Intelligent management method and management system for encrypted issuing of electronic chart

Through intelligent management methods, electronic chart files are encrypted and authenticated, identifiers and encryption certificates are generated, orders are automatically processed and data use is monitored, solving the problems of many manual operations and poor security in the existing technology, and achieving efficient and secure electronic chart encryption issuance management.

CN120281518AActive Publication Date: 2025-07-08GUANGZHOU COSCO SHIPPING HAINING TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510351741.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-08
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

There are problems in the existing electronic chart encryption issuance management such as many manual operations, low efficiency, poor security, and lack of automation and systematic management, resulting in poor information transparency and data security risks.

Method used

The intelligent management method is adopted to encrypt the original electronic chart file through a preset encryption algorithm, generate identifiers and encrypted certificates, and automatically process order requests based on identity verification and permission management, generate electronic license and unlock keys with authorization attributes, distribute data packets using encrypted transmission channels, and perform continuous monitoring and security operations.

Benefits of technology

It realizes the automated and systematic management of electronic chart encryption issuance, improves data security and traceability, reduces workload and error risks, and improves information transparency and overall efficiency between publishers, agents and shipping companies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281518A_ABST
    Figure CN120281518A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of maritime navigation and information security, in particular to an intelligent management method and management system for encrypted issuing of an electronic chart, and the method comprises the steps: outputting an encrypted file when an original electronic chart file is received; generating an identifier and a corresponding encryption evidence; when an order request of a client is received, order core information is extracted, and identity permission is verified; when the verification is passed, associating the order core information with the encrypted evidence, and marking the order as a to-be-paid state; when it is detected that the order is changed into a payment completion state, generating an electronic permission and an unlocking key; based on the encrypted transmission channel, when the encrypted data packet is distributed to the client, outputting a distribution confirmation notification; and continuously monitoring the encrypted data packet and the use condition of the client, executing a corresponding security operation based on a monitoring result, and outputting a corresponding processing result. The method has the effects of improving the working efficiency, ensuring the data security, reducing human errors and improving the customer experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical fields of maritime navigation and information security, and particularly to an intelligent management method and management system for encrypted distribution of electronic nautical charts. Background Art

[0002] In the field of encrypted distribution management of electronic nautical charts, the existing technologies mainly adopt the following solutions. These solutions have achieved the encrypted protection and distribution management of nautical chart data to a certain extent, but there are still many deficiencies:

[0003] 1. Data encryption and storage: After obtaining the electronic nautical chart data, use an encryption tool to manually input the data version information for encrypted storage. This manual operation is prone to errors and lacks automation, increasing the workload and the risk of errors.

[0004] 2. Customer order placement and record: Customers place orders by contacting, and use the method of manual bookkeeping for order recording and management. This method is inefficient, prone to omissions or errors, and lacks real-time update and query functions.

[0005] 3. User license registration and chart sheet license generation: After the order is completed, manually register the customer's user license in the encryption tool, and generate the chart sheet license according to the user license. This process is cumbersome and prone to errors, lacking automation and systematic management.

[0006] 4. Sending of electronic nautical charts and chart sheet licenses: Send the encrypted electronic nautical charts and chart sheet licenses to customers by email. This method may have security risks and lacks effective tracking and management of the sending process.

[0007] In summary, the existing technologies have problems in the encrypted distribution management of electronic nautical charts, such as the three most important parties in the nautical chart distribution management, namely the distributor, agent, and shipping company, being separated from each other, poor information permeability, many manual operations, low efficiency, poor security, and lack of automation and systematic management.

[0008] Therefore, a new method is urgently needed. Summary of the Invention

[0009] To improve work efficiency, ensure data security, reduce human errors, and enhance the customer experience. This application provides an intelligent management method and management system for encrypted distribution of electronic nautical charts.

[0010] The first invention object of this application is achieved through the following technical solutions:

[0011] An intelligent management method for encrypted distribution of electronic nautical charts, comprising:

[0012] When receiving the original electronic nautical chart file, output an encrypted file based on a preset encryption algorithm;

[0013] Generate an identifier and a corresponding encrypted digital certificate based on the encrypted file.

[0014] When receiving an order request from a client, extract the core information of the order and verify the identity and permissions.

[0015] When the verification passes, associate the core information of the order with the encrypted digital certificate and mark the order as pending payment.

[0016] When it is detected that the order has changed to the payment completed state, generate an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file based on the associated encrypted digital certificate.

[0017] When distributing the encrypted data packet to the client based on the encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted digital certificate.

