Project supervision file anti-divulging method and project supervision file anti-divulging system

Through CP-ABE encryption, invisible watermarking and secure transmission sandbox technology, the problem of lagging access control and cross-platform collaboration risks in the electronic process of engineering supervision files is solved, dynamic permission control and full-link traceability of engineering supervision files are realized, and the security and audit capabilities of the files are improved.

CN120296779AActive Publication Date: 2025-07-11LADDER PROJECT CONSULTING CO LTD

Patent Information

Application Number
CN202510356372.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-11
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

During the electronicization process, existing project supervision documents have problems such as lagging access control, cross-platform collaboration risks and audit traceability. Especially when the permissions are not adjusted in time during the change of the project stage, insufficient isolation of file versions, poor transmission security of uncontrolled platforms, and lack real-timeness and integrity of the audit mechanism.

Method used

CP-ABE encryption technology is used to combine dynamic key rotation, invisible watermarks are embedded and a secure transmission sandbox is created, operation logs are recorded on the blockchain, and abnormal detection and traceability are used to realize dynamic permission control of files and full-link traceability.

Benefits of technology

Ensure that the project supervision documents are only accessible within the scope of authorized users, and the uncontrolled platform risks are isolated during the transmission process, and the security management and accurate audit traceability of documents are realized, which improves the security, access control accuracy and audit capabilities of documents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296779A_ABST
    Figure CN120296779A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security protection, in particular to a project supervision file anti-leakage method and system, and the method comprises the steps: encrypting a file through a CP-ABE encryption technology, binding an access control attribute, dynamically adjusting the authority and a secret key according to the project progress, and guaranteeing the precise control of file access. An invisible watermark is embedded before file transmission, a target platform is judged, and if the target platform is an uncontrolled platform, a security sandbox is created for decryption, so that transmission security is guaranteed. Meanwhile, an operation log is recorded and stored in the block chain, abnormal behaviors are detected through the knowledge graph, file tracing is achieved in combination with watermarks, and the audit tracing ability is enhanced. And when the destroying condition is met, the system automatically destroys the file and cancels the decryption key, so that the leakage risk is eliminated. According to the invention, file leakage is effectively prevented, file security management and access tracking are realized, and the security, access control accuracy and auditing traceability of project supervision files are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security protection, and specifically to a method and system for preventing the leakage of engineering supervision documents. Background Art

[0002] In the field of construction engineering, engineering supervision documents contain key information such as design blueprints, construction progress plans, quality inspection reports, and change records, which are crucial for project quality control, project progress management, and data security. With the development of information technology, existing supervision documents have gradually become electronic. Although existing solutions have improved efficiency, there are still security challenges such as information leakage, lagging access control, risks of cross-platform collaboration, and difficulties in audit traceability.

[0003] First of all, the access control lacks dynamic adaptability. The existing static role model is based on fixed rules and cannot adjust access permissions according to the engineering stage, resulting in the possibility that the construction party may still access sensitive documents after completion. At the same time, there is a lack of a version-level isolation mechanism for historical documents, and it is difficult to avoid the risk of leakage of old version drawings.

[0004] Secondly, cross-platform collaboration leads to out-of-control of documents. When engineering documents are transmitted on an uncontrolled platform, they often need to be unpacked from the security package into a plain text format. Existing structured data protection solutions cannot cover the content transfer in an uncontrolled environment. The documents lack dynamic identification and invalidation strategies, and it is difficult to trace them after leakage. At the same time, operations such as abnormal forwarding and screenshotting lack real-time perception capabilities, forming a security protection blind spot.

[0005] Finally, these solutions have certain limitations in the distributed audit mechanism. File operation records are stored separately on independent platforms, lacking a unified standard and a real-time synchronization mechanism, making it difficult to accurately identify covert leakage behaviors. In addition, the integrity of log storage is not guaranteed, and key records may be tampered with or forged, affecting the traceability and evidence collection of leakage incidents.

[0006] In order to improve the security, access control accuracy, and audit traceability of engineering supervision documents, a method and system for preventing the leakage of engineering supervision documents are proposed. Summary of the Invention

[0007] The object of the present invention is to provide a method and system for preventing the leakage of engineering supervision documents. The documents are encrypted by CP-ABE encryption technology and bound with access control attributes. The permissions and keys are dynamically adjusted according to the project progress to ensure precise control of file access. Before file transmission, an invisible watermark is embedded, and the target platform is judged. If it is an uncontrolled platform, a secure sandbox is created for decryption to ensure transmission security. At the same time, operation logs are recorded and stored in the blockchain. The knowledge graph is used to detect abnormal behaviors, and combined with the watermark, file traceability is realized to enhance the audit and traceability ability. When the destruction condition is met, the system automatically destroys the file and revokes the decryption key to eliminate the leakage risk. The present invention effectively prevents file leakage, realizes file security management and access tracking, and improves the security, access control accuracy, and audit and traceability ability of engineering supervision documents.

