An intelligent management method and system for electronic chart encryption and distribution
Through automatic encryption, identity authentication and continuous monitoring of electronic nautical chart files, the problems of multiple manual operations and poor security in existing technologies are solved, and efficient and secure electronic nautical chart encryption issuance management is achieved.
Patent Information
- Application Number
- CN202510351741.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-03-24
AI Technical Summary
The existing electronic nautical chart encryption and issuance management has problems such as excessive manual operations, low efficiency, poor security, and lack of automation and systematic management, resulting in poor information transparency and prone to errors in manual operations.
The system automatically encrypts the original electronic chart files using a preset encryption algorithm, generates identifiers and encrypted evidence, automatically extracts the core information of the order and verifies identity permissions, automatically generates electronic licenses and unlocking keys with authorization attributes, distributes data packets through encrypted transmission channels, and conducts continuous monitoring and security operations.
It has achieved automated and systematic management of encrypted issuance of electronic nautical charts, improved data security and traceability, reduced workload and error risks, and enhanced information transparency and overall efficiency among issuers, agents and shipping companies.
Smart Images

Figure CN120281518B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of maritime navigation and information security technology, and specifically to an intelligent management method and management system for encrypted issuance of electronic nautical charts. Background Art
[0002] In the field of encrypted issuance and management of electronic nautical charts, existing technologies mainly adopt the following solutions. These solutions have achieved the encryption protection and distribution management of nautical chart data to a certain extent, but there are still many shortcomings:
[0003] 1. Data encryption and storage: After acquiring electronic chart data, encryption tools are used to manually enter data version information for encrypted storage. This manual operation is prone to errors and lacks automation, increasing workload and the risk of errors.
[0004] 2. Customer order placement and record keeping: Customers place orders through contact, and order records and management are performed manually. This method is inefficient, prone to omissions and errors, and lacks real-time updates and query capabilities.
[0005] 3. User License Registration and Map License Generation: After the order is completed, the customer's user license is manually registered in the encryption tool, and the map license is generated based on the user license. This process is cumbersome and error-prone, lacking automation and systematic management.
[0006] 4. Sending electronic charts and chart permits: Encrypted electronic charts and chart permits are sent to customers via email. This method may pose security risks and lacks effective tracking and management of the delivery process.
[0007] In summary, the existing technology in the management of encrypted issuance of electronic nautical charts has problems such as the separation of the three most important roles in electronic nautical chart issuance management, namely, issuers, agents, and shipping companies, poor information transparency, many manual operations, low efficiency, poor security, and lack of automation and systematic management.
[0008] Therefore, a new method is urgently needed. Summary of the Invention
[0009] To improve work efficiency, ensure data security, reduce human errors, and enhance customer experience, this application provides an intelligent management method and management system for encrypted issuance of electronic nautical charts.
[0010] The first object of the invention of this application is achieved through the following technical solutions:
[0011] An intelligent management method for encrypted issuance of electronic nautical charts, comprising:
[0012] When receiving the original electronic chart file, it outputs the encrypted file based on the preset encryption algorithm;
[0013] Generate identifiers and corresponding encrypted evidence based on encrypted files;
[0014] When receiving an order request from the client, extract the core order information and verify the identity and authority;
[0015] When the verification is passed, the core information of the order is associated with the encrypted evidence and the order is marked as pending payment;
[0016] When it is detected that the order status has been changed to payment completion, an electronic license with authorization attributes and an unlocking key bound to the electronic license and encrypted file are generated based on the associated encrypted evidence;
[0017] When distributing encrypted data packets to clients via an encrypted transmission channel, a distribution confirmation notification is output based on the associated encrypted evidence.
[0018] Continuously monitor encrypted data packets and client usage, perform corresponding security operations based on the monitoring results, and output corresponding processing results.
[0019] In a preferred embodiment, when receiving the original electronic chart file, the step of outputting the encrypted file based on a preset encryption algorithm includes:
[0020] Receive original electronic chart files based on the preset file transfer protocol;
[0021] The preset file transfer protocols include SFTP and HTTPS;
[0022] Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result;
[0023] The file integrity check result includes a list of files that passed or failed and the corresponding reasons;
[0024] The file list includes file name, size, and receiving time;
[0025] Based on the preset encryption algorithm, encrypt the file that passes the integrity check and output the encrypted file and the corresponding encryption key;
[0026] The preset encryption algorithm includes AES-256.