[0018] Continuously monitor the encrypted data packet and the usage of the client. Based on the monitoring results, perform corresponding security operations and output corresponding processing results.

[0019] In a preferred embodiment, the step of outputting an encrypted file based on a preset encryption algorithm when receiving the original electronic chart file includes:

[0020] Receive the original electronic chart file based on a preset file transfer protocol.

[0021] The preset file transfer protocol includes SFTP and HTTPS.

[0022] Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result.

[0023] The file integrity verification result includes a list of files that pass or fail and the corresponding reasons.

[0024] The list of files includes file name, size, and reception time.

[0025] Encrypt the files that pass the integrity verification based on a preset encryption algorithm, and output the encrypted file and the corresponding encryption key.

[0026] The preset encryption algorithm includes AES-256.

[0027] In a preferred embodiment, the step of generating an identifier and a corresponding encrypted digital certificate based on the encrypted file includes:

[0028] Extract the key information of the encrypted file.

[0029] The key information includes, for example, file basic information and encryption parameters.

[0030] The basic information of the file includes the file name, size, and type;

[0031] The encryption parameters include the encryption key length;

[0032] Based on the key information and the preset identifier generation rules, a unique identifier and the corresponding encryption record are generated for each encrypted file;

[0033] The preset identifier generation rules include the UUID algorithm and the file hash value combined with the timestamp.

[0034] In a preferred embodiment, the step of extracting the core order information and verifying the identity and permission when receiving an order request from the client includes:

[0035] The core order information includes the order number, customer ID, and request time;

[0036] Based on the customer ID and the preset identity verification rules, query the preset permission database to verify whether the identity of the client is legal;

[0037] When the identity is legal, further verify whether there is the corresponding permission to make the order request;

[0038] When the verification is successful, output the core order information and the customer permission information, and trigger the subsequent process;

[0039] When the verification fails, reject the order request.

[0040] In a preferred embodiment, the step of outputting a distribution confirmation notice based on the associated encryption record when distributing the encrypted data packet to the client through the encrypted transmission channel includes:

[0041] Based on the preset distribution protocol, perform the packaging process of the encrypted file, electronic license, and unlocking key, and output the encrypted data packet ready for distribution;

[0042] Based on the encrypted data packet, establish and perform the security verification of the encrypted transmission channel, and output a secure encrypted transmission environment;

[0043] Based on the encrypted data packet, the encrypted transmission environment, and the associated encryption record, perform the embedding operation of the timestamp and the recipient identifier, and output an information packet with distribution evidence;

[0044] Based on the integrity of the information packet, generate and store the distribution evidence chain, and output a complete distribution evidence record;

[0045] Based on the distribution evidence record, perform the tracking of the client's receipt confirmation, and output a distribution confirmation notice.

[0046] In a preferred embodiment, the step of performing the embedding operation of the timestamp and the recipient identifier based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence preservation, and outputting an information packet with distribution evidence includes:

[0047] Automatically extract the recipient identifier from the order request of the client based on a preset recognition algorithm, and record the timestamp;

[0048] Bind the recipient identifier, the timestamp, and the associated encrypted evidence preservation, and based on a preset embedding algorithm, embed them into the encrypted data packet to output an information packet with distribution evidence;

[0049] Send the information packet to the client based on the encrypted transmission environment.

[0050] In a preferred embodiment, the step of continuously monitoring the encrypted data packet and the client usage situation, and based on the monitoring result, performing corresponding security operations and outputting corresponding processing results includes:

[0051] The security operations include data recovery, freeze permission, and recycle permission operations;

[0052] When the monitoring result is that the encrypted file is damaged, based on a preset data recovery mechanism, restore the damaged encrypted file to an available state and output a recovery success notification;

[0053] When the monitoring result is that the electronic permission is abnormal, based on a preset permission management mechanism, freeze the abnormal permission to prevent illegal use and output a freeze permission confirmation message;

[0054] When the monitoring result is that the client abuses its permissions, based on a preset permission management rule, recycle the abused permissions and output a successful feedback on permission recycling.

[0055] The second inventive object of the present application is achieved by the following technical solutions:

[0056] An intelligent management system for encrypted distribution of electronic nautical charts includes:

[0057] A first output module: when receiving the original electronic nautical chart file, output an encrypted file based on a preset encryption algorithm;

[0058] A first generation module: generate an identifier and a corresponding encrypted evidence preservation based on the encrypted file;

[0059] A first verification module: when receiving an order request from the client, extract the core information of the order and verify the identity and permissions;

[0060] A first marking module: when the verification is passed, associate the core information of the order with the encrypted evidence preservation and mark the order as a pending payment status;

[0061] The second generation module: When it is detected that the order changes to the payment completed state, based on the associated encrypted deposit evidence, generate an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file;

[0062] The second output module: When distributing the encrypted data packet to the client based on the encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted deposit evidence;

[0063] The third output module: Continuously monitor the encrypted data packet and the usage of the client. Based on the monitoring results, perform corresponding security operations and output corresponding processing results.