[0008] To achieve the above object, the present invention provides the following technical solutions:

[0009] An engineering supervision document anti-leakage method, comprising:

[0010] Bind attributes to the uploaded engineering supervision documents, generate an encryption key using the CP-ABE algorithm, and encrypt the engineering supervision documents;

[0011] Monitor project progress events and obtain the engineering stage information of the engineering supervision documents;

[0012] Based on a rule engine, match the engineering stage information, and execute a permission change strategy and a key rotation mechanism; the permission change strategy is used for version isolation and permission synchronization of the engineering supervision documents; the key rotation mechanism is used to update the key revocation list and generate a new key;

[0013] Monitor file transmission requests, embed an invisible watermark in the engineering supervision documents, and judge whether the target platform is a controlled platform; if the target platform is the controlled platform, transmit the engineering supervision documents according to the user permissions; otherwise, create a secure transmission sandbox, and decrypt the file in the secure transmission sandbox;

[0014] Record operation logs, perform signature verification on the operation logs and write them into the blockchain; construct a knowledge graph based on the blockchain for detecting abnormal access behaviors, compare the invisible watermark with the operation logs, and generate a traceability report;

[0015] Execute file destruction when the destruction condition is met, and receive a request to revoke the decryption key.

[0016] Further, the rule engine matches the project stage information based on a preset permission rule library, and the permission rule library includes: a stage permission mapping rule for defining file access permissions for different project stages; a role permission rule for allocating access permissions according to the identities of project participants; and a historical version access rule for restricting access permissions to old versions after the version of the project supervision document is changed.

[0017] Further, the permission synchronization includes: broadcasting a permission change event to all user terminals through a distributed message push mechanism; online user terminals subscribing to the broadcast permission change event and automatically refreshing the local permission cache, and offline user terminals locking file access and refreshing the local permission cache after reconnecting.

[0018] Further, the process of embedding the invisible watermark includes:

[0019] Dividing the project supervision document into N data blocks, and performing discrete cosine transform on each data block to generate a DCT transform coefficient matrix; partitioning the DCT transform coefficient matrix according to a preset frequency threshold to extract low-frequency DCT coefficients and high-frequency DCT coefficients; wherein, the low-frequency DCT coefficients represent the global features of the project supervision document; the high-frequency DCT coefficients represent the detailed information of the project supervision document;

[0020] Embedding watermark information in the low-frequency DCT coefficients, and the watermark information includes a user ID, a timestamp, and a file hash value, expressed as:

[0021] C′(u,v)=C(u,v)+α×W(u,c);

[0022] Wherein, C'(u,v) is the updated low-frequency DCT coefficient, C(u,v) is the original low-frequency DCT coefficient, W(i,v) is the watermark information, α is an intensity factor, and u and v are the row and column indices of the DCT transform coefficient matrix;

[0023] Performing inverse DCT transform on the DCT transform coefficient matrix to obtain the watermarked data block; merging all the data blocks to obtain the updated project supervision document.

[0024] Further, the process of creating the secure transmission sandbox includes:

[0025] Initializing the secure transmission sandbox on the target platform and creating a controlled running space for the project supervision document;

[0026] Execute file decryption within the secure transmission sandbox, and prevent operations such as copying, pasting, dragging, printing, and screenshotting of files through a process-level interception mechanism; among them, the secure transmission sandbox on the desktop intercepts global screenshot requests through the operating system hook mechanism, and the secure transmission sandbox in the browser intercepts file access interfaces through WebAssembly technology;

[0027] If the abnormal access behavior is detected, forcibly terminate the process of the secure transmission sandbox.

[0028] Furthermore, the abnormal access behavior includes frequent cross-platform access and short-term high-frequency access;

[0029] The inspection method for the frequent cross-platform access includes: setting a first time window, counting the download operations of the user on different target platforms, and if the same user downloads the same project supervision file from more than K target platforms within the first time window, an abnormal warning is triggered;

[0030] The inspection method for the short-term high-frequency access includes: setting a second time window, calculating the access entropy value of the user for the project supervision file, and if the access entropy value exceeds the set entropy threshold, the abnormal warning is triggered.

[0031] An anti-disclosure system for project supervision files, including:

[0032] A key management module that binds attributes to the uploaded project supervision files, generates encryption keys using the CP-ABE algorithm, and encrypts the project supervision files;

[0033] A dynamic permission engine module for listening to project progress events and obtaining the project stage information of the project supervision files; based on a rule engine, matching the project stage information, and executing a permission change strategy and a key rotation mechanism; the permission change strategy is used for version isolation and permission synchronization of the project supervision files; the key rotation mechanism is used to update the key revocation list and generate new keys;

[0034] A secure transmission sandbox module that listens to file transmission requests, embeds invisible watermarks in the project supervision files, and determines whether the target platform is a controlled platform; if the target platform is the controlled platform, transmit the project supervision files according to user permissions; otherwise, create a secure transmission sandbox and decrypt the files within the secure transmission sandbox;

[0035] A blockchain auditing module that records operation logs, performs signature verification on the operation logs and then writes them into the blockchain; constructs a knowledge graph based on the blockchain for detecting abnormal access behaviors, compares the invisible watermark with the operation logs, and generates a traceability report; executes file destruction when the destruction conditions are met and receives requests to revoke decryption keys.