[0027] In a preferred embodiment, the step of generating an identifier and a corresponding encrypted evidence based on the encrypted file includes:
[0028] Extract key information from encrypted files;
[0029] The key information includes basic file information and encryption parameters;
[0030] The basic information of the file includes file name, size, and type;
[0031] The encryption parameters include encryption key length;
[0032] Based on the key information and the preset identifier generation rules, a unique identifier and corresponding encrypted evidence are generated for each encrypted file;
[0033] The preset identifier generation rules include UUID algorithm, file hash value combined with timestamp.
[0034] In a preferred embodiment, when receiving an order request from a client, the steps of extracting the core order information and verifying the identity authority include:
[0035] The core order information includes order number, customer ID, and request time;
[0036] Based on the client ID and the preset authentication rules, query the preset authority database to verify whether the client's identity is legal;
[0037] If the identity is legitimate, further verification is conducted to determine whether the user has the corresponding authority to make the order request.
[0038] When verification is successful, the core order information and customer authority information are output to trigger subsequent processes;
[0039] When verification fails, the order request is rejected.
[0040] In a preferred embodiment, when distributing the encrypted data packet to the client based on the encrypted transmission channel, the step of outputting a distribution confirmation notification based on the associated encrypted evidence includes:
[0041] Based on the preset distribution protocol, the encrypted file, electronic license and unlocking key are packaged and processed, and the encrypted data package to be distributed is output;
[0042] Based on the encrypted data packet, establish and verify the encrypted transmission channel, and output a secure encrypted transmission environment;
[0043] Based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence, performing an embedding operation of a timestamp and a recipient identifier, and outputting an information packet with distribution evidence;
[0044] Based on the integrity of the information package, the generation and storage of the distribution evidence chain is executed, and a complete distribution evidence record is output;
[0045] Based on the distribution evidence record, perform client reception confirmation tracking and output distribution confirmation notification.
[0046] In a preferred embodiment, the step of embedding the receiver identifier, the timestamp and the associated encrypted evidence into the encrypted data packet based on a preset embedding algorithm, and outputting the information packet with distribution evidence, comprises:
[0047] Based on a preset identification algorithm, the receiver identifier is automatically extracted from the order request of the client, and the timestamp is recorded;
[0048] The receiver identifier, the timestamp and the associated encrypted evidence are bound and embedded into the encrypted data packet based on a preset embedding algorithm, and the information packet with distribution evidence is outputted;
[0049] Based on the encrypted transmission environment, the information packet is sent to the client.
[0050] In a preferred embodiment, the step of continuously monitoring the encrypted data packet and the usage of the client, and executing corresponding security operations based on the monitoring results, and outputting corresponding processing results, comprises:
[0051] The security operations include data recovery, freezing permission, and recycling permission operations;
[0052] When the monitoring result is encrypted file damage, the damaged encrypted file is recovered to a usable state based on a preset data recovery mechanism, and a recovery success notification is outputted;
[0053] When the monitoring result is an electronic permission exception, the abnormal permission is frozen to prevent illegal use based on a preset permission management mechanism, and a frozen permission confirmation information is outputted;
[0054] When the monitoring result is client permission abuse, the abused permission is recycled based on a preset permission management rule, and a permission recycling success feedback is outputted.
[0055] The second object of the application is achieved by the following technical solutions:
[0056] An intelligent management system for encrypted issuance of electronic charts, comprising:
[0057] The first output module: when receiving the original electronic chart file, an encrypted file is outputted based on a preset encryption algorithm;
[0058] The first generation module: based on the encrypted file, an identifier and a corresponding encrypted evidence are generated;
[0059] The first verification module: when receiving the order request of the client, the order core information is extracted, and the identity permission is verified;
[0060] The first marking module: when the verification is passed, the order core information is associated with the encrypted evidence, and the order is marked as a to-be-paid state.
[0061] The second generation module: when it is detected that the order has changed to the payment completed state, based on the associated encrypted evidence, generates an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file;
[0062] Second output module: when distributing encrypted data packets to the client based on the encrypted transmission channel, outputs a distribution confirmation notification based on the associated encrypted evidence;
[0063] The third output module: continuously monitors the encrypted data packets and client usage, performs corresponding security operations based on the monitoring results, and outputs the corresponding processing results.
[0064] The third object of the invention of this application is achieved through the following technical solutions:
[0065] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned intelligent management method for encrypted issuance of electronic nautical charts are implemented.
