-security device in the method embodiment for securely accessing electronic files of the present invention.
[0040] The present invention will be further described below in conjunction with the accompanying drawings and embodiments. Specific Embodiments
[0041] The secure electronic file access device and method of the present invention integrate hardware devices and software algorithms, and solve security problems such as permissions for offline access to electronic files, data scope, copy transmission, access, anti-tampering, theft, unlimited dissemination, and illegal terminal access without sacrificing convenience.
[0042] Embodiment of the Secure Electronic File Access Device:
[0043] See Figure 1 , this embodiment includes an electronic file management device 1 and an offline access security device 2, and the electronic file management device 1 is connected to the offline access security device 2 to achieve data transmission.
[0044] The electronic file management device 1 is used to store and manage multiple file data packets, where one file data packet corresponds to one electronic file, and is also used to review the received access requests. After the access request passes the review, it determines the target file data packet and target constraint information corresponding to the access request, and then provides the download of the target file data packet and target constraint information after receiving a download request that matches the access request.
[0045] The target file data packet is selected from multiple file data packets according to the access request, which represents the information of the file to be borrowed in the electronic files stored and managed by the electronic file management device 1 required by the access request. The target constraint information represents the set borrowing permission restrictions on the target file data packet, including one or any combination of the usage period, geographical location range, MAC address, identity information, and access range information. Among them, the usage period is used to limit the time period during which the target file data packet can be read, the geographical location range is used to limit the geographical location where the target file data packet can be read, the MAC address is used to limit the reading device required when the target file data packet can be read, the identity information is used to limit the users who can access the target file data packet, which can be specifically fingerprints, passwords, etc., and the access range information is used to limit the specific range of accessing the target file data packet. For example, it is used to limit that only specific chapters of the electronic file content corresponding to the target file data packet can be provided to the reading device.
[0046] See Figure 2 , the offline access security device 2 includes a plurality of controllable separable sub-security devices 21 and a control touch screen 22.
[0047] The offline access security device 2 is used to receive an access download application, authenticate the access download application, and after the access download application passes the authentication, send a download request corresponding to the access download application to the electronic file management device 1, and allocate a sub-security device from the plurality of sub-security devices 21 to obtain the target file data packet and the target constraint information corresponding to the access download application from the external electronic file management system, and release the selected sub-security device, and the selected sub-security device is the target sub-security device. Among them, the offline access security device 2 is provided with a plurality of locking components with controllable switches, and each locking component is used to fix a sub-security device, and releasing means that the offline access security device 2 controls the switch of the locking component so that the corresponding sub-security device can be separated from the offline access security device 2.
[0048] Each sub-security device 21 is used to store a file data packet and the constraint information corresponding to the file data packet, determine the borrowing permission according to the constraint information, and provide the content of the stored file data packet according to the borrowing permission.
[0049] A communication interface is provided on the sub-security device 21, and it can be connected to an external reading device through a matching communication data line, and then provide the content of the file data packet stored in the sub-security device 21 on the reading device according to the borrowing permission. See Figure 3 , the reading device can specifically be reading devices such as a personal computer 41 and a tablet computer 51.
[0050] The control touch screen 22 is used to obtain the input information of the user. For example, the user fills in the specific content of the access and download application on the control touch screen 22.
[0051] See Figure 4 , the secure access electronic file device of this embodiment further includes an electronic file management system 10 and an offline access security system 20. The electronic file management system 10 is connected to the offline access security system 20 to achieve data transmission. Among them, the electronic file management system 10 runs on the electronic file management device 1, and the offline access security system 20 runs on the offline access security device 2.
[0052] The electronic file management system 10 includes an archive offline borrowing review and authorization module 101, an archive data packet storage module 102, and an archive data security extraction module 103. Among them, the archive offline borrowing review and authorization module 101 is used to obtain a access request, which identifies applicant information and their access permissions, the archive information to be borrowed and their access data range, the expiration date of the borrowing time, the accessible geographical location and other information. The borrowing review and authorization module 101 reviews the access request, determines the target archive data packet and target constraint information corresponding to the access request after passing the review, and sends the corresponding authorization information to the archive data packet storage module 102.
