Multi-mode security collaborative management system and implementation method for small and micro enterprises and individual industrial and commercial tenants
Through the ERP system with three-level architectural mode switching and distributed storage, the high cost, complex operation and data security problems of small and micro enterprises and individual industrial and commercial households are solved, flexible network switching and efficient multi-terminal collaboration are achieved, and data security and business continuity are ensured.
Patent Information
- Application Number
- CN202510255261.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-07-08
AI Technical Summary
The existing ERP system has high implementation costs for small and micro enterprises and individual industrial and commercial households, complex operations, insufficient data security, and difficult to adapt to the needs of specific industries, resulting in low usage rates and high data leakage risks.
Three-level architectural mode switching, distributed data storage and backup, edge computing, zero-trust security mechanism and dual encryption technology are adopted to realize flexible mode switching and end-to-end security protection. Data synchronization is optimized through Myers differential algorithm, and the optimal node is dynamically elected for task load balancing.
It realizes seamless switching in different network environments, reduces costs, improves multi-terminal collaboration efficiency, ensures data security and business continuity, and adapts to specific industry needs.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise digital management, and particularly relates to a distributed security collaborative management system based on three - level architecture mode switching. This system is particularly suitable for individual industrial and commercial households and small and micro enterprises with unstable network environments, limited IT budgets, and strict data security requirements. Through a multi - modal operation architecture, distributed storage and computing, a zero - trust security system, and military - level encryption technology, it realizes seamless switching among multi - scenarios such as offline / LAN / Internet for the operation management system, and solves the problems of high data leakage risk, low multi - terminal collaboration efficiency, and insufficient cost adaptability of existing SaaS software. Background Art
[0002] The current management software market for small and micro enterprises and individual industrial and commercial households in China shows the characteristics of "rapid demand growth, rapid technology iteration, and obvious competition differentiation". Although cloudification and intelligence have reduced some usage thresholds, cost, ease of use, adaptability, and security are still the core pain points: Contradiction between implementation cost and cost - effectiveness: Traditional ERP systems are expensive, and the customization and development costs exceed the budgets of small and micro enterprises. Low - price standardized products are difficult to meet personalized needs; Insufficient function complexity and user - friendliness: Most ERP systems are complex to operate. Small and micro enterprises and individual industrial and commercial households lack professional IT personnel, resulting in low system utilization rate or idle functions; Concerns about data security and system stability: Although cloud - based ERP has become popular, some enterprises and individual industrial and commercial households have doubts about data privacy and the stability of cloud services. Especially when it comes to financially sensitive information, encryption technology mainly focuses on the transmission layer, lacking military - level protection for local storage and multi - terminal collaboration; Insufficient industry adaptability: General - purpose ERP is difficult to match the process requirements of specific industries (such as catering, retail), and additional customization and development are required, further increasing costs. Summary of the Invention
[0003] This system realizes the following through three - level architecture mode switching, distributed data storage and backup, dynamic allocation of edge computing, zero - trust security mechanism, dual encryption, and blockchain logging technology: Flexible mode switching: In the offline mode, the full - function single - machine runs, and a military - level encryption (AES - 256 - GCM+SQLCipher4) is used to store the local SQLite database; In the LAN mode, multi - terminal collaboration is realized based on the P2P network, supporting full - volume storage and backup of multi - terminal data, distributed storage and backup of multi - terminal data, and edge - node computing; In the Internet mode, it supports data encryption and cloud backup, and can expand advanced functions (such as supply chain visualization); End - to - end security protection: Double encryption of AES-256-GCM + SQLCipher4 combined with zero-trust dynamic authentication reduces the risk of data leakage; Performance optimization: Myers difference algorithm reduces the amount of synchronized data; Dynamically elect the optimal node within the local area network (based on CPU, memory, and latency parameters), eliminate low-performance devices, and balance the task load; recover within 30 seconds in case of node failure, and the main device automatically takes over and triggers re-election; Cost optimization: Reduce the dependence on cloud computing through edge computing; Reduce device investment and lower the usage cost for small and micro enterprises through multi-terminal data storage and backup. Innovative points
[0004] Three-level architecture mode: Automatically downgrade / upgrade the mode according to the network status to ensure business continuity; Military-grade data protection: Local storage encryption + zero-trust dynamic authentication + blockchain log to achieve end-to-end security; Low-cost edge computing: Maximize the use of existing terminal devices through edge computing and distributed storage to reduce enterprise IT costs. Description of the drawings
[0005] Figure 1 It is a schematic diagram of multi-terminal incremental synchronization distributed storage; Figure 2 It is a schematic diagram of multi-terminal full synchronization full storage; Figure 3 It is a schematic diagram of multi-terminal incremental synchronization full storage; Figure 4 It is a mode switching flowchart for three-level mode switching; Figure 5 It is a flowchart for dynamically electing the optimal node within the local area network. Detailed implementation manners
[0006] Example 1: Mode switching process When the user starts the system, it defaults to the offline mode; After detecting a stable local area network environment, it prompts to switch to the local area network mode and enables multi-terminal collaboration and edge computing allocation; After connecting to the Internet, advanced functions such as supply chain tracking and visual analysis are unlocked.