[0064] The third inventive object of the present application is achieved by the following technical solutions:

[0065] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned intelligent management method for encrypted distribution of electronic charts are implemented.

[0066] The fourth inventive object of the present application is achieved by the following technical solutions:

[0067] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned intelligent management method for encrypted distribution of electronic charts are implemented.

[0068] In summary, the present application includes at least one of the following beneficial technical effects:

[0069] Aiming at the problems existing in the existing encrypted distribution management of electronic nautical charts, such as many manual operations, low efficiency, poor security, lack of automation and systematic management, etc., an intelligent management method is proposed. This method automatically encrypts the original electronic nautical chart file through a preset encryption algorithm, generates an identifier and the corresponding encrypted certificate, ensuring the security and traceability of the data. After receiving the order request from the client, the system automatically extracts the core information of the order and verifies the identity and permissions, effectively avoiding the errors and omissions of manual operations. After the verification is passed, the core information of the order is associated with the encrypted certificate, and the order status is marked, realizing the real-time update and query of the order. After the order payment is completed, an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file are automatically generated based on the associated encrypted certificate, simplifying the cumbersome processes of user license registration and chart license generation and improving the efficiency. The encrypted data packet is distributed to the client through an encrypted transmission channel, and a distribution confirmation notice is output, ensuring the security and traceability of data transmission. In addition, continuous monitoring is carried out on the encrypted data packet and the usage of the client, and corresponding security operations are performed according to the monitoring results, such as data recovery, freezing the license, revoking the permissions, etc., and the processing results are output in a timely manner, effectively preventing risks such as data damage, license anomalies, and permission abuse. This method realizes the automated and systematic management of the encrypted distribution of electronic nautical charts, improves the information transparency among publishers, agents, and shipping companies, reduces the workload and the risk of errors, and enhances the overall security and efficiency. Description of the Drawings

[0070] Figure 1 is a flowchart of an implementation of an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0071] Figure 2 is a flowchart of an implementation of step S10 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0072] Figure 3 is a flowchart of an implementation of step S20 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0073] Figure 4 is a flowchart of an implementation of step S30 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0074] Figure 5 is a flowchart of an implementation of step S60 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0075] Figure 6 is a flowchart of an implementation of step S603 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts in this application;

[0076] Figure 7 It is a flowchart of the implementation of step S70 in an embodiment of an intelligent management method for encrypted distribution of electronic nautical charts according to the present application;

[0077] Figure 8 It is a principle block diagram of a computer device according to the present application. Detailed implementation manners

[0078] The following further describes the present application in detail with reference to the attached Figure 1-8 drawings.

[0079] In one embodiment, as Figure 1 shown, the present application discloses an intelligent management method for encrypted distribution of electronic nautical charts, which specifically includes the following steps:

[0080] S10: When receiving the original electronic nautical chart file, output an encrypted file based on a preset encryption algorithm;

[0081] S20: Generate an identifier and a corresponding encrypted certificate based on the encrypted file;

[0082] S30: When receiving an order request from a client, extract the core information of the order and verify the identity and permissions;

[0083] S40: When the verification is passed, associate the core information of the order with the encrypted certificate and mark the order as pending payment;

[0084] S50: When it is detected that the order changes to the payment completed state, generate an electronic license with an authorization attribute and an unlocking key bound to the electronic license and the encrypted file based on the associated encrypted certificate;

[0085] S60: When distributing the encrypted data packet to the client through an encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted certificate;

[0086] S70: Continuously monitor the encrypted data packet and the usage situation of the client, and perform corresponding security operations based on the monitoring results, and output corresponding processing results.

[0087] In this embodiment, in view of the problems existing in the existing encrypted distribution management of electronic nautical charts, such as many manual operations, low efficiency, poor security, lack of automation and systematic management, etc., an intelligent management method is proposed. This method automatically encrypts the original electronic nautical chart file through a preset encryption algorithm, generates an identifier and a corresponding encrypted certificate, ensuring the security and traceability of the data. After receiving the order request from the client, the system automatically extracts the core information of the order and verifies the identity and permissions, effectively avoiding errors and omissions in manual operations. After the verification is passed, the core information of the order is associated with the encrypted certificate, and the order status is marked, realizing real-time update and query of the order.

