Building CAD fine-grained encryption method and device based on primitive attributes and storage medium
Through the fine-grained encryption method of architectural CAD based on element attributes, precise encryption and permission control of individual elements are achieved, which solves the problem of inflexible element encryption methods in the existing technology, and improves the security and flexibility of architectural CAD drawings.
Patent Information
- Application Number
- CN202510438536.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-11
AI Technical Summary
The existing architectural CAD drawing encryption method cannot achieve fine-grained independent permission control for a single element, and it is difficult to meet the complex and diverse information security needs, and users are not flexible enough.
The fine-grained encryption method of architectural CAD based on element attributes is used to analyze element attribute information, establish an element ID database, and adopt various encryption modes and permission controls such as visible, hidden, and time-sensitive to achieve accurate encryption of a single element.
It improves the security and flexibility of architectural CAD drawing data, supports precise encryption and permission control of individual elements, and improves the flexibility and security of encryption.
Smart Images

Figure CN120296791A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of CAD data security, and particularly to a fine-grained encryption method, device and storage medium for building CAD based on graphic element attributes. Background Art
[0002] With the digital development of the construction industry, building CAD drawings, as the core design documents of projects, carry a large amount of important and sensitive design information, such as building shapes, structural details, geometric data, material parameters, etc., and also embody the wisdom and unique creativity of designers, having extremely high commercial value. However, these drawings are faced with security threats such as being illegally obtained and tampered with. Once this information is leaked, it will seriously damage the commercial interests of design institutes and construction parties.
[0003] Therefore, design institutes or construction parties often take encryption measures for drawings. The existing CAD drawing encryption methods usually adopt file-level and partial-level encryption. File-level encryption encrypts the entire CAD drawing file, encrypting the drawing into a read-only block. One can see the drawing when opening the file but cannot edit it. This encryption method is obviously not flexible enough. Partial-level encryption encrypts part of the CAD file and encrypts part of the drawing. This encryption method has improved flexibility, but the granularity is still relatively coarse. However, in related technologies, the mainstream encryption methods are all file-level and partial-level encryption, which cannot protect individual graphic elements (such as specific lines, specific annotations, etc.), lack fine-grained independent permission control for graphic elements (such as only encrypting specific graphic elements and allowing other graphic elements to be editable), and cannot perform in-depth encryption based on graphic element attributes, making it difficult to meet the complex and diverse information security requirements in architectural design, and the user experience is not flexible enough.
[0004] In view of the above problems, no effective solution has been proposed yet.
[0005] To solve the above problems, it is necessary to develop a method, device and corresponding storage medium that can achieve fine-grained encryption based on graphic element attributes. Through graphic element attribute parsing, precise encryption of individual graphic elements is realized to improve the security, flexibility and precision of building CAD drawing data encryption. Summary of the Invention
[0006] The embodiments of the present invention provide a fine-grained encryption method, device and storage medium for building CAD based on graphic element attributes, to at least solve the technical problems of inflexible use and low precision in the prior art, and propose the following technical solutions:
[0007] In a first aspect, the embodiments of the present invention provide a fine-grained encryption method for building CAD based on graphic element attributes, including:
[0008] Receiving a CAD drawing file;
[0009] Analyze the primitive attribute information in the CAD drawing file to obtain the primitive attribute data of the target to be encrypted;
[0010] Establish an ID database corresponding to the target primitive to be encrypted according to the primitive attribute data of the target to be encrypted;
[0011] In response to the user's encryption permission configuration operation, perform at least one of the following encryption modes on the target primitive to be encrypted;
[0012] In some embodiments, the step of establishing the primitive ID database includes:
[0013] Associate and store the target primitive to be encrypted and its attribute data with the ID identifier in the primitive ID database;
[0014] The decryption operation of the primitive ID database is implemented by an independent decryption unit. The decryption unit generates a decryption token based on the user permission verification result and reads the decrypted data according to the decryption token.