[0053] The archive data packet storage module 102 maintains an electronic file database, which is used to receive the authorization information issued by the archive offline borrowing review and authorization module 101, prepare the corresponding target archive data packet according to the authorization information for encryption processing, ensure that the data blocks to be downloaded are cut from the complete data and sorted and format-converted as required, and ensure the security of the data copy process without being tampered with or stolen while improving the readability of the offline archives.
[0054] The archive data security extraction module 103 is used to transmit the previously prepared target archive data packet and target constraint information to the specified sub-security device through a secure encrypted data channel to prevent data, thereby preventing it from being stolen or tampered with during the transmission process.
[0055] The offline access security system 20 includes a device control module 201 and a sub-device management module 202.
[0056] The device control module 201 is used to receive the access and download application, authenticate the access and download application, and control and allocate the currently available sub-security devices to the access and download applications that pass the authentication.
[0057] The sub-device management module 202 includes a sub-device inventory unit and a sub-device unlocking unit. The sub-device inventory unit is used to determine the status of each sub-security device, such as in use and not in use, etc. The sub-device unlocking unit is used to control each sub-security device to be separated from the offline access security device so that it can be taken away by the user.
[0058] See Figure 5 , for each sub - safety device 21, an offline access - review subsystem 30 runs on it. The offline access - review subsystem 30 includes a data security management module 301, an archive storage module 302, and a validity - period management module 303. The data security management module 301 provides archives for data security protection. The archive storage module 302 is used to manage the stored archive data packets. The validity - period management module 303 is used to maintain the usage period of the stored archive data packets.
[0059] Specifically, see Figure 6 , the data security management module 301 includes an encryption - algorithm unit 3011, a positioning unit 3012, a device - detection unit 3013, an identity - authentication unit 3014, and an automatic - erasure unit 3015. The encryption - algorithm unit 3011 is used to decrypt the received archive data packets, and the decryption method matches the encryption method of the archive - data - packet storage module 102, that is, the same encryption and decryption algorithms are used. The positioning unit 3012 is used to determine the location of the sub - safety device 21 where it is located, which is specifically implemented through existing positioning technologies such as GPS, and cooperates with the geographical - location range in the stored constraint information to provide the content of the stored archive data packets only within a specific geographical range. The device - detection unit 301 is used to detect the MAC address of the connected reading device, and cooperates with the MAC address in the stored constraint information to provide the content of the stored archive data packets only when a specific reading device is accessed. The identity - authentication unit 3014 uses biometric or other strong - authentication technologies, and cooperates with the identity information in the stored constraint information, so as to ensure that only verified users can use the device and access the archives. The automatic - erasure unit 3015 is used to automatically delete the saved archive data packets when the set conditions are met. The set conditions can be set according to needs, for example, set to be used outside the geographical - location range or beyond the usage period.
[0060] See Figure 7 , the archive storage module 302 includes an archive - associated query unit 3021 and an archive - management unit 3022. The archive - associated query unit 3021 is used to provide the search function for the archive content of the archive data packets and the function of adding temporary labels. The search function is to search and locate the text and temporary labels of the archive content allowed to be read in the saved archive data packets. The function of adding temporary labels allows users to make some remarks on the upper layer of the archive - content page without changing the original data, which is convenient for data analysis and use comparison. The archive - management unit 3022 is used to provide the content of the archive data packets according to the borrowing permission, and bring the source identification in the picture through visible and / or invisible watermarks, and prohibit functions such as taking pictures, screen - capturing, copying, etc., and form a viewing log of information such as the viewer and the viewing location and save it inside the sub - safety device.