[0088] After the order payment is completed, an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file are automatically generated based on the associated encrypted digital evidence, simplifying the cumbersome processes of user license registration and chart license generation and improving efficiency. The encrypted data packet is distributed to the client through an encrypted transmission channel, and a distribution confirmation notice is output, ensuring the security and traceability of data transmission.

[0089] In addition, the encrypted data packet and the client usage are continuously monitored, and corresponding security operations are performed according to the monitoring results, such as data recovery, license freezing, permission revocation, etc., and the processing results are output in a timely manner, effectively preventing risks such as data corruption, license anomalies, and permission abuse. This method realizes the automated and systematic management of the encrypted distribution of electronic charts, improves the information transparency among distributors, agents, and shipping companies, reduces the workload and the risk of errors, and enhances the overall security and efficiency.

[0090] Figure 2 , Step S10 includes:

[0091] S101: Receive the original electronic chart file based on a preset file transfer protocol;

[0092] S102: The preset file transfer protocol includes SFTP and HTTPS;

[0093] S103: Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result;

[0094] S104: The file integrity verification result includes the passed or failed file list and the corresponding reasons;

[0095] S105: The file list includes the file name, size, and reception time;

[0096] S106: Encrypt the files that pass the integrity verification based on a preset encryption algorithm, and output the encrypted file and the corresponding encryption key;

[0097] S107: The preset encryption algorithm includes AES-256.

[0098] In this embodiment, step S10 details an efficient and secure process for receiving and encrypting electronic chart files. First, the security and stability of the original electronic chart file during transmission are ensured through a preset file transfer protocol (such as SFTP, HTTPS). Then, the received file is calculated for its SHA-256 hash value and compared with the source hash value, thereby outputting the file integrity verification result. This step effectively guarantees the integrity and non-tampering of the file, and at the same time provides a detailed list of passed or failed files and corresponding reasons, facilitating subsequent processing and tracking.

[0099] For the files that pass the integrity verification, they are encrypted using a preset encryption algorithm (such as AES-256) to output the encrypted file and the corresponding encryption key. This process not only ensures the security of the file content but also provides a flexible key management mechanism. The entire step S10 realizes an automated process from file reception, integrity verification to encryption processing, greatly improving work efficiency and reducing errors and risks caused by manual operations. At the same time, through the detailed file list and verification results, the traceability and transparency of the system are enhanced, laying a solid foundation for the subsequent management of encrypted electronic chart distribution.

[0100] Figure 3 , step S20 includes:

[0101] S201: Extract the key information of the encrypted file;

[0102] S202: The key information includes, for example, file basic information and encryption parameters;

[0103] S203: The file basic information includes file name, size, and type;

[0104] S204: The encryption parameters include the encryption key length;

[0105] S205: Based on the key information and a preset identifier generation rule, generate a unique identifier and the corresponding encrypted deposit certificate for each encrypted file;

[0106] S206: The preset identifier generation rule includes the UUID algorithm, file hash value combined with timestamp.

[0107] In this embodiment, first, extract the key information from the encrypted file, including the basic information of the file (such as file name, size, type) and encryption parameters (such as encryption key length). The extraction of this information provides basic data for subsequent file management and tracking.

[0108] Next, based on these key information and the preset identifier generation rules, a unique identifier and the corresponding encrypted deposit certificate are generated for each encrypted file. The preset identifier generation rules adopt a method that combines the UUID algorithm and the file hash value with the timestamp, ensuring the uniqueness and unpredictability of the identifier, thereby enhancing the security and traceability of the file.

[0109] Through step S20, each encrypted file has a unique "identity certificate", which not only facilitates the management and query of the file, but also greatly improves the security and credibility of the file during distribution and use. In addition, the generation of the encrypted deposit certificate further ensures the integrity and consistency of the file information, providing a reliable basis for subsequent security operations such as permission management and data recovery. The entire step S20 realizes the systematic and automated management of encrypted file information, effectively improving the efficiency and security of the encrypted distribution management of electronic charts.

[0110] Figure 4 , step S30, includes:

[0111] S301: The core order information includes the order number, customer ID, and request time;

[0112] S302: Based on the customer ID and the preset identity verification rules, query the preset permission database to verify whether the identity of the client is legal;

[0113] S303: When the identity is legal, further verify whether there is the corresponding permission to make the order request;

[0114] S304: When the verification is successful, output the core order information and the customer permission information, triggering the subsequent process;

[0115] S305: When the verification fails, reject the order request.