[0015] In some embodiments, after encrypting the target primitive to be encrypted, the method includes:
[0016] Visible encryption state, the primitive is displayed as visible, and the primitive can be configured according to the encryption permission operation;
[0017] Hidden encryption state, the primitive is displayed as invisible. After entering the set key for verification, the primitive becomes visible again, and the primitive can be configured according to the encryption permission operation;
[0018] Time-limited encryption state, the primitive is displayed as visible within the set time. When the set time is exceeded, a secondary encryption process is automatically triggered to re-encrypt the primitive and update the encryption policy in the primitive ID database. The secondary encryption includes switching the encryption algorithm to make the primitive invisible.
[0019] In some embodiments, the switching of the encryption algorithm includes at least one of the following: standard encryption algorithm, AES (Advanced Encryption Standard) algorithm, RSA (Rivest-Shamir-Adleman) algorithm, and hybrid encryption method.
[0020] In some embodiments, the encryption permission configuration operation further includes at least one of the following permission control instructions:
[0021] Operation permission control: Restrict users' operations on encrypted primitives such as modification, decomposition, deletion, or copying;
[0022] Watermark permission control: Embed a dynamic watermark in the primitive in the visible encryption state through the discrete cosine transform algorithm. The watermark content includes the user identity identifier and the timestamp;
[0023] Output permission control: Forbid or authorize users to perform printing and exporting operations on encrypted graphics elements.
[0024] In a second aspect, an embodiment of the present invention further provides a file decryption method, including: receiving a CAD drawing file to be decrypted; obtaining a target key, where the target key includes an ID database decryption algorithm or at least one graphics element decryption algorithm or a password set during encryption; verifying the ID corresponding to the graphics element in the ID database according to the decryption algorithm or password, and decrypting at least one encrypted graphics element in the CAD drawing file to be decrypted.
[0025] In a third aspect, an embodiment of the present invention further provides a fine-grained encryption device for building CAD based on graphics element attributes, which is characterized by including:
[0026] A file receiving module, configured to receive a CAD drawing file;
[0027] An attribute parsing module, configured to parse the graphics element attribute information in the CAD drawing file to obtain the attribute data of the target graphics element to be encrypted;
[0028] An ID establishment module, configured to generate a unique ID identifier and a corresponding graphics element ID database according to the graphics element attribute information;
[0029] An encryption execution module, configured to respond to a user's encryption permission configuration operation and perform visible encryption, hidden encryption, or time-limited encryption;
[0030] Among them, the encryption execution module includes:
[0031] A visible encryption unit, configured to convert the target graphics element to be encrypted into a visible encryption state and embed a dynamic watermark based on the encryption permission configuration;
[0032] A hidden encryption unit, configured to respond to a user's setting of a key and trigger a hidden encryption state based on the encryption permission configuration;
[0033] A time-limited encryption unit, configured to set time-limited parameters and monitor the system timestamp based on the encryption permission configuration, and trigger a secondary encryption process after exceeding the termination timestamp;
[0034] A permission control module, configured to manage the operation permissions of users on encrypted graphics elements, watermark embedding, and output permissions.
[0035] In some of the embodiments, the ID establishment module is further configured to:
[0036] Associate and store the target graphics element to be encrypted and its attribute data with the ID identifier in the graphics element ID database;
[0037] Communicate with an independent decryption unit, which generates a decryption token based on the user permission verification result and reads the decrypted data in the graphic element ID database through the decryption token.
[0038] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium storing a computer program, and when the program is executed by a processor, the method described in any one of the above first aspects is implemented.
[0039] The present invention has the following advantages or beneficial effects: Compared with traditional encryption methods, the method, device and storage medium for fine-grained encryption of building CAD based on graphic element attributes provided by the embodiments of the present invention refine the encryption granularity from the file level and local level to the graphic element level, support multiple encryption modes (visible, hidden, time-limited) and permission control (modification, printing, watermarking), meet the requirements of different scenarios, and use an encryption algorithm to perform precise encryption of different degrees on a single graphic element (such as a specific line, a specific annotation, etc.) or a group of graphic elements, realizing fine-grained encryption protection and improving the flexibility of encryption.
[0040] At the same time, the graphic element encryption method can perform fine-grained permission control at the graphic element level (such as only encrypting specific graphic elements and allowing other graphic elements to be editable), and through the combination of the graphic element ID database and the independent decryption unit, it is ensured that only authorized users can access the encrypted graphic elements. This deep encryption based on graphic element attributes solves the problems of extensive permission control and insufficient flexibility in traditional encryption technology solutions, and significantly improves the security of building CAD drawing data.