[0036] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0037] 1. Based on CP-ABE encryption combined with a dynamic key rotation mechanism, the present invention ensures that engineering supervision documents can only be accessed by authorized users. When the project stage changes, the old key is automatically revoked and a new key is generated to prevent the abuse of expired keys. In addition, by adopting a rule engine and a distributed permission synchronization mechanism, after the permission is adjusted, the update is automatically pushed, and the online users can instantly refresh the permissions, while the offline users can synchronize the permissions after reconnecting, avoiding unauthorized access caused by permission lag. At the same time, the version isolation mechanism restricts the access permissions of old version files, ensuring the security and controllability of engineering documents at different stages and improving the security of engineering supervision documents.

[0038] 2. The present invention adopts the invisible watermark technology combined with DCT transformation to embed user identity, timestamp and file hash value in the file. Even if the file is leaked, the source of the leak can still be traced through the watermark. For the security of file transmission, the secure transmission sandbox can create an isolated environment on an uncontrolled platform and intercept high-risk operations to prevent the risk of file leakage during transmission. In addition, the system supports an automatic file destruction mechanism. When the leakage determination condition is met, the destruction operation is automatically executed, and a decryption key revocation request is submitted, improving the security, access control accuracy and audit traceability of engineering supervision documents.

[0039] 3. The present invention combines blockchain technology and knowledge graph analysis to achieve immutable log storage and intelligent anomaly detection. All user operation logs are written into the blockchain after being verified by digital signatures to ensure data integrity and traceability. By constructing a knowledge graph to analyze the associations between users, files, devices and operation behaviors, abnormal behaviors such as frequent cross-platform access and short-term high-frequency downloads can be identified. In addition, the system can compare the invisible watermark information with the blockchain log to accurately locate the leakage source and generate a traceability report, thus improving the security, access control accuracy and audit traceability of engineering supervision documents. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a schematic flow chart of a method for preventing the leakage of engineering supervision documents provided by the present invention;

[0041] Figure 2 It is a schematic flow chart of users accessing engineering supervision documents provided by the present invention;

[0042] Figure 3 It is a schematic structural diagram of a system for preventing the leakage of engineering supervision documents provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0043] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] Please refer to Figures 1 to 3 , the present invention provides a method and system for preventing the leakage of engineering supervision documents, and the technical solutions are as follows:

[0045] Embodiment 1:

[0046] While the electronicization of construction project supervision documents improves collaborative efficiency, it faces multiple security challenges. Traditional methods rely on static role division and cannot dynamically adjust permissions according to project phases (such as design, construction, and completion), resulting in sensitive documents still being accessible to unauthorized parties after phase transitions. Moreover, there is a lack of version isolation mechanism, and old versions of documents are likely to be leaked through historical archives. In addition, when files are transmitted across platforms, they need to be decrypted into plaintext. Traditional encryption technologies are difficult to restrict the transfer through uncontrolled channels, and there is a lack of dynamic identification and self-destruction strategies, making it difficult to trace after leakage. Also, audit logs are scattered in independent systems such as OA and cloud storage, lacking real-time aggregation and anti-tampering capabilities, resulting in the possibility of key records being tampered with.

[0047] To address the above problems, this embodiment proposes a method for preventing the leakage of engineering supervision documents. Through technologies such as dynamic permission control, version isolation, cross-platform secure transmission, and aggregated auditing, it improves file security, access control accuracy, and audit traceability capabilities. The process is as Figure 1 shown and includes:

[0048] Step 1: Bind attributes to the uploaded engineering supervision documents, generate an encryption key using the CP-ABE algorithm, and encrypt the engineering supervision documents.

[0049] Specifically, in order to achieve file encryption and access control, it is necessary to define attributes for engineering supervision documents. As shown in Table 1, the basic attributes of each file are defined, such as project phase, department, and security level, which are used for file management and encryption policy configuration. At the same time, attributes can also be defined for users. As shown in Table 2, attributes are defined for users, covering roles, departments, and security permission levels. The administrator or file owner sets access policies for the files. As shown in Table 3, only users who meet specific attributes can access the corresponding files.

[0050] The system calls the CP-ABE algorithm to generate an encryption key based on the access policy and generates an encrypted file after encrypting the file. This algorithm supports complex access policies, ensuring that only eligible users (such as specific roles or departments) can decrypt the file. For example, only design engineers in the design department or high-authority project managers can access the design drawings. It not only realizes efficient permission management but also improves file security and project collaboration flexibility.