[0116] In this embodiment, step S30 details the identity verification and permission check processes in order processing, ensuring the security and compliance in the encrypted distribution management of electronic charts. First, the system extracts the core order information, including the order number, customer ID, and request time, which are the basis for the subsequent verification processes. Then, based on the customer ID and the preset identity verification rules, the system queries the preset permission database to verify whether the identity of the client is legal. This step effectively prevents illegal users from accessing the system and protects the security of the data.

[0117] For a client with a legal identity, the system further verifies whether it has the corresponding permission to make the order request. This dual-verification mechanism ensures that only authorized users can perform specific operations, thus avoiding the risks of permission abuse and illegal operations.

[0118] After successful verification, the system outputs the core order information and customer permission information, and triggers subsequent processes, such as generating electronic licenses, distributing encrypted files, etc. This seamless process design improves the efficiency and quality of order processing.

[0119] For order requests with failed verification, the system will reject the processing and can provide corresponding error messages or processing suggestions. This measure further enhances the security and user-friendliness of the system.

[0120] Generally speaking, step S30 realizes the refined management and control of order requests through strict identity verification and permission checks, effectively ensuring the security and standardization of the encrypted distribution management of electronic nautical charts, while also improving the user experience and system operation efficiency.

[0121] Figure 5 , step S60, includes:

[0122] S601: Based on a preset distribution protocol, perform the packaging process of encrypted files, electronic licenses, and unlocking keys, and output an encrypted data packet ready for distribution;

[0123] S602: Based on the encrypted data packet, establish and perform security verification of the encrypted transmission channel, and output a secure encrypted transmission environment;

[0124] S603: Based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted digital signature, perform the embedding operation of the timestamp and the recipient identifier, and output an information packet with distribution evidence;

[0125] S604: Based on the integrity of the information packet, generate and store the distribution evidence chain, and output a complete distribution evidence record;

[0126] S605: Based on the distribution evidence record, perform the tracking of the client reception confirmation, and output a distribution confirmation notice.

[0127] In this embodiment, step S60 elaborates a secure and efficient encrypted data packet distribution mechanism. First, the system packages encrypted files, electronic licenses, and unlocking keys based on a preset distribution protocol to generate an encrypted data packet ready for distribution. This step ensures the integrity and consistency of the data before distribution.

[0128] Next, the system establishes an encrypted transmission channel and performs security verification, providing a secure encrypted transmission environment for the transmission of the data packet. This measure effectively prevents the data from being stolen or tampered with during transmission, ensuring the security of the data.

[0129] Based on the secure transmission environment, the system further embeds a timestamp and the recipient identifier to generate a packet with distribution evidence. This operation not only provides temporal traceability for the distribution of data packets but also clarifies the identity of the recipient, enhancing the traceability and accountability of the distribution.

[0130] Subsequently, based on the integrity of the packet, the system generates and stores a chain of distribution evidence and outputs a complete record of distribution evidence. This record provides a reliable basis for subsequent audits and tracking, ensuring the transparency and verifiability of the distribution process.

[0131] Finally, based on the distribution evidence record, the system performs tracking of the client's receipt confirmation and outputs a distribution confirmation notice. This step completes the closed-loop management of the distribution process, ensuring that the data packet is successfully delivered to the client and confirmed by the client.

[0132] Figure 6 , step S603, includes:

[0133] SA1: Automatically extract the recipient identifier from the client's order request based on a preset recognition algorithm and record the timestamp.

[0134] SA2: Bind the recipient identifier, the timestamp, and the associated encrypted evidence of deposit, and based on a preset embedding algorithm, embed them into the encrypted data packet to output a packet with distribution evidence.

[0135] SA3: Send the packet to the client based on the encrypted transmission environment.

[0136] In this embodiment, in the intelligent management method for the encrypted distribution of electronic charts, when distributing an encrypted data packet to a client, the system automatically extracts the recipient identifier from the client's order request through a preset recognition algorithm and records the current timestamp. Then, the recipient identifier, the timestamp, and the associated encrypted evidence of deposit are bound, and these information are embedded into the encrypted data packet using a preset embedding algorithm, thereby generating a packet with distribution evidence. This step ensures that each distributed encrypted data packet has a unique and traceable distribution evidence. Finally, the system sends the packet with distribution evidence to the client through a secure encrypted transmission environment. This process not only enhances the security of the data packet during transmission but also provides a complete record of distribution evidence for subsequent tracking and verification, effectively improving the intelligence and security of the electronic chart distribution management.

[0137] Figure 7 , step S70, includes:

[0138] S701: The security operations include data recovery, freeze permission, and recovery of permissions operations.