[0066] The fourth object of the invention of this application is achieved through the following technical solutions:
[0067] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned intelligent management method for encrypted issuance of electronic nautical charts.
[0068] In summary, this application includes at least one of the following beneficial technical effects:
[0069] To address the challenges of existing electronic nautical chart encryption issuance management, which include numerous manual operations, low efficiency, poor security, and a lack of automated and systematic management, an intelligent management method has been proposed. This method automatically encrypts the original electronic nautical chart file using a preset encryption algorithm, generating an identifier and corresponding encrypted evidence, ensuring data security and traceability. Upon receiving an order request from the client, the system automatically extracts the core order information and verifies identity and permissions, effectively avoiding manual errors and omissions. Once verified, the core order information is linked to the encrypted evidence and the order status is marked, enabling real-time order updates and queries. After payment is completed, an electronic license with authorization attributes and an unlocking key bound to the electronic license and encrypted file are automatically generated based on the linked encrypted evidence. This simplifies the tedious process of user license registration and chart sheet license generation, improving efficiency. The encrypted data package is distributed to the client via an encrypted transmission channel, and a delivery confirmation notification is output, ensuring the security and traceability of data transmission. Furthermore, the system continuously monitors encrypted data packets and client usage, executing corresponding security actions based on the monitoring results, such as data recovery, freezing permissions, and revoking permissions. The system also promptly outputs the processing results, effectively preventing risks such as data corruption, permission anomalies, and permission abuse. This approach enables automated and systematic management of encrypted electronic chart issuance, improving information transparency between issuers, agents, and shipping companies, reducing workload and the risk of errors, and enhancing overall security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 This is a flowchart of an implementation of an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts according to the present application;
[0071] Figure 2 This is a flowchart for implementing step S10 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0072] Figure 3 This is a flowchart for implementing step S20 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0073] Figure 4 This is a flowchart for implementing step S30 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0074] Figure 5 This is a flowchart for implementing step S60 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0075] Figure 6 This is a flowchart for implementing step S603 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0076] Figure 7 This is a flowchart for implementing step S70 in an embodiment of an intelligent management method for encrypted issuance of electronic nautical charts of the present application;
[0077] Figure 8 This is a principle block diagram of a computer device of the present application. DETAILED DESCRIPTION
[0078] The following is combined with Figure 1-8 This application is described in further detail.
[0079] In one embodiment, if Figure 1 As shown, the present application discloses an intelligent management method for encrypted issuance of electronic nautical charts, which specifically includes the following steps:
[0080] S10: When receiving the original electronic chart file, output the encrypted file based on the preset encryption algorithm;
[0081] S20: Generate an identifier and corresponding encrypted evidence based on the encrypted file;
[0082] S30: When receiving an order request from the client, extract the core order information and verify the identity authority;
[0083] S40: When the verification is passed, the core information of the order is associated with the encrypted evidence, and the order is marked as pending payment;
[0084] S50: When it is detected that the order has changed to a payment completed state, an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file are generated based on the associated encrypted evidence;
[0085] S60: When distributing the encrypted data packet to the client based on the encrypted transmission channel, output a distribution confirmation notification based on the associated encrypted evidence;
[0086] S70: Continuously monitor the encrypted data packets and client usage, perform corresponding security operations based on the monitoring results, and output corresponding processing results.
[0087] In this embodiment, an intelligent management method is proposed to address the existing issues of encrypted electronic chart issuance and management, such as excessive manual work, low efficiency, poor security, and a lack of automated and systematic management. This method automatically encrypts the original electronic chart file using a preset encryption algorithm, generating an identifier and corresponding encrypted evidence, ensuring data security and traceability. Upon receiving an order request from the client, the system automatically extracts the core order information and verifies identity and permissions, effectively avoiding manual errors and omissions. Once verified, the core order information is linked to the encrypted evidence and the order status is marked, enabling real-time order updates and queries.
[0088] After payment is complete, an electronic license with authorization attributes and an unlocking key bound to the electronic license and encrypted file are automatically generated based on the associated encrypted evidence. This simplifies the tedious process of user license registration and map license generation, improving efficiency. Encrypted data packages are distributed to the client via an encrypted transmission channel, and a delivery confirmation notification is output, ensuring the security and traceability of data transmission.