[0051] Table 1 File Attribute Table

[0052] File ID File Name Project Phase Department Security Level F001 design drawing.pdf Design Phase Design Department Confidential F002 construction plan.docx Construction Phase Construction Department Internal

[0053] Table 2 User Attribute Table

[0054] User ID Role Department Affiliation Security Clearance Level U001 Design Engineer Design Department Medium U002 Construction Worker Construction Department Low U003 Project Manager Project Management Department High

[0055] Table 3 Access Policy Table

[0056]

[0057] Step 2: Listen for project progress events and obtain the project phase information of the engineering supervision documents.

[0058] Project progress events refer to specific events that occur in an engineering project and can change the project phase or status. Specifically, they cover the following categories: First, the start and end of phases, such as "Design phase starts" and "Construction phase ends"; second, the achievement of milestones, like "The main structure is capped" and "The completion acceptance is passed"; third, the change of roles, such as "The project manager is replaced" and "The design team is adjusted"; fourth, the change of the version of engineering supervision documents, such as "Construction drawings V2.0 version" replacing "Construction drawings V1.0 version". By listening to these project progress events, the changes in the project phase can be detected in real time, thereby ensuring that the file management strategy is synchronized with the actual progress of the project. And the project phase information refers to the project phase where the engineering supervision document is currently located (such as "Design phase" and "Construction phase").

[0059] The specific operation method is as follows: Connect with project management software (such as Microsoft Project) through an API interface or a Webhook mechanism. When a key event occurs in the project management software, an event notification will be sent. After the system receives this notification, it will extract information such as the event type, project ID, event occurrence time, and new phase. Subsequently, it will query the files associated with the project in the database based on the project ID and update the "project phase" attribute of these files. Finally, it will send the file ID and the updated "project phase" information to the rule engine to trigger subsequent permission adjustment strategies.

[0060] Step 3: Based on the rule engine, match the engineering stage information and execute the permission change policy and key rotation mechanism; the permission change policy is used to perform version isolation and permission synchronization on the engineering supervision documents; the key rotation mechanism is used to update the Certificate Revocation List (CRL) and generate new keys.

[0061] Furthermore, the rule engine matches the engineering stage information based on a preset permission rule library, and the permission rule library includes:

[0062] Stage permission mapping rules, which are used to define the file access permissions for different engineering stages. When the rule engine detects a switch in the engineering stage, it will automatically load the stage permission mapping rules. For example, in the "design stage", for design-related files, the design team has "read and write" permissions, while the construction team has "no permissions"; after entering the "construction stage", the permissions for design-related files will be changed accordingly: the design team only has "read-only" permissions, and the construction team has "read and write" permissions.

[0063] Role permission rules, which are used to allocate access permissions according to the identities of project participants. The rule engine will dynamically generate a permission matrix by combining user identities and role attributes to implement the principle of least privilege. For example, the "project manager" has "read and write" permissions for all files, while the "construction personnel" only have "read and write" permissions for construction-related files and have no access permissions to other files.

[0064] Historical version access rules, which are used to restrict the access permissions of old versions after the version change of the engineering supervision documents. When the rule engine detects a version change in the engineering supervision documents, it will automatically adjust the access control list of the old version files to complete version isolation. For example, when the file is updated to version 2, the permissions of version 1 will be set to "readable only by auditors".

[0065] Specifically, in this embodiment, the rule engine framework Drools is adopted. The rule engine can automatically release the permission change policy according to the engineering stage. Through dual control of the stage and role, it ensures that users can only access the files within their scope of responsibility, thereby reducing the risk of internal leakage. At the same time, the rule engine supports declarative rule definition, which enables administrators to flexibly adjust the policy according to project requirements. For example, if a new "completion stage" needs to be added, only the corresponding rules need to be added, thereby improving the security and access control accuracy of the engineering supervision documents.

[0066] Furthermore, the permission change policy is used to dynamically adjust the access permissions of engineering supervision documents, ensure that the permissions match the project progress, and at the same time achieve version isolation and permission synchronization. Among them, version isolation restricts access to old version files and only allows specific roles to view historical versions. Permission synchronization is used to synchronize permission change events to all user terminals in real time to ensure that the terminal permissions are consistent with the server.

[0067] Furthermore, the permission synchronization includes:

[0068] Broadcasting permission change events to all user terminals through a distributed message push mechanism;

[0069] Online user terminals subscribe to the broadcast permission change events, automatically refreshing the local permission cache. Offline user terminals lock file access and refresh the local permission cache after reconnecting.