[0139] S702: When the monitoring result indicates that the encrypted file is damaged, based on a preset data recovery mechanism, restore the damaged encrypted file to a usable state and output a successful recovery notification.

[0140] S703: When the monitoring result shows an electronic license anomaly, based on a preset license management mechanism, freeze the abnormal license to prevent illegal use and output a confirmation message for freezing the license.

[0141] S704: When the monitoring result reveals client privilege abuse, based on a preset privilege management rule, reclaim the abused privileges and output a successful feedback for privilege reclamation.

[0142] In this embodiment, step S70 constructs a comprehensive security response mechanism for dealing with various anomalies in the encrypted distribution management of electronic nautical charts. First, the system defines multiple security operations, including data recovery, license freezing, and privilege reclamation, to respond to different types of monitoring results.

[0143] When it is detected that the encrypted file is damaged, the system activates the preset data recovery mechanism, restores the damaged file to a usable state, and outputs a successful recovery notification. This mechanism ensures the integrity and availability of the data, reducing the impact of data loss on the business.

[0144] For the case of an electronic license anomaly, the system, based on the preset license management mechanism, freezes the abnormal license, prevents illegal use, and outputs a confirmation message for freezing the license. This measure effectively prevents the abuse or theft of the license, ensuring the security and compliance of the system.

[0145] When it is detected that the client privileges are abused, the system, according to the preset privilege management rule, reclaims the abused privileges and outputs a successful feedback for privilege reclamation. This operation promptly corrects the improper use of privileges and maintains the privilege management system of the system.

[0146] Through step S70, the system realizes a rapid response and effective handling of anomalies, enhancing the security and stability of the encrypted distribution management of electronic nautical charts. At the same time, the detailed output of the processing results improves the transparency and traceability of the system, providing strong support for subsequent auditing and improvement. Overall, step S70 enhances the security protection ability of the system, ensuring the reliability and legality of the electronic nautical chart data.

[0147] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not imply the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0148] In one embodiment, a smart management system for encrypted distribution of electronic nautical charts is provided. This smart management system for encrypted distribution of electronic nautical charts corresponds to the method for encrypted distribution of electronic nautical charts in the above embodiment. This smart management system for encrypted distribution of electronic nautical charts includes:

[0149] A first output module: When receiving the original electronic nautical chart file, output an encrypted file based on a preset encryption algorithm;

[0150] A first generation module: Generate an identifier and a corresponding encrypted deposit certificate based on the encrypted file;

[0151] A first verification module: When receiving an order request from a client, extract the core information of the order and verify the identity and permissions;

[0152] A first marking module: When the verification is passed, associate the core information of the order with the encrypted deposit certificate and mark the order as pending payment;

[0153] A second generation module: When it is detected that the order has changed to the payment completed state, generate an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file based on the associated encrypted deposit certificate;

[0154] A second output module: When distributing the encrypted data packet to the client based on the encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted deposit certificate;

[0155] A third output module: Continuously monitor the encrypted data packet and the usage situation of the client, perform corresponding security operations based on the monitoring results, and output corresponding processing results.

[0156] Optionally, it further includes:

[0157] A first receiving module: Receive the original electronic nautical chart file based on a preset file transfer protocol;

[0158] A first inclusion module: The preset file transfer protocol includes SFTP and HTTPS;

[0159] A fourth output module: Calculate the SHA-256 hash value of the original electronic nautical chart file, compare it with the source hash value, and output the file integrity verification result;

[0160] A second inclusion module: The file integrity verification result includes a list of files that passed or failed and the corresponding reasons;

[0161] A third inclusion module: The file list includes the file name, size, and reception time;

[0162] Fifth Output Module: Based on a preset encryption algorithm, encrypt the files that have passed the integrity check, and output the encrypted files and the corresponding encryption keys;

[0163] Fourth Inclusion Module: The preset encryption algorithm includes AES-256.

[0164] Optionally, it further includes:

[0165] First Extraction Module: Extract the key information of the encrypted files;

[0166] Fifth Inclusion Module: The key information includes file basic information and encryption parameters;

[0167] Sixth Inclusion Module: The file basic information includes file name, size, and type;

[0168] Seventh Inclusion Module: The encryption parameters include the encryption key length;

[0169] Third Generation Module: Based on the key information and the preset identifier generation rules, generate a unique identifier and the corresponding encrypted deposit certificate for each encrypted file;

[0170] Eighth Inclusion Module: The preset identifier generation rules include the UUID algorithm and the file hash value combined with the timestamp.