[0041] Furthermore, the establishment of the ID database corresponding to the target graphic element to be encrypted in the present invention, combined with hidden encryption and time-limited encryption, greatly improves the security of encryption. In the scenario of classified encryption, the permission to view the attributes of downstream users can be effectively controlled.
[0042] Moreover, the present invention saves the ID database together with the drawing. First, it does not increase the size of the drawing file. Second, it improves the flexibility of encryption. Third, the encryption performance is better than traditional encryption methods. Description of the Drawings
[0043] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0044] Figure 1 is a flowchart of a method for fine-grained encryption of building CAD based on graphic element attributes according to an embodiment of the present invention;
[0045] Figure 2 is a flowchart of a method for fine-grained decryption of building CAD based on graphic element attributes according to an embodiment of the present invention;
[0046] Figure 3 It is a schematic diagram of a graphic element in the CAD drawing according to an embodiment of the present invention;
[0047] Figure 4 It is a schematic diagram of the visible encryption mode of a graphic element in the CAD drawing according to an embodiment of the present invention;
[0048] Figure 5 It is a schematic diagram of the hidden encryption mode of a graphic element in the CAD drawing according to an embodiment of the present invention;
[0049] Figure 6 It is a schematic diagram of the time-limited encryption mode of a graphic element in the CAD drawing according to an embodiment of the present invention;
[0050] Figure 7 It is a structural framework diagram of a building CAD fine-grained encryption device based on graphic element attributes according to an embodiment of the present invention;
[0051] Figure 8 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention.
[0052] Reference numerals: 71, file receiving module; 72, attribute parsing module; 73, ID establishment module; 74, encryption execution module (including 741 visible encryption unit, 742 hidden encryption unit, 743 time-limited encryption unit); 75, permission control module. Detailed implementation manners
[0053] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Based on the embodiments provided by the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.
[0054] Obviously, the accompanying drawings in the following description are only some examples or embodiments of the present invention. For those of ordinary skill in the art, without making creative efforts, the present invention can also be applied to other similar scenarios based on these drawings. In addition, it can also be understood that although the efforts made in this development process may be complex and lengthy, for those of ordinary skill in the art related to the content disclosed by the present invention, making some design, manufacturing, or production changes based on the technical content disclosed by the present invention is only a conventional technical means and should not be understood that the content disclosed by the present invention is insufficient.
[0055] References to "embodiments" in this invention mean that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those of ordinary skill in the art will explicitly and implicitly understand that the embodiments described in this invention can be combined with other embodiments without conflict.
[0056] Unless otherwise defined, technical terms or scientific terms involved in this invention should have the ordinary meaning understood by those with ordinary skills in the technical field to which this invention belongs. The words such as "a", "an", "one", "the", etc. involved in this invention do not indicate a limitation in quantity and can represent a singular or plural number. The terms "include", "comprise", "have" and any variations thereof involved in this invention are intended to cover non-exclusive inclusion; for example, a process, method, device, product, or equipment that includes a series of steps or modules (units) is not limited to the listed steps or units, but may further include unlisted steps or units, or may further include other steps or units inherent to these processes, methods, products, or equipment. The terms "connected", "coupled", etc. involved in this invention are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The term "plurality" involved in this invention refers to two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. The terms "first", "second", "third", etc. involved in this invention are only used to distinguish similar objects and do not represent a specific order for the objects.
[0057] As used herein, the "CAD drawing file" refers to a DWG format file that can run in CAD design software and is used for drawing, editing, modifying, storing, and viewing CAD drawings.
[0058] As used herein, as Figure 3 shown, a "graphical primitive" refers to a geometric figure that can be separately created, edited, and operated in CAD design software and is the most basic element that constitutes a complex CAD graphic, just like letters are the basis for forming words. As shown in the figure, a line, a circle, a dimension, a text, etc. are all graphical primitives.