[0089] Furthermore, the system continuously monitors encrypted data packets and client usage, executing corresponding security actions based on the monitoring results, such as data recovery, freezing permissions, and revoking permissions. The system also promptly outputs the processing results, effectively preventing risks such as data corruption, permission anomalies, and permission abuse. This approach enables automated and systematic management of encrypted electronic chart issuance, improving information transparency between issuers, agents, and shipping companies, reducing workload and the risk of errors, and enhancing overall security and efficiency.
[0090] Figure 2 , step S10 includes:
[0091] S101: receiving an original electronic nautical chart file based on a preset file transfer protocol;
[0092] S102: The preset file transfer protocol includes SFTP and HTTPS;
[0093] S103: Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result;
[0094] S104: The file integrity check result includes a list of files that passed or failed and the corresponding reasons;
[0095] S105: The file list includes the file name, size, and receiving time;
[0096] S106: Encrypt the file that has passed the integrity check based on a preset encryption algorithm, and output the encrypted file and the corresponding encryption key;
[0097] S107: The preset encryption algorithm includes AES-256.
[0098] In this embodiment, step S10 details an efficient and secure process for receiving and encrypting electronic chart files. First, the security and stability of the original electronic chart file during transmission are ensured through a pre-defined file transfer protocol (such as SFTP or HTTPS). Next, a SHA-256 hash value is calculated for the received file and compared with the source hash value, outputting a file integrity check result. This step effectively ensures file integrity and tamper-proofing, while also providing a detailed list of files that passed or failed, along with the corresponding reasons, to facilitate subsequent processing and tracking.
[0099] For files that pass integrity verification, a preset encryption algorithm (such as AES-256) is used for encryption, and the encrypted file and corresponding encryption key are output. This process not only ensures the security of the file content but also provides a flexible key management mechanism. The entire S10 process automates the entire process from file reception, integrity verification, and encryption, significantly improving work efficiency and reducing the errors and risks associated with manual operations. Furthermore, the detailed file list and verification results enhance the system's traceability and transparency, laying a solid foundation for the subsequent management of encrypted electronic chart issuance.
[0100] Figure 3 , step S20 includes:
[0101] S201: Extract key information of the encrypted file;
[0102] S202: The key information includes basic file information and encryption parameters;
[0103] S203: The basic file information includes file name, size, and type;
[0104] S204: The encryption parameters include the encryption key length;
[0105] S205: Based on the key information and the preset identifier generation rules, generate a unique identifier and corresponding encrypted evidence for each encrypted file;
[0106] S206: The preset identifier generation rules include a UUID algorithm, a file hash value combined with a timestamp.
[0107] In this embodiment, key information is first extracted from the encrypted file, including basic file information (such as file name, size, type) and encryption parameters (such as encryption key length). The extraction of this information provides basic data for subsequent file management and tracking.
[0108] Next, based on this key information and pre-defined identifier generation rules, a unique identifier and corresponding encrypted evidence are generated for each encrypted file. The pre-defined identifier generation rules use a UUID algorithm and a file hash value combined with a timestamp to ensure the uniqueness and unpredictability of the identifier, thereby enhancing the security and traceability of the file.
[0109] Through the S20 process, each encrypted file has a unique "identity," which not only facilitates file management and querying but also significantly enhances the security and credibility of file distribution and use. Furthermore, the generation of encrypted evidence further ensures the integrity and consistency of file information, providing a reliable basis for subsequent security operations such as permissions management and data recovery. The entire S20 process enables systematic and automated management of encrypted file information, effectively improving the efficiency and security of electronic chart issuance and management.
[0110] Figure 4 , step S30 includes:
[0111] S301: The order core information includes order number, customer ID, and request time;
[0112] S302: Based on the client ID and the preset identity authentication rules, query the preset authority database to verify whether the client's identity is legal;
[0113] S303: If the identity is legitimate, further verify whether the corresponding authority is available to make the order request;
[0114] S304: When verification is successful, the order core information and customer authority information are output, triggering the subsequent process;
[0115] S305: When verification fails, the order request is rejected.
[0116] In this embodiment, step S30 details the authentication and permission checking process during order processing, ensuring security and compliance in the management of encrypted electronic chart issuance. First, the system extracts core order information, including the order number, customer ID, and request time. This information forms the basis for subsequent verification. Next, based on the customer ID and pre-set authentication rules, the system queries a pre-set permission database to verify the client's identity. This step effectively prevents unauthorized users from accessing the system and protects data security.