[0070] Specifically, the permission change event is a permission change instruction that needs to be synchronized to all terminal devices in real time after the rule engine triggers a permission adjustment based on the project phase information. For example, when the system detects that the project phase changes from the "design phase" to the "construction phase", the rule engine immediately generates a permission change event and broadcasts the change instruction to all registered terminals through the RedisPub / Sub distributed message system. This mechanism ensures that after the permission is changed, online terminal devices can immediately receive the message and automatically refresh the local permission cache. When offline terminal devices reconnect to the server, they will actively retrieve the latest permission configuration and synchronize the local cache, thereby achieving the consistency of device permissions across the platform. As shown in Table 4, to ensure the traceability of operations, each permission change and synchronization status will be fully recorded. The log information is stored in a structured format.

[0071] Table 4 Log Information

[0072] User ID U001 File ID F001 Operation Permission Synchronization Time 2024-03-14T10:25:00Z Status Success Device Number Unique Identifier of Terminal Device

[0073] Furthermore, the key rotation mechanism is used to update the CRL and generate new keys to ensure the security of file encryption. The specific implementation steps are as follows: Use the CP-ABE algorithm to generate a brand-new encryption key, ensuring that the key is bound to the access control policy of the current phase. Use this new key to re-encrypt the associated files, blocking the access ability of the old key to the files in the new phase. Add the old key to the CRL and synchronize the updated CRL to all user terminals through a secure channel. This process uses TLS encryption for transmission to prevent the CRL from being tampered with or stolen during distribution. Then, before decrypting the file, the user terminal needs to request the latest CRL from the authentication server for verification. If it is detected that the key to be used exists in the CRL, the decryption operation will be rejected and a violation access log will be recorded, ensuring the continuous effectiveness of file encryption.

[0074] Step Four: Figure 2 This is a schematic diagram of the process for the user to access the project supervision files provided by the present invention. As Figure 2As shown in the upper part of , listen for file transfer requests, embed invisible watermarks in the project supervision files, and determine whether the target platform is a controlled platform; if the target platform is the controlled platform, transmit the project supervision files according to user permissions; otherwise, create a secure transmission sandbox and decrypt the files within the secure transmission sandbox.

[0075] Among them, a file transfer request refers to an operation initiated by a user or a system to transfer a project supervision file from one place to another. The transfer starting point and ending point cover platforms such as servers, user terminals, and cloud storage. A controlled platform is a high-security environment controlled by a system administrator or an organization, while a non-controlled platform is a platform with unguaranteed security such as external devices, third-party applications, or public networks, such as personal USB drives, social media platforms, or uncertified external servers.

[0076] Furthermore, the process of embedding the invisible watermark includes:

[0077] Divide the project supervision file into N data blocks. Each block can be a part of the file, such as a pixel block in an image or a page area in a document. And perform a discrete cosine transform (DCT) on each data block. The DCT transform decomposes the file content into frequency components, generating a DCT transform coefficient matrix; the values in the coefficient matrix represent the energy distribution of different frequencies, facilitating subsequent watermark embedding.

[0078] Partition the DCT transform coefficient matrix according to a preset frequency threshold, and extract low-frequency DCT coefficients and high-frequency DCT coefficients;

[0079] Among them, the low-frequency DCT coefficients represent the global features of the project supervision file (such as overall brightness or color distribution), usually located in the upper left corner of the matrix. The high-frequency DCT coefficients represent the detailed information of the project supervision file (such as edges or textures), usually located in the lower right corner of the matrix.

[0080] Since the low-frequency DCT coefficients have less visual impact on the file, embed watermark information in the low-frequency DCT coefficients. The watermark information includes user ID, timestamp, and file hash value, expressed as:

[0081] C′(u,v)=C(u,c)+α×W(u,v);

[0082] Among them, C'(u,v) is the updated low-frequency DCT coefficient, C(u,v) is the original low-frequency DCT coefficient, W(u,v) is the watermark information, α is the strength factor, and u and v are the row and column indices of the DCT transform coefficient matrix. By adjusting α, a balance can be achieved between invisibility (the watermark is invisible) and robustness (the watermark can be extracted). For example, when α is smaller, the watermark is more concealed, and when α is larger, the watermark is more resistant to attacks.

[0083] Perform an inverse DCT transformation on the DCT transformation coefficient matrix to convert the frequency domain data back to the spatial domain, obtaining the data block with the watermark; merge all the data blocks to obtain the updated project supervision document.

[0084] By embedding the watermark in the low-frequency region of the file, the visual effect of the file is not affected, ensuring that the user cannot detect the existence of the watermark during normal use, and guaranteeing the appearance and usage experience of the project supervision document. In addition, the watermark information is bound to the file, enhancing the anti-counterfeiting and anti-tampering capabilities of the project supervision document, thus improving the security, access control accuracy, and audit traceability capabilities of the project supervision document.

[0085] Furthermore, the creation process of the secure transmission sandbox includes:

[0086] Initialize the secure transmission sandbox on the target platform and create a controlled running space for the project supervision document. The secure transmission sandbox is implemented using the isolation technology of the operating system. For example, use namespace on Linux and Job Objects on Windows, which is completely isolated from the main system environment. In addition, the controlled running space restricts the access rights of the project supervision document, only allowing the file to be decrypted and viewed within the sandbox, and prohibiting the file content from leaving the sandbox in any form.