[0059] An embodiment of the present invention provides a fine-grained encryption method for building CAD based on graphical primitive attributes. Figure 1 is a flowchart of the fine-grained encryption method for building CAD based on graphical primitive attributes according to an embodiment of the present invention, as Figure 1As shown, the method includes the following steps:
[0060] Step S11, receiving a CAD drawing file;
[0061] Step S12, parsing the graphic element attribute information in the CAD drawing file to obtain the attribute data of the target graphic element to be encrypted;
[0062] Specifically, parsing the graphic element attribute information includes characteristic data such as color, layer, linetype, linetype scale, print style, line width, transparency, hyperlink, thickness, dimension, coordinates, etc. for describing the corresponding graphic element.
[0063] Step S13, establishing an ID database corresponding to the target graphic element to be encrypted according to the attribute data of the target graphic element to be encrypted;
[0064] Specifically, the step of establishing the graphic element ID database includes:
[0065] Associating and storing the target graphic element to be encrypted and its attribute data with the ID identifier in the graphic element ID database;
[0066] The decryption operation of the graphic element ID database is implemented by an independent decryption unit. The decryption unit generates a decryption token based on the user permission verification result and reads the decrypted data according to the decryption token.
[0067] Furthermore, the unique ID identifier is generated by the SHA-256 algorithm for the graphic element attribute data to ensure the uniqueness and non-tamperability of the ID.
[0068] Step S14, in response to the user's encryption permission configuration operation, performing at least one of the following encryption modes on the target graphic element to be encrypted;
[0069] Specifically, the user selects the target graphic element through a graphical interface and configures permissions (such as prohibiting copying, restricting export), and the system associates and stores the configuration information with the graphic element ID in the database.
[0070] Specifically, after encrypting the target graphic element to be encrypted, the method includes:
[0071] In the visible encryption state, the graphic element is displayed as visible, and the graphic element can be operated according to the encryption permission configuration;
[0072] In the hidden encryption state, the graphic element is displayed as invisible. After inputting the set key for verification, the graphic element becomes visible again, and the graphic element can be operated according to the encryption permission configuration;
[0073] Time-limited encryption state. During the set time, the graphic elements are visible. When the set time is exceeded, a secondary encryption process is automatically triggered to re-encrypt the graphic elements and update the encryption policy in the graphic element ID database. The secondary encryption includes switching the encryption algorithm to make the graphic elements invisible.
[0074] Specifically, Figure 4 It is a schematic diagram of the visible encryption mode of graphic elements in a CAD drawing according to an embodiment of the present invention. The encrypted graphic elements are in a visible state, and users can perform operations such as modification, editing, copying, deletion, watermark setting, and printing according to the configured encryption permissions. Figure 5 It is a schematic diagram of the hidden encryption mode of graphic elements in a CAD drawing according to an embodiment of the present invention. The encrypted graphic elements are in a hidden state. The graphic elements can be restored to a visible state by entering the set password. Then, users can perform operations such as modification, editing, copying, deletion, watermark setting, and printing according to the configured encryption permissions. Figure 6 It is a schematic diagram of the time-limited encryption mode of graphic elements in a CAD drawing according to an embodiment of the present invention. The encrypted graphic elements are in a visible state. When the set time is exceeded, a secondary encryption process is automatically triggered, and the encryption algorithm is switched to make the graphic elements invisible.
[0075] Further, the encryption algorithm includes at least one of the following: standard encryption algorithm, AES (Advanced Encryption Standard) algorithm, RSA (Rivest-Shamir-Adleman) algorithm, and hybrid encryption method. Among them, standard encryption algorithm is used for visible encryption, the combination of AES algorithm and RSA algorithm is used for hidden encryption, and hybrid encryption algorithm is used for time-limited encryption.
[0076] Further, time-limited encryption listens to the system timestamp and automatically triggers secondary encryption when the set time is exceeded.
[0077] Optionally, the encryption permission configuration operation further includes at least one of the following permission control instructions:
[0078] Operation permission control: Restrict users' operations of modifying, decomposing, deleting, or copying encrypted graphic elements;
[0079] Watermark permission control: Embed a dynamic watermark in the graphic elements in the visible encryption state through the discrete cosine transform algorithm. The watermark content includes the user identity identifier and the timestamp;
[0080] Output permission control: Prohibit or authorize users to perform printing and exporting operations on encrypted graphic elements.