[0171] Optionally, it further includes:

[0172] Ninth Inclusion Module: The order core information includes the order number, customer ID, and request time;

[0173] First Verification Module: Based on the customer ID and the preset identity verification rules, query the preset permission database to verify whether the identity of the client is legal;

[0174] Second Verification Module: When the identity is legal, further verify whether there is the corresponding permission to make the order request;

[0175] Sixth Output Module: When the verification is successful, output the order core information and the customer permission information, and trigger the subsequent process;

[0176] First Rejection Module: When the verification fails, reject the order request.

[0177] Optionally, it further includes:

[0178] Seventh Output Module: Based on the preset distribution protocol, perform the packaging process of the encrypted files, electronic licenses, and unlocking keys, and output the encrypted data packets ready for distribution;

[0179] Eighth Output Module: Based on the encrypted data packets, establish and perform the security verification of the encrypted transmission channel, and output a secure encrypted transmission environment;

[0180] The ninth output module: Based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence preservation, perform the embedding operations of the time stamp and the recipient identifier, and output an information packet with distribution evidence;

[0181] The first module: Based on the integrity of the information packet, generate and store a distribution evidence chain, and output a complete distribution evidence record;

[0182] The second module: Based on the distribution evidence record, perform the tracking of the client reception confirmation, and output a distribution confirmation notice.

[0183] Optionally, it further includes:

[0184] The second extraction module: Automatically extract the recipient identifier from the order request of the client based on a preset recognition algorithm, and record the time stamp;

[0185] The third module: Bind the recipient identifier, the time stamp, and the associated encrypted evidence preservation, and based on a preset embedding algorithm, embed them into the encrypted data packet, and output an information packet with distribution evidence;

[0186] The first sending module: Based on the encrypted transmission environment, send the information packet to the client.

[0187] Optionally, it further includes:

[0188] The fourth module: The security operations include data recovery, freeze permission, and recycle permission operations;

[0189] The fifth module: When the monitoring result is that the encrypted file is damaged, based on a preset data recovery mechanism, recover the damaged encrypted file to an available state, and output a recovery success notice;

[0190] The sixth module: When the monitoring result is an electronic permission exception, based on a preset permission management mechanism, freeze the abnormal permission to prevent illegal use, and output a freeze permission confirmation message;

[0191] The seventh module: When the monitoring result is client permission abuse, based on a preset permission management rule, recycle the abused permission, and output a permission recycle success feedback.

[0192] For the specific limitations of an intelligent management system for encrypted distribution of electronic nautical charts, reference can be made to the limitations of an intelligent management method for encrypted distribution of electronic nautical charts in the above text, which will not be elaborated here. Each module in the above intelligent management system for encrypted distribution of electronic nautical charts can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of a computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0193] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store encrypted files. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements an intelligent management method for encrypted distribution of electronic nautical charts.

[0194] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements an intelligent management method for encrypted distribution of electronic nautical charts.

[0195] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, it is an intelligent management method for encrypted distribution of electronic nautical charts.

[0196] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0197] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

Claims

1. An intelligent management method for encrypted distribution of electronic nautical charts, characterized in that, Including: When receiving the original electronic chart file, output an encrypted file based on a preset encryption algorithm; Generate an identifier and a corresponding encrypted deposit certificate based on the encrypted file; When receiving an order request from a client, extract the core information of the order and verify the identity and permissions; When the verification passes, associate the core information of the order with the encrypted deposit certificate and mark the order as pending payment; When it is detected that the order changes to the payment completed state, generate an electronic license with authorization attributes, and an unlocking key bound to the electronic license and the encrypted file based on the associated encrypted deposit certificate; When distributing the encrypted data packet to the client through an encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted deposit certificate; Continuously monitor the encrypted data packet and the usage situation of the client, and based on the monitoring results, perform corresponding security operations and output corresponding processing results.

2. The intelligent management method for encrypted distribution of electronic nautical charts according to claim 1, characterized in that, The step of outputting an encrypted file based on a preset encryption algorithm when receiving the original electronic chart file includes the steps: Receive the original electronic chart file based on a preset file transfer protocol; The preset file transfer protocol includes SFTP and HTTPS; Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result; The file integrity verification result includes a list of files that pass or fail and the corresponding reasons; The file list includes file name, size, and reception time; Encrypt the file that passes the integrity verification based on a preset encryption algorithm, and output the encrypted file and the corresponding encryption key; The preset encryption algorithm includes AES-256.