[0087] Perform file decryption within the secure transmission sandbox and prevent file copy, paste, drag, print, and screenshot operations through a process-level interception mechanism; among them, the secure transmission sandbox on the desktop intercepts global screenshot requests through the operating system hook mechanism (such as SetWindowsHookEx in Windows) to prevent users from capturing file content through screenshot tools. The secure transmission sandbox in the browser intercepts the file access interface through WebAssembly technology to limit the scope of file operations. Disable high-risk APIs and screenshot APIs and replace them with a black screen image return to prevent file content from being captured and saved by screenshots.

[0088] The sandbox is embedded with behavior monitoring to detect user operations in real time. If the abnormal access behavior is detected, the process of the secure transmission sandbox will be forcibly terminated.

[0089] The sandbox allows users to securely view files on an uncontrolled platform without affecting the normal reading experience. Isolating file operations from the main system environment ensures that file content will not leak to the uncontrolled platform, thus improving the security and access control accuracy of the project supervision document.

[0090] Step 5: Record the operation log, perform signature verification on the operation log, and write it into the blockchain; construct a knowledge graph based on the blockchain for detecting abnormal access behaviors, compare the invisible watermark with the operation log, and generate a traceability report.

[0091] Among them, the operation behaviors of users viewing, downloading, and transmitting engineering supervision documents are recorded in detail to generate an operation log containing user ID, file ID, operation type, timestamp, device information, and platform type. The Ed25519 signature algorithm is used to digitally sign each log, and the signature result is appended to the log to form a complete data packet, ensuring the authenticity and integrity of the file. The signed log is written into a private chain based on Hyperledger Fabric through a smart contract. After the smart contract verifies the validity of the signature, the log is stored in the blockchain to ensure immutability.

[0092] At the same time, use the Neo4j graph database to construct a knowledge graph, and parse the operation logs in the blockchain into graph nodes and graph relationships for visual storage. The graph nodes include user ID, file ID, operation type, timestamp, device information, and platform type, and the graph relationship represents the operation behavior, such as "User A downloaded File F on Platform P".

[0093] Furthermore, the abnormal access behaviors include frequent cross-platform access and short-term high-frequency access;

[0094] The inspection method for frequent cross-platform access includes: setting a first time window, counting the download operations of the user on different target platforms, and if the same user downloads the same engineering supervision document from more than K target platforms within the first time window, an abnormal warning is triggered;

[0095] The inspection method for short-term high-frequency access includes: setting a second time window, calculating the access entropy value of the user for the engineering supervision document, and if the access entropy value exceeds the set entropy threshold, the abnormal warning is triggered.

[0096] Abnormal access behaviors can also include the inspection methods for device / IP change access and file abnormal access.

[0097] The inspection method for device / IP change access includes: monitoring that the same user replaces the device or IP address to access the same file within a short period of time, and if the device fingerprint or IP address of the user changes more than M times within the second time window, an abnormal warning is triggered.

[0098] The inspection method for file abnormal access includes: monitoring the file access permission, and if the user's role does not conform to the access rule but still tries to access the file, an abnormal warning is triggered.

[0099] Specifically, such asFigure 2 As shown in the lower part of

[0100] H=-∑ i P i logP i ;

[0101] where H is the access entropy value, and P i is the frequency of the i-th operation type (such as viewing and downloading), and log() is the logarithmic function.

[0102] When an exception warning is triggered, extract the invisible watermark in the file, obtain the embedded user ID, timestamp, and file hash value, query the operation log of the user on this file at this time point in the blockchain, and generate a traceability report, including the leaked file, the responsible user, the operation time, and device information.

[0103] The operation log is signed with Ed25519 and stored in the blockchain, ensuring its authenticity and tamper-proof ability. The knowledge graph presents the relationship between users, files, and platforms. Through Cypher queries, frequent cross-platform access behaviors can be quickly discovered, effectively improving the efficiency of anomaly detection. In addition, the comparison between the invisible watermark and the blockchain log can accurately locate the source of file leakage, further enhancing the security of engineering supervision files, the accuracy of access control, and the audit and traceability ability.

[0104] Step 6: Execute file destruction when the destruction conditions are met, and receive a request to revoke the decryption key.

[0105] Specifically, set the self-destruction conditions according to the number of accesses (such as up to 3 times of opening) or time (such as invalid after 24 hours). The user terminal marks the file as "destroyed" and deletes the local file copy to ensure that it cannot be accessed again. After the client completes file destruction, it sends a request to revoke the decryption key to the server. The server processes the request, adds the decryption key associated with this file to the CRL, updates and distributes the CRL to all relevant clients to ensure that the old key cannot decrypt the file.