[0081] Through steps S11 to S14 in the embodiments of the present invention, the technical solution of the present invention refines the encryption granularity from the file level and local level to the primitive level, supports multiple encryption modes (visible, hidden, time-limited) and permission controls (modification, printing, watermarking), meets the requirements of different scenarios, and uses an encryption algorithm to perform precise encryption of different degrees on a single primitive (such as a specific line, a specific annotation, etc.) or a group of primitives, realizing fine-grained encryption protection and improving the flexibility of encryption.
[0082] Meanwhile, the primitive encryption method can perform fine-grained permission control at the primitive level (such as only encrypting specific primitives and allowing other primitives to be editable), and through the combination of the primitive ID database and the independent decryption unit, it is ensured that only authorized users can access the encrypted primitives. This deep encryption based on primitive attributes solves the problems of extensive permission control and insufficient flexibility in traditional encryption technical solutions, and significantly improves the security of building CAD drawing data.
[0083] Furthermore, the establishment of the ID database corresponding to the target primitive to be encrypted in the present invention, combined with hidden encryption and time-limited encryption, greatly improves the security of encryption. In the scenario of classified encryption, it can effectively control the permission for downstream users to view attributes.
[0084] Moreover, the present invention saves the ID database together with the drawing. First, it ensures that the size of the drawing file does not increase. Second, it improves the flexibility of encryption. Third, the encryption performance is better than that of traditional encryption methods.
[0085] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0086] The embodiments of the present invention provide a method for fine-grained decryption of building CAD based on primitive attributes. Figure 2 It is a flowchart of the method for fine-grained decryption of building CAD based on primitive attributes according to the embodiments of the present invention. As Figure 2 shown, the method includes the following steps:
[0087] S21 receives the CAD drawing file to be decrypted; S22 obtains the target key, where the target key includes the ID database decryption algorithm or at least one primitive decryption algorithm or the password set during encryption; S23 verifies the ID corresponding to the primitive in the ID database according to the decryption algorithm or password, and decrypts at least one encrypted primitive in the CAD drawing file to be decrypted. Among them, obtaining the ID database decryption algorithm or at least one primitive decryption algorithm or the password set during encryption enables the user to obtain the required information without decrypting the entire file, improving the flexibility of use while ensuring the security of the file, thus solving the technical problem that the entire file needs to be decrypted to ensure file security in the related art and the user's inflexible use.
[0088] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0089] The embodiment of the present invention provides a building CAD fine-grained encryption device based on primitive attributes. Figure 7 It is the structural framework diagram of the building CAD fine-grained encryption device according to the embodiment of the present invention, as Figure 7 shown, the device includes: a file receiving module 71, an attribute parsing module 72, an ID establishment module 73, an encryption execution module 74, and a permission control module 75;
[0090] The file receiving module 71 is used to receive the CAD drawing file;
[0091] The attribute parsing module 72 is used to parse the primitive attribute information in the CAD drawing file to obtain the target primitive attribute data to be encrypted;
[0092] The ID establishment module 73 is used to generate a unique ID identifier and the corresponding primitive ID database according to the primitive attribute information;
[0093] The encryption execution module 74 is used to respond to the user's encryption permission configuration operation and execute visible encryption, hidden encryption, or time-limited encryption;
[0094] Among them, the encryption execution module includes:
[0095] The visible encryption unit 741 is used to convert the target primitive to be encrypted into a visible encryption state based on the encryption permission configuration and embed a dynamic watermark;
[0096] The hidden encryption unit 742 is used to respond to the user's setting of the key and trigger the hidden encryption state based on the encryption permission configuration;
[0097] The aging encryption unit 743 is used to set aging parameters and monitor the system timestamp based on the encryption permission configuration, and trigger a secondary encryption process after exceeding the termination timestamp;
[0098] The permission control module 75 is used to manage the user's operation permissions on encrypted primitives, watermark embedding and output permissions.