3. The intelligent management method for encrypted distribution of electronic nautical charts according to claim 1, characterized in that, The step of generating an identifier and a corresponding encrypted deposit certificate based on the encrypted file includes the steps: Extract the key information of the encrypted file; The key information includes, for example, file basic information and encryption parameters; The file basic information includes file name, size, and type; The encryption parameters include the encryption key length; Generate a unique identifier and a corresponding encrypted deposit certificate for each encrypted file based on the key information and a preset identifier generation rule; The preset identifier generation rule includes the UUID algorithm and the file hash value combined with the timestamp.

4. The intelligent management method for encrypted distribution of electronic nautical charts according to claim 1, wherein The step of extracting the core information of the order and verifying the identity and permissions when receiving an order request from a client includes the steps: The core information of the order includes order number, customer ID, and request time; Query the preset permission database based on the customer ID and a preset identity verification rule to verify whether the identity of the client is legal; When the identity is legal, further verify whether there are corresponding permissions for the order request; When the verification is successful, output the core information of the order and the customer permission information, and trigger the subsequent process; When the verification fails, reject the order request.

5. The intelligent management method for encrypted distribution of electronic nautical charts according to claim 1, characterized in that, The step of outputting a distribution confirmation notice based on the associated encrypted deposit certificate when distributing the encrypted data packet to the client through an encrypted transmission channel includes the steps: Perform packaging processing of the encrypted file, electronic license, and unlocking key based on a preset distribution protocol, and output the encrypted data packet ready for distribution; Based on the encrypted data packet, establish and perform security verification of the encrypted transmission channel, and output a secure encrypted transmission environment; Perform the embedding operation of the timestamp and the recipient identifier based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence retention, and output an information packet with distribution evidence; Generate and store a distribution evidence chain based on the integrity of the information packet, and output a complete distribution evidence record; Track the client reception confirmation based on the distribution evidence record, and output a distribution confirmation notice.

6. The intelligent management method for encrypted distribution of electronic nautical charts according to claim 5, characterized in that, The step of performing the embedding operation of the timestamp and the recipient identifier based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence retention, and outputting an information packet with distribution evidence includes: Automatically extract the recipient identifier from the client's order request based on a preset recognition algorithm, and record the timestamp; Bind the recipient identifier, the timestamp, and the associated encrypted evidence retention, and based on a preset embedding algorithm, embed them into the encrypted data packet, and output an information packet with distribution evidence; Send the information packet to the client based on the encrypted transmission environment.

7. A smart management method for encrypted distribution of electronic nautical charts according to claim 1, characterized in that, The step of continuously monitoring the encrypted data packet and the client usage situation, and based on the monitoring result, performing corresponding security operations and outputting corresponding processing results includes steps: The security operations include data recovery, freeze permission, and recycle permission operations; When the monitoring result is that the encrypted file is damaged, based on a preset data recovery mechanism, restore the damaged encrypted file to an available state, and output a recovery success notice; When the monitoring result is that the electronic permission is abnormal, based on a preset permission management mechanism, freeze the abnormal permission to prevent illegal use, and output a freeze permission confirmation message; When the monitoring result is that the client abuses permissions, based on a preset permission management rule, recycle the abused permissions, and output a permission recycle success feedback.

8. An intelligent management system for encrypted distribution of electronic nautical charts, characterized in that, Include: The first output module: when receiving the original electronic chart file, output an encrypted file based on a preset encryption algorithm; The first generation module: generate an identifier and a corresponding encrypted evidence retention based on the encrypted file; The first verification module: when receiving the client's order request, extract the core order information and verify the identity permission; The first marking module: when the verification is passed, associate the core order information with the encrypted evidence retention, and mark the order as a pending payment status; The second generation module: when it is detected that the order changes to the payment completed state, generate an electronic permission with an authorization attribute and an unlocking key bound to the electronic permission and the encrypted file based on the associated encrypted evidence retention; The second output module: when distributing the encrypted data packet to the client based on the encrypted transmission channel, output a distribution confirmation notice based on the associated encrypted evidence retention; The third output module: continuously monitor the encrypted data packet and the client usage situation, and based on the monitoring result, perform corresponding security operations and output corresponding processing results.

9. A computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of a smart management method for electronic chart encryption and distribution as claimed in claims 1-7 are implemented.

10. A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of an intelligent management method for electronic chart encryption and distribution as described in claims 1-7.

Citation Information

Patent Citations

  • A method for protecting data of an electronic chart

    CN104135368A

  • VDES electronic chart data online updating and protecting method

    CN110166224A

  • Data transmission verification method suitable for shipborne equipment

    CN115865977A

  • Instant messaging and social network operation system based on ship digital certificate

    CN116506387A

  • Ship electronic recording method and system based on encryption technology

    CN117938531A