[0061] SeeFigure 8 The validity period management module 303 includes a validity period verification unit 3031 and an extension verification code verification unit 3032. The validity period verification unit 3031 is used to determine the current time. When the current time exceeds the usage period in the saved constraint information, it notifies the automatic erasure unit 3015 to delete the saved archive data packet. The verification code verification unit 3032 is used to verify the input extension verification code. When the extension verification code passes the verification, it extends the usage period in the saved constraint information.
[0062] In some different embodiments, the secure access electronic archive device may not include an electronic archive management device. For example, if some enterprises have already built an electronic archive management device and an electronic archive management system is running, the offline access security device can directly dock with the electronic archive management system to jointly implement the secure access electronic archive device of the present invention.
[0063] Embodiment of the method for securely accessing electronic archives:
[0064] This embodiment is implemented based on the secure access electronic archive device of the above embodiment, and is described by taking the process of a single secure access of an electronic archive as an example.
[0065] When the applicant needs to access the target electronic archive, a access request is sent to the electronic archive management device. Among them, referring to Figure 9 , the electronic archive management device executes the following steps through a computer program:
[0066] S11: Obtain the access request.
[0067] Among them, the electronic archive management system receives the access request sent by the applicant.
[0068] S12: Review the access request.
[0069] Among them, the reviewer operates in the electronic archive management system, so that the electronic archive management system reviews the access request.
[0070] S13: After the access request is reviewed and approved, determine the target archive data packet and target constraint information corresponding to the access request.
[0071] Among them, the archive data packet storage module retrieves the corresponding target archive data packet from the electronic archive database.
[0072] S14: Wait for the download of the target archive data packet and target constraint information.
[0073] Among them, the target archive data packet and target constraint information are prepared and waiting to be sent to the offline access security device.
[0074] Then, the applicant comes to the location where the offline access security device is located, and inputs a retrieval and download application through means such as a touch control screen to obtain the target electronic file. Among them, referring to Figure 10 , the offline access security device executes the following steps through a computer program:
[0075] S21: Obtain and review the retrieval and download application.
[0076] Among them, the retrieval and download application includes applicant information and the information of the file to be borrowed.
[0077] S22: After the retrieval and download application passes the identity verification, allocate the target sub-security device to obtain the target file data packet and the target constraint information corresponding to the retrieval and download application from the electronic file management system.
[0078] Among them, the identity verification can be to obtain the account password input by the applicant, and determine the applicant information corresponding to the applicant according to the account password. Thus, send the applicant information and the information of the file to be borrowed to the electronic file management system. After the electronic file management system determines that there is a retrieval request in which the applicant information and the information of the file to be borrowed are the same as those in the reviewed retrieval and download application and have passed the review, it allows the target file data packet and the target constraint information to be transmitted to the target sub-security device through an encrypted channel.
[0079] Among them, it can be that the target sub-security device downloads the marked file data packet and the target constraint information from the electronic file management system; or, it can also be that the target sub-security device requests the target file data packet and the target constraint information corresponding to the retrieval and download application from the electronic file management system, downloads the target file data packet and the target constraint information and then stores them in the target sub-security device again.
[0080] S23: Release the target sub-security device.
[0081] Thus, the applicant can take away the target sub-security device, connect the target sub-security device to a reading device to obtain the target electronic file. Among them, referring to Figure 11 , the target sub-security device executes the following steps:
[0082] S31: Determine the borrowing permission of the target file data packet according to the stored target constraint information.
[0083] For example, after the target constraint information includes the MAC address, the borrowing permission of the target file data packet only allows the reading device corresponding to the MAC address to read the target file data packet.
[0084] S32: Provide the content of the target file data packet according to the borrowing permission.
[0085] When the validity period inspection unit detects that the expiration is approaching, it issues a reminder. The user can apply for an extension authorization code online through the file offline borrowing review authorization module of the electronic file management device. After obtaining the extension verification code, the user inputs the extension verification code in the sub-security device. After being verified by the algorithm preset by the verification code verification unit, the extension is completed.