[0099] In some of these embodiments, the attribute parsing module 42 is further used for:
[0100] Parse the primitive attribute information including color, layer, linetype, linetype scale, print style, line width, transparency, hyperlink, thickness, dimension, coordinates, etc., which are characteristic data used to describe the corresponding primitive, and organize these attribute information into a standardized data structure and pass it to the next module.
[0101] In some of these embodiments, the ID establishment module 43 is further used for:
[0102] Associate and store the to-be-encrypted target primitive and its attribute data with the ID identifier in the primitive ID database;
[0103] Communicate with the independent decryption unit, and the decryption unit generates a decryption token based on the user permission verification result and reads the decrypted data in the primitive ID database through the decryption token.
[0104] Through the modules 71 to 75 in the embodiments of the present invention, the technical solution of the present invention refines the encryption granularity from the file level and local level to the primitive level, supports multiple encryption modes (visible, hidden, aging) and permission control (modification, printing, watermark), meets the requirements of different scenarios, and uses an encryption algorithm to perform precise encryption of different degrees on a single primitive (such as a specific line, a specific annotation, etc.) or a primitive group, realizing fine-grained encryption protection and improving the flexibility of encryption.
[0105] At the same time, the primitive encryption method can perform fine-grained permission control at the primitive level (such as only encrypting specific primitives and allowing other primitives to be editable), and through the combination of the primitive ID database and the independent decryption unit, it is ensured that only authorized users can access the encrypted primitives. This deep encryption based on primitive attributes solves the problems of extensive permission control and lack of flexibility in traditional encryption technical solutions, and significantly improves the security of building CAD drawing data.
[0106] Furthermore, establishing the ID database corresponding to the to-be-encrypted target primitive in the present invention, combined with hidden encryption and aging encryption, greatly improves the security of encryption. In the scenario of classified encryption, it can effectively control the permission for downstream users to view attributes.
[0107] Moreover, the present invention saves the ID database together with the drawings. First, it prevents the drawing file size from increasing. Second, it improves the flexibility of encryption. Third, the encryption performance is superior to traditional encryption methods.
[0108] It should be noted that the above-mentioned each module can be a functional module or a program module, and can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned each module can be located in the same processor; or the above-mentioned each module can also be located in different processors in any combined form.
[0109] The embodiment of the present invention also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the building CAD fine-grained encryption method based on graphic element attributes in any embodiment of the present invention. Among them, the detailed implementation process of the building CAD fine-grained encryption method based on graphic element attributes has been described in detail in this specification, and will not be elaborated here.
[0110] The embodiment of the present invention also provides a computer-readable storage medium, characterized in that the storage medium stores a computer program, and when the program is read by the processor and loaded into the memory, the steps of the building CAD fine-grained encryption method based on graphic element attributes in any embodiment of the present invention are implemented when executed. Among them, the detailed implementation process of the building CAD fine-grained encryption method based on graphic element attributes has been described in detail in this specification, and will not be elaborated here.
[0111] In one embodiment, Figure 8 is a schematic structural diagram of an electronic device according to an embodiment of the present invention. The electronic device is connected with a network interface, a processor, a memory, and a storage controller through an internal system bus. Among them, the network interface is used to communicate with an external terminal through a network connection; the storage controller is connected to at least one non-volatile storage medium, and the storage medium stores an operating system and a computer program; the processor is used to provide computing and control capabilities; the memory is a volatile memory, responsible for loading the operating system and the computer program in the storage medium into the running environment; the processor realizes the building CAD fine-grained encryption method based on graphic element attributes by executing the program instructions in the memory.
[0112] Those skilled in the art can understand that Figure 8 the structure shown in
[0113] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by instructing relevant hardware through a computer program. This computer program can be stored in a computer-readable storage medium and, when running, can execute the processes of the above-described method embodiments. The memory, storage, database, or other media used herein all fall within the scope of storage media. Storage media include, but are not limited to: read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, magnetic disks, or optical discs, etc.
[0114] Those skilled in the art should understand that the technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.
[0115] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent should be subject to the appended claims.