[0117] For legitimate clients, the system further verifies whether they have the corresponding permissions to make the order request. This dual verification mechanism ensures that only authorized users can perform specific operations, thus avoiding the risk of abuse of permissions and illegal operations.
[0118] After successful verification, the system outputs the core order information and customer permission information, and triggers subsequent processes such as generating electronic licenses and distributing encrypted files. This seamless process design improves the efficiency and quality of order processing.
[0119] For order requests that fail verification, the system will refuse to process them and provide corresponding error prompts or handling suggestions. This measure further enhances the security and user-friendliness of the system.
[0120] In general, step S30 achieves refined management and control of order requests through strict identity authentication and permission checks, effectively ensuring the security and standardization of electronic nautical chart encryption issuance management, while also improving user experience and system operation efficiency.
[0121] Figure 5 , step S60 includes:
[0122] S601: Based on a preset distribution protocol, the encrypted file, electronic license, and unlocking key are packaged and processed, and an encrypted data package to be distributed is output;
[0123] S602: Based on the encrypted data packet, establish and verify the encrypted transmission channel, and output a secure encrypted transmission environment;
[0124] S603: Based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence, perform an embedding operation of the timestamp and the recipient identifier, and output an information packet with the distribution evidence;
[0125] S604: Based on the integrity of the information package, generate and store the distribution evidence chain and output a complete distribution evidence record;
[0126] S605: Based on the distribution evidence record, perform tracking of the client's receipt confirmation and output a distribution confirmation notification.
[0127] In this embodiment, step S60 details a secure and efficient encrypted data package distribution mechanism. First, the system packages the encrypted file, electronic license, and unlocking key based on a pre-set distribution protocol to generate an encrypted data package ready for distribution. This step ensures data integrity and consistency before distribution.
[0128] Next, the system establishes an encrypted transmission channel and performs security verification, providing a secure encrypted transmission environment for the data packet transmission. This measure effectively prevents the data from being stolen or tampered with during transmission, ensuring data security.
[0129] On the basis of a secure transmission environment, the system further embeds timestamps and recipient identifiers to generate information packets with distribution evidence. This operation not only provides temporal traceability for the distribution of data packets but also clearly identifies the recipient, enhancing the traceability and responsibility of the distribution.
[0130] Subsequently, the system generates and stores a distribution evidence chain based on the integrity of the information packets, outputting a complete distribution evidence record. This record provides a reliable basis for subsequent audits and tracking, ensuring the transparency and verifiability of the distribution process.
[0131] Finally, the system performs tracking of client receipt confirmation based on the distribution evidence record and outputs a distribution confirmation notification. This step completes the closed-loop management of the distribution process, ensuring that the data packets successfully reach the client and are confirmed by the client.
[0132] Figure 6 , S603 step, comprising:
[0133] SA1: Based on a preset recognition algorithm, automatically extract the recipient identifier from the client's order request and record the timestamp;
[0134] SA2: Bind the recipient identifier, the timestamp, and the associated encrypted evidence, and embed them into the encrypted data packet based on a preset embedding algorithm, outputting an information packet with distribution evidence;
[0135] SA3: Based on the encrypted transmission environment, send the information packet to the client.
[0136] In this embodiment, in the intelligent management method for encrypted issuance of electronic charts, when distributing encrypted data packets to clients, the system automatically extracts the recipient identifier from the client's order request through a preset recognition algorithm and records the current timestamp. Then, the recipient identifier, timestamp, and associated encrypted evidence are bound, and these information is embedded into the encrypted data packet using a preset embedding algorithm, generating an information packet with distribution evidence. This step ensures that each distributed encrypted data packet has unique and traceable distribution evidence. Finally, the system sends the information packet with distribution evidence to the client through a secure encrypted transmission environment. This process not only enhances the security of data packets during transmission but also provides complete distribution evidence records for subsequent tracking and verification, effectively improving the intelligence and security of electronic chart distribution management.
[0137] Figure 7 , S70 step, comprising:
[0138] S701: The security operation includes data recovery, frozen permissions, and recycling permissions operations;
[0139] S702: When the monitoring result indicates that the encrypted file is damaged, the damaged encrypted file is restored to a usable state based on a preset data recovery mechanism, and a recovery success notification is output;
[0140] S703: When the monitoring result indicates that the electronic license is abnormal, based on the preset license management mechanism, the abnormal license is frozen to prevent illegal use, and frozen license confirmation information is output;
[0141] S704: When the monitoring result indicates that the client abuses the rights, the abused rights are reclaimed based on the preset rights management rules, and feedback indicating successful rights reclaim is output.