[0007] Example 2: Data synchronization mechanism Full synchronization: Periodically and automatically back up to all terminals; Incremental synchronization: Use the Myers algorithm to compress the changed data and reduce the synchronization time; The blockchain logs are stored in each terminal to ensure that the operation records cannot be tampered with.
Claims
1. A multi-mode security collaborative management system for small and micro enterprises and self-employed businesses, characterized in that, Including: Three - level architecture module: Supports seamless switching between offline mode, local area network mode, and Internet mode. The high - level mode is compatible with low - level functions. Users can independently apply for mode upgrades and set automatic switching strategies when the network status changes; Dynamic network monitoring module: Real - time detects changes in network status, triggers automatic switching or switching reminders according to preset strategies, and automatically synchronizes unfinished operation logs when the network resumes; Multi - terminal collaboration module: Supports data interaction among mobile, PC, and tablet devices. Allocates computing tasks based on the dynamic election algorithm of edge computing nodes. The election parameters include CPU performance, memory occupancy rate, and network latency. When a node fails, a secondary election is automatically triggered; Dual - encryption module: Encrypts sensitive fields using the AES - 256 - GCM algorithm and then superimposes the overall encryption of the SQLCipher4 database. Based on the current mode, multi - factor authentication or zero - trust dynamic verification is superimposed; Data synchronization module: Supports full - volume / incremental synchronization, uses the Myers difference algorithm to compress the amount of changed data, and prevents tampering through blockchain logs (SHA - 3 hash chain + PBFT consensus). For conflicting data, the timestamp - priority strategy is adopted; Near - field communication data migration / synchronization module: Requires multi - factor authentication in local area network mode and zero - trust dynamic verification in Internet mode. Supports automatic migration or synchronization of preset secure target devices; Function expansion module: Provides on - demand subscription functions and encrypted data cloud backup services, and supports API - level hot - plug deployment. 2. The system according to claim 1, wherein: The offline mode supports full - function offline operations on mobile phones, tablets, and PCs, and uses a military - grade encrypted local database; The local area network mode realizes distributed computing and storage based on the P2P network, supports full - volume backup to multiple terminals or specified terminals, or distributed backup to multiple terminals. 3. The system according to claim 1, wherein: The zero - trust dynamic verification includes dynamically hiding fields when sensitive data is displayed, and re - verification is required to view sensitive fields; The dynamic election algorithm of edge computing nodes periodically evaluates the performance parameters of terminal devices. When the primary node fails, the backup node automatically takes over the task and triggers a new election process. 4. The system according to claim 3, wherein: The node failure recovery mechanism includes that the primary device automatically takes over the task and triggers a re - election process within 30 seconds; In the secondary election process, the weighted scoring model preferentially selects devices with a CPU load lower than 30%, a memory occupancy rate lower than 60%, and a network latency less than 50ms. 5. The system according to claim 1, wherein: The dual - encryption module superimposes fingerprint + password multi - factor authentication in offline mode and zero - trust dynamic verification in Internet mode; The blockchain logs are stored in at least three distributed nodes, and data modification requires more than 2 / 3 of the nodes to reach PBFT consensus. 6. The system according to claim 1, wherein: The on - demand subscription function of the function expansion module includes an API - level coupling interface between the local encryption module and the cloud SaaS service; Cloud computing services support the deployment of subscription function components based on containerization technology, and the core system encryption policy is retained during hot pluggable deployment.
7. The system according to claim 1, wherein: In the three-level architecture module, the offline mode uses a local military-grade encrypted database, the local area network mode constructs a P2P-based distributed computing network, and the Internet mode integrates a zero-trust dynamic verification framework; The mode switching strategy includes automatic degradation when the network interruption exceeds 30 seconds and a switching reminder is triggered when the bandwidth is lower than 1 Mbps.
8. The system according to claim 7, wherein: Under the Internet mode, data synchronization needs to establish a secure channel through the TLS 1.3 protocol, and a temporary session key is generated for each transmission; The military-grade encrypted local database uses the national cryptographic SM4 algorithm to perform secondary encapsulation on the database encrypted by SQLCipher4.