[0106] The present invention first uses the CP-ABE encryption algorithm to perform fine-grained permission control on files, ensuring that only users who meet the access policy can decrypt the files. Combining with the key rotation mechanism, the encryption key is updated regularly and the old key is revoked, thus preventing the illegal use of expired keys at the source. Secondly, the engineering stage information is matched in real time through the rule engine, the file access permissions are dynamically adjusted, cross-terminal permission synchronization is achieved by combining the distributed message push technology, and the access scope of old version files is automatically restricted through the version isolation strategy. In the file transmission and usage links, the invisible watermark technology embeds the user identity, timestamp and file hash value into the file frequency domain, which not only keeps the file appearance imperceptible, but also provides a unique identifier for tracing leaks; the secure transmission sandbox prohibits high-risk behaviors such as screenshotting and printing through memory isolation and operation interception, preventing the leakage of file content. In addition, all user operation logs are digitally signed and written into the blockchain, the smart contract is used to ensure the data cannot be tampered with, and a knowledge graph is constructed based on Neo4j to realize the multi-dimensional correlation analysis of operation behaviors, accurately identifying abnormal access patterns. When the file triggers the preset destruction condition, memory erasure and key revocation are automatically executed to eliminate the risk of residual sensitive information. Through the organic coordination of the above technologies, the dynamic permission control and full-link traceability of engineering supervision files are realized, improving the security, access control accuracy and audit traceability ability of engineering supervision files.

[0107] Embodiment 2:

[0108] A construction engineering company A is responsible for multiple infrastructure projects. Since the engineering supervision files involve core information such as construction drawings, quality inspection reports, progress plans and change approval forms, the company uses a digital management platform to store and share engineering supervision files. However, as the engineering project progresses, it is difficult to dynamically adjust file access permissions, the risk of data leakage increases, and it is difficult to trace files. The traditional static permission management method can no longer meet the security requirements. To solve the above problems, Company A introduced an anti-leakage system for engineering supervision files, as Figure 3 shown, including:

[0109] Refer to Figure 3 's key management module, bind attributes to the uploaded engineering supervision files, generate encryption keys using the CP-ABE algorithm and encrypt the engineering supervision files;

[0110] Refer to Figure 3 's dynamic permission engine module, which is used to monitor project progress events and obtain the engineering stage information of the engineering supervision files; based on the rule engine, match the engineering stage information, and execute the permission change strategy and key rotation mechanism; the permission change strategy is used to perform version isolation and permission synchronization on the engineering supervision files; the key rotation mechanism is used to update the key revocation list and generate new keys;

[0111] Refer toFigure 3 The secure transmission sandbox module listens for file transmission requests, embeds invisible watermarks in the project supervision files, and determines whether the target platform is a controlled platform. If the target platform is the controlled platform, the project supervision files are transmitted according to the user permissions. Otherwise, a secure transmission sandbox is created, and the files are decrypted within the secure transmission sandbox.

[0112] Reference Figure 3 The blockchain auditing module records operation logs, performs signature verification on the operation logs and then writes them into the blockchain. A knowledge graph is constructed based on the blockchain for detecting abnormal access behaviors. The invisible watermark is compared with the operation logs to generate a traceability report. File destruction is performed when the destruction conditions are met, and a request to revoke the decryption key is received.

[0113] Table 5 Log Information

[0114]

[0115] Table 6 Traceability Report

[0116]

[0117] Specifically, for example, User A (a supervisor) downloads a construction acceptance report in the OA system. When User A performs the download operation, the system automatically generates an operation log, as shown in Table 5, including the user ID, file ID, and operation, etc., thus assisting in constructing a file access relationship graph.

[0118] If File F001 is leaked, as shown in Table 6, Company A can extract the invisible watermark from the leaked file, compare it with the blockchain log, confirm the leakage source, and generate a traceability report, thereby improving the security, compliance, and traceability of the project supervision files.

[0119] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for preventing the leakage of engineering supervision documents, characterized in that, Including: Bind attributes to the uploaded project supervision documents, generate an encryption key using the CP-ABE algorithm, and encrypt the project supervision documents; Monitor project progress events and obtain the project phase information of the project supervision documents; Based on a rule engine, match the project phase information and execute a permission change policy and a key rotation mechanism; The permission change policy is used for version isolation and permission synchronization of the project supervision documents; the key rotation mechanism is used to update the key revocation list and generate a new key; Monitor file transfer requests, embed an invisible watermark in the project supervision documents, and determine whether the target platform is a controlled platform; If the target platform is the controlled platform, transmit the project supervision documents according to user permissions; Otherwise, create a secure transmission sandbox and decrypt the file within the secure transmission sandbox; Record operation logs, perform signature verification on the operation logs, and write them to the blockchain; Construct a knowledge graph based on the blockchain for detecting abnormal access behaviors, compare the invisible watermark with the operation logs, and generate a traceability report; Execute file destruction when the destruction conditions are met and receive a request to revoke the decryption key.