[0142] In this embodiment, step S70 establishes a comprehensive security response mechanism to address various anomalies in the management of encrypted electronic chart issuance. First, the system defines multiple security actions, including data recovery, permission freezing, and permission revocation, to respond to different types of monitoring results.
[0143] When an encrypted file is detected to be corrupted, the system activates a pre-set data recovery mechanism to restore the damaged file to a usable state and issues a successful recovery notification. This mechanism ensures data integrity and availability, minimizing the impact of data loss on business operations.
[0144] In the event of an electronic license anomaly, the system, based on a pre-set license management mechanism, freezes the abnormal license, preventing illegal use, and outputs a frozen license confirmation message. This measure effectively prevents license abuse or theft, ensuring system security and compliance.
[0145] When client-side permission abuse is detected, the system revokes the abused permissions according to pre-set permission management rules and outputs feedback indicating successful permission recovery. This action promptly corrects the improper use of permissions and maintains the system's permission management system.
[0146] Through the S70 process, the system achieves rapid response and effective handling of abnormal situations, enhancing the security and stability of electronic chart encryption issuance management. Furthermore, the detailed output of processing results improves system transparency and traceability, providing strong support for subsequent audits and improvements. Overall, the S70 process enhances the system's security capabilities and ensures the reliability and legitimacy of electronic chart data.
[0147] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0148] In one embodiment, an intelligent management system for encrypted issuance of electronic nautical charts is provided. The intelligent management system for encrypted issuance of electronic nautical charts corresponds to the intelligent management method for encrypted issuance of electronic nautical charts in the above embodiment. The intelligent management system for encrypted issuance of electronic nautical charts includes:
[0149] The first output module: when receiving the original electronic chart file, outputs the encrypted file based on the preset encryption algorithm;
[0150] The first generation module: generates an identifier and corresponding encrypted evidence based on the encrypted file;
[0151] First verification module: when receiving an order request from the client, extract the core order information and verify the identity authority;
[0152] First marking module: when verification is passed, the core information of the order is associated with the encrypted evidence and the order is marked as pending payment;
[0153] The second generation module: when it is detected that the order has changed to the payment completed state, based on the associated encrypted evidence, generates an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file;
[0154] Second output module: when distributing encrypted data packets to the client based on the encrypted transmission channel, outputs a distribution confirmation notification based on the associated encrypted evidence;
[0155] The third output module: continuously monitors the encrypted data packets and client usage, performs corresponding security operations based on the monitoring results, and outputs the corresponding processing results.
[0156] Optionally, also include:
[0157] The first receiving module receives the original electronic chart file based on a preset file transfer protocol;
[0158] The first module includes: the preset file transfer protocol includes SFTP and HTTPS;
[0159] The fourth output module: calculates the SHA-256 hash value of the original electronic chart file, compares it with the source hash value, and outputs the file integrity verification result;
[0160] The second module includes: the file integrity check result includes a list of files that passed or failed and the corresponding reasons;
[0161] The third module includes: the file list includes file name, size, and receiving time;
[0162] The fifth output module: encrypts the file that passes the integrity check based on a preset encryption algorithm, and outputs the encrypted file and the corresponding encryption key;
[0163] The fourth module includes: the preset encryption algorithm includes AES-256.
[0164] Optionally, also include:
[0165] The first extraction module: extracts key information of the encrypted file;
[0166] The fifth module includes: the key information includes basic file information and encryption parameters;
[0167] The sixth module includes: the basic information of the file includes the file name, size, and type;
[0168] The seventh module includes: the encryption parameter includes the encryption key length;
[0169] The third generation module generates a unique identifier and corresponding encrypted evidence for each encrypted file based on the key information and the preset identifier generation rules;
[0170] The eighth module includes: the preset identifier generation rules include UUID algorithm, file hash value combined with timestamp.
[0171] Optionally, also include:
[0172] Ninth including module: the order core information includes order number, customer ID, and request time;
[0173] The first verification module: based on the client ID and the preset identity authentication rules, queries the preset authority database to verify whether the client's identity is legal;
[0174] Second verification module: when the identity is legal, further verify whether the corresponding authority is available to make the order request;
[0175] The sixth output module: when the verification is successful, it outputs the core order information and customer authority information, triggering the subsequent process;
[0176] First rejection module: when verification fails, reject the order request.