[0086] In summary, the present invention obtains the required electronic files through the access and download application, enabling the electronic file management system to still provide on demand even when deployed in the intranet. Moreover, the user needs to initiate the access and download application through the offline access security device, and the target file data packet and target constraint information directly enter the offline access security device from the electronic file management system, making it difficult for electronic files to be leaked during this process and improving the security of retrieving electronic files.
[0087] Finally, it should be emphasized that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. For example, the electronic file management device can be integrated into the offline access security device. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A device for securely accessing electronic files, characterized in that: include: An offline access safety device, wherein the offline access safety device comprises a plurality of controllably separable sub-safety devices; The offline access safety device is used for: Obtain access and download application; The target sub-security device for allocating the target obtains the target archive data package and target constraint information corresponding to the access and download application from the external electronic archive management system; releasing the target sub-safety device; The target sub-safety device is used for: Determining the borrowing authority of the target archive data package according to the stored target constraint information; The content of the target archive data package is provided according to the borrowing authority.
2. The device for securely accessing electronic files as claimed in claim 1, characterized in that: After the download and access application passes identity authentication, the offline access security device allocates the target sub-security device to obtain the target archive data package and the target constraint information corresponding to the download and access application from the electronic archive management system.
3. The device for securely accessing electronic files as claimed in claim 2, characterized in that: Before the offline access security device receives the access download application, the electronic archive management system obtains an access request that matches the access download application, and examines the access request to determine the target archive data package and the target constraint information.
4. The device for securely accessing electronic files as claimed in claim 1, characterized in that: include: When the target sub-security device is assigned to obtain the target archive data package and the target constraint information from the electronic archive management system, it includes: The target sub-security device downloads the target archive data package and the target constraint information from the electronic archive management system; Alternatively, the target sub-security device requests the electronic archive management system for the target archive data package and the target constraint information corresponding to the access download application, downloads the target archive data package and the target constraint information, and stores them in the target sub-security device.
5. The device for securely accessing electronic files as claimed in claim 4, characterized in that: When the target sub-security device downloads the target archive data package and the target constraint information from the electronic archive management system, it includes: the target archive data package and the target constraint information are encrypted in the electronic archive management system, the electronic archive management system transmits the target archive data package and the target constraint information to the target sub-security device through an encrypted channel, and the target sub-security device decrypts the target archive data package and the target constraint information.
6. The device for securely accessing electronic files as claimed in any one of claims 1 to 5, characterized in that: The target constraint information includes one or any combination of the following: usage period, geographical location range, and MAC address.
7. The device for securely accessing electronic files as claimed in claim 6, characterized in that: When the target constraint information includes a usage period, the target sub-security device deletes the target archive data package when detecting that the usage period has been exceeded.
8. The device for securely accessing electronic files as claimed in claim 7, characterized in that: After receiving the extension request corresponding to the access and download application, the electronic archive management system generates a corresponding target extension verification code; The target sub-security device is further used to obtain an input extension verification code and extend the usage period according to the extension verification code.
9. The device for securely accessing electronic files as claimed in claim 8, characterized in that: When the target sub-security device provides the content of the archive data package according to the borrowing authority, it includes: connecting to an external terminal device via a data line, and providing the archive screen with a clear watermark and / or a dark watermark to the terminal device.
10. A method for securely accessing electronic files, characterized in that: The following steps are involved: The electronic archive management system obtains the access request and reviews the access request to determine the target archive data package and target constraint information; The offline access security device obtains the access download application; the access download application matches the access request; The offline access security device allocates the target sub-security device to obtain the target archive data package and the target constraint information corresponding to the access download application from the external electronic archive management system; The offline access safety device releases the target sub-safety device; The target sub-security device determines the borrowing authority of the target archive data package according to the stored target constraint information; The target sub-security device provides the content of the archive data package according to the borrowing authority.