2. The method for preventing leakage of engineering supervision documents according to claim 1, characterized in that, The rule engine matches the project phase information based on a preset permission rule library, and the permission rule library includes: a phase permission mapping rule for defining file access permissions for different project phases; a role permission rule for allocating access permissions according to the identities of project participants; a historical version access rule for restricting access permissions to old versions after the version change of the project supervision documents.

3. The method for preventing leakage of engineering supervision documents according to claim 1, characterized in that, The permission synchronization includes: broadcasting permission change events to all user terminals through a distributed message push mechanism; online user terminals subscribe to the broadcast permission change events, automatically refresh the local permission cache, and offline user terminals lock file access and refresh the local permission cache after reconnecting.

4. A method for preventing leakage of engineering supervision documents according to claim 1, characterized in that, The process of embedding the invisible watermark includes: Divide the project supervision document into N data blocks, perform a discrete cosine transform on each data block to generate a DCT transform coefficient matrix; partition the DCT transform coefficient matrix according to a preset frequency threshold, and extract low-frequency DCT coefficients and high-frequency DCT coefficients; where the low-frequency DCT coefficients represent the global features of the project supervision document; the high-frequency DCT coefficients represent the detailed information of the project supervision document; Embed watermark information in the low-frequency DCT coefficients, and the watermark information includes a user ID, a timestamp, and a file hash value, expressed as: C’(u,v)=C(u,v)+α×W(u,v); where C'(u,v) is the updated low-frequency DCT coefficient, C(u,v) is the original low-frequency DCT coefficient, W(u,v) is the watermark information, α is an intensity factor, and u and v are the row and column indices of the DCT transform coefficient matrix; Perform an inverse DCT transform on the DCT transform coefficient matrix to obtain the watermarked data block; merge all the data blocks to obtain the updated project supervision document.

5. A method for preventing leakage of engineering supervision documents according to claim 1, characterized in that, The process of creating the secure transmission sandbox includes: Initialize the secure transmission sandbox on the target platform and create a controlled running space for the project supervision file; Execute file decryption within the secure transmission sandbox and prevent copy, paste, drag, print, and screenshot operations of the project supervision file through a process-level interception mechanism; among them, the secure transmission sandbox on the desktop intercepts global screenshot requests through the operating system hook mechanism, and the secure transmission sandbox in the browser intercepts file access interfaces through WebAssembly technology; If the abnormal access behavior is detected, forcibly terminate the process of the secure transmission sandbox.

6. The method for preventing leakage of engineering supervision documents according to claim 1, characterized in that The abnormal access behavior includes frequent cross-platform access and short-term high-frequency access; The inspection method for the frequent cross-platform access includes: setting a first time window, counting the download operations of the user on different target platforms, and if the same user downloads the same project supervision file from more than K target platforms within the first time window, an abnormal warning is triggered; The inspection method for the short-term high-frequency access includes: setting a second time window, calculating the access entropy value of the user to the project supervision file, and if the access entropy value exceeds the set entropy threshold, the abnormal warning is triggered.

7. An engineering supervision document anti-disclosure system, characterized in that, Includes: A key management module that binds attributes to the uploaded project supervision file, generates an encryption key using the CP-ABE algorithm, and encrypts the project supervision file; A dynamic permission engine module for listening to project progress events and obtaining the project phase information of the project supervision file; Based on a rule engine, match the project phase information and execute a permission change policy and a key rotation mechanism; The permission change policy is used for version isolation and permission synchronization of the project supervision file; the key rotation mechanism is used to update the key revocation list and generate new keys; A secure transmission sandbox module that listens for file transmission requests, embeds an invisible watermark in the project supervision file, and determines whether the target platform is a controlled platform; If the target platform is the controlled platform, transmit the project supervision file according to the user's permissions; Otherwise, create a secure transmission sandbox and decrypt the file within the secure transmission sandbox; A blockchain auditing module that records operation logs, performs signature verification on the operation logs, and writes them into the blockchain; Construct a knowledge graph based on the blockchain for detecting abnormal access behavior, compare the invisible watermark with the operation logs, generate a traceability report; execute file destruction when the destruction conditions are met, and receive a request to revoke the decryption key.

Citation Information

Patent Citations

  • Web log abnormal behavior identification method based on knowledge graph

    CN114328962A

  • Identifier-based data tracking and tracing method

    CN116579008A

  • Method, device and system relating to transaction security

    WO2002043346A1

  • Water sample traceability management method and system based on alliance blockchain ledger and smart contract

    WO2024239468A1

Cited By

  • Project authority management system and steam pipe network project authority management method

    CN121030726A

  • Integrated chip data security control method, computer device and storage medium

    CN121071945A

  • Project file confidentiality management system and method based on SD-WAN overseas network environment

    CN121211483A