[0177] Optionally, also include:
[0178] The seventh output module: based on the preset distribution protocol, performs packaging processing of the encrypted file, electronic license and unlocking key, and outputs the encrypted data package to be distributed;
[0179] An eighth output module: based on the encrypted data packet, performs the establishment and security verification of the encrypted transmission channel, and outputs a secure encrypted transmission environment;
[0180] The ninth output module: based on the encrypted data packet, the encrypted transmission environment, the associated encrypted evidence, the embedding operation of the timestamp and the receiver identification is performed, and the information packet with the distribution evidence is outputted;
[0181] The first module: based on the integrity of the information packet, the generation and storage of the distribution evidence chain are performed, and the complete distribution evidence record is outputted;
[0182] The second module: based on the distribution evidence record, the tracking of the client receiving confirmation is performed, and the distribution confirmation notification is outputted.
[0183] Optionally, further comprising:
[0184] The second extraction module: based on the preset identification algorithm, the receiver identification is automatically extracted from the order request of the client, and the timestamp is recorded;
[0185] The third module: the receiver identification, the timestamp and the associated encrypted evidence are bound, and based on the preset embedding algorithm, the encrypted data packet is embedded, and the information packet with the distribution evidence is outputted;
[0186] The first sending module: based on the encrypted transmission environment, the information packet is sent to the client.
[0187] Optionally, further comprising:
[0188] The fourth module: the security operation includes data recovery, frozen permission, and recycling permission operation;
[0189] The fifth module: when the monitoring result is the encrypted file damage, based on the preset data recovery mechanism, the damaged encrypted file is recovered to the available state, and the recovery success notification is outputted;
[0190] The sixth module: when the monitoring result is the electronic permission exception, based on the preset permission management mechanism, the abnormal permission is frozen to prevent illegal use, and the frozen permission confirmation information is outputted;
[0191] The seventh module: when the monitoring result is the client permission abuse, based on the preset permission management rule, the abused permission is recycled, and the permission recycling success feedback is outputted.
[0192] The specific definition of the intelligent management system for encrypted distribution of electronic charts can refer to the definition of the intelligent management method for encrypted distribution of electronic charts, which will not be repeated here. Each module in the intelligent management system for encrypted distribution of electronic charts can be realized by software, hardware, or a combination thereof, in whole or in part. Each module can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0193] In one embodiment, a computer device, which can be a server, is provided, and an internal structure diagram of the computer device can be as shown in Figure 8 The computer device includes a processor, a memory, a network interface, and a database connected by a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store encrypted files. The network interface of the computer device is configured to communicate with an external terminal through a network connection. The computer program is executed by the processor to implement an intelligent management method for encrypted distribution of electronic charts.
[0194] In one embodiment, a computer device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor implements an intelligent management method for encrypted distribution of electronic charts when executing the computer program.
[0195] In one embodiment, a computer readable storage medium is provided, which stores a computer program. The computer program is executed by a processor to implement an intelligent management method for encrypted distribution of electronic charts.
[0196] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, storage, database or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0197] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of functional units and modules is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above.
Claims
1. An intelligent management method for encrypted issuance of electronic nautical charts, characterized in that: include: When receiving the original electronic chart file, it outputs the encrypted file based on the preset encryption algorithm; Generate identifiers and corresponding encrypted evidence based on encrypted files; When receiving an order request from the client, extract the core order information and verify the identity and authority; When the verification is passed, the core information of the order is associated with the encrypted evidence and the order is marked as pending payment; When it is detected that the order status has been changed to payment completion, an electronic license with authorization attributes and an unlocking key bound to the electronic license and encrypted file are generated based on the associated encrypted evidence; When distributing encrypted data packets to clients via an encrypted transmission channel, a distribution confirmation notification is output based on the associated encrypted evidence. Continuously monitor encrypted data packets and client usage, perform corresponding security operations based on the monitoring results, and output corresponding processing results.
2. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 1, characterized in that: The step of outputting an encrypted file based on a preset encryption algorithm when receiving the original electronic chart file comprises the following steps: Receive original electronic chart files based on the preset file transfer protocol; The preset file transfer protocols include SFTP and HTTPS; Calculate the SHA-256 hash value of the original electronic chart file, compare it with the source hash value, and output the file integrity verification result; The file integrity check result includes a list of files that passed or failed and the corresponding reasons; The file list includes file name, size, and receiving time; Based on the preset encryption algorithm, encrypt the file that passes the integrity check and output the encrypted file and the corresponding encryption key; The preset encryption algorithm includes AES-256.
3. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 1, characterized in that: The step of generating an identifier and a corresponding encrypted evidence based on an encrypted file includes the following steps: Extract key information from encrypted files; The key information includes basic file information and encryption parameters; The basic information of the file includes file name, size, and type; The encryption parameters include encryption key length; Based on the key information and the preset identifier generation rules, a unique identifier and corresponding encrypted evidence are generated for each encrypted file; The preset identifier generation rules include UUID algorithm, file hash value combined with timestamp.
4. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 1, characterized in that: The steps of extracting the core order information and verifying the identity authority upon receiving the order request from the client include the following steps: The core order information includes order number, customer ID, and request time; Based on the client ID and the preset authentication rules, query the preset authority database to verify whether the client's identity is legal; If the identity is legitimate, further verification is conducted to determine whether the user has the corresponding authority to make the order request. When verification is successful, the core order information and customer authority information are output to trigger subsequent processes; When verification fails, the order request is rejected.
5. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 1, characterized in that: The step of distributing an encrypted data packet to a client based on an encrypted transmission channel and outputting a distribution confirmation notification based on associated encrypted evidence comprises the following steps: Based on the preset distribution protocol, the encrypted file, electronic license and unlocking key are packaged and processed, and the encrypted data package to be distributed is output; Based on the encrypted data packet, establish and verify the encrypted transmission channel, and output a secure encrypted transmission environment; Based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence, performing an embedding operation of a timestamp and a recipient identifier, and outputting an information packet with distribution evidence; Based on the integrity of the information package, the generation and storage of the distribution evidence chain is executed, and a complete distribution evidence record is output; Based on the distribution evidence record, perform client reception confirmation tracking and output distribution confirmation notification.
6. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 5, characterized in that: The step of embedding a timestamp and a recipient identifier based on the encrypted data packet, the encrypted transmission environment, and the associated encrypted evidence, and outputting an information packet with distribution evidence includes: Based on the preset recognition algorithm, the recipient ID is automatically extracted from the client's order request and the timestamp is recorded; Binding the recipient identifier, the timestamp, and the associated encrypted evidence, and embedding them into the encrypted data packet based on a preset embedding algorithm, and outputting an information packet with distribution evidence; Based on the encrypted transmission environment, the information packet is sent to the client.
7. The intelligent management method for encrypted issuance of electronic nautical charts according to claim 1, characterized in that: The step of continuously monitoring the encrypted data packets and the client usage, executing corresponding security operations based on the monitoring results, and outputting corresponding processing results includes the following steps: The security operations include data recovery, permission freezing, and permission recovery operations; When the monitoring result shows that the encrypted file is damaged, the damaged encrypted file is restored to a usable state based on the preset data recovery mechanism, and a recovery success notification is output; When the monitoring result shows that the electronic license is abnormal, based on the preset license management mechanism, the abnormal license is frozen to prevent illegal use, and frozen license confirmation information is output; When the monitoring result is that the client abuses the permissions, the abused permissions will be reclaimed based on the preset permission management rules, and feedback on successful permission recovery will be output.
8. An intelligent management system for encrypted issuance of electronic nautical charts, characterized in that: include: The first output module: when receiving the original electronic chart file, outputs the encrypted file based on the preset encryption algorithm; The first generation module: generates an identifier and corresponding encrypted evidence based on the encrypted file; First verification module: when receiving an order request from the client, extract the core order information and verify the identity authority; First marking module: when verification is passed, the core information of the order is associated with the encrypted evidence and the order is marked as pending payment; The second generation module: when it is detected that the order has changed to the payment completed state, based on the associated encrypted evidence, generates an electronic license with authorization attributes and an unlocking key bound to the electronic license and the encrypted file; Second output module: when distributing encrypted data packets to the client based on the encrypted transmission channel, outputs a distribution confirmation notification based on the associated encrypted evidence; The third output module: continuously monitors the encrypted data packets and client usage, performs corresponding security operations based on the monitoring results, and outputs the corresponding processing results.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the intelligent management method for encrypted issuance of electronic nautical charts as described in claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the intelligent management method for encrypted issuance of electronic nautical charts according to claims 1 to 7.
Citation Information
Patent Citations
Instant messaging and social network operation system based on ship digital certificate
CN116506387A
Sea chart data resource management method and system based on data verification
CN118394280A