Claims
1. A fine-grained encryption method for building CAD based on graphic primitive attributes, characterized in that, Including: Receiving CAD drawing files; Analyzing the primitive attribute information in the CAD drawing file to obtain the target primitive attribute data to be encrypted; Establishing an ID database corresponding to the target primitive to be encrypted according to the target primitive attribute data to be encrypted; Responding to the user's encryption permission configuration operation, performing at least one of the following encryption modes on the target primitive to be encrypted: Visible encryption mode, the steps include: obtaining the target primitive to be encrypted, and converting the target primitive to be encrypted into a visible encryption state according to the encryption permission configuration; Hidden encryption mode, the steps include: obtaining the target primitive to be encrypted, setting a key according to the encryption permission configuration, and converting the target primitive to be encrypted into a hidden encryption state; Time-limited encryption mode, the steps include: obtaining the target primitive to be encrypted, setting a time limit parameter according to the encryption permission configuration, and converting the target primitive to be encrypted into a time-limited encryption state.
2. The method according to claim 1, wherein The steps of establishing the primitive ID database include: Associating and storing the target primitive to be encrypted and its attribute data with the ID identifier in the primitive ID database; The decryption operation of the primitive ID database is implemented by an independent decryption unit, and the decryption unit generates a decryption token based on the user permission verification result and reads the decrypted data according to the decryption token.
3. The method according to claim 1, wherein , after encrypting the target primitive to be encrypted, the method includes: In the visible encryption state, the primitive is displayed as visible, and the primitive can be operated according to the encryption permission configuration; In the hidden encryption state, the primitive is displayed as invisible. After inputting the set key for verification, the primitive becomes visible again, and the primitive can be operated according to the encryption permission configuration; In the time-limited encryption state, the primitive is displayed as visible within the set time. When the set time is exceeded, a secondary encryption process is automatically triggered to re-encrypt the primitive and update the encryption policy in the primitive ID database. The secondary encryption includes switching the encryption algorithm to make the primitive invisible.
4. The method according to claim 1 or 3, characterized in that, The switching of the encryption algorithm includes at least one of the following: standard encryption algorithm, AES (Advanced Encryption Standard) algorithm, RSA (Rivest-Shamir-Adleman) algorithm, and hybrid encryption method.
5. The method according to claim 1, characterized in that, The encryption permission configuration operation also includes at least one of the following permission control instructions: Operation permission control: restricting users' operations of modifying, decomposing, deleting, or copying encrypted primitives; Watermark permission control: embedding a dynamic watermark in the primitive in the visible encryption state through the discrete cosine transform algorithm, and the watermark content includes the user identity identifier and timestamp; Output permission control: prohibiting or authorizing users to perform printing and exporting operations on encrypted primitives.
6. An architectural CAD fine-grained encryption device based on graphic primitive attributes, characterized in that, Including: A file receiving module for receiving CAD drawing files; An attribute analysis module for analyzing the primitive attribute information in the CAD drawing file to obtain the target primitive attribute data to be encrypted; An ID establishment module for generating a unique ID identifier and the corresponding primitive ID database according to the primitive attribute information; An encryption execution module for performing visible encryption, hidden encryption, or time-limited encryption in response to the user's encryption permission configuration operation; Among them, the encryption execution module includes: A visible encryption unit for converting the target primitive to be encrypted into a visible encryption state based on the encryption permission configuration and embedding a dynamic watermark; A hidden encryption unit for triggering a hidden encryption state in response to a user setting a key based on an encryption permission configuration; An aging encryption unit for setting aging parameters and monitoring a system timestamp based on an encryption permission configuration, and triggering a secondary encryption process after exceeding a termination timestamp; A permission control module for managing a user's operation permissions on encryption primitives, watermark embedding, and output permissions.
7. The device according to claim 6, characterized in that The ID establishment module is further configured to: Associate and store the target primitive to be encrypted and its attribute data with the ID identifier in the primitive ID database; Communicate with an independent decryption unit, where the decryption unit generates a decryption token based on a user permission verification result and reads the decrypted data in the primitive ID database through the decryption token.
8. A computer-readable storage medium storing a computer program, characterized in that , When the program is executed by a processor, it implements the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and equipment for safety protection CAD drawing information
CN112084516A
Fine-grained protection method for drawing data
CN112241545A
Local encryption method and system for CAD file, storage medium and program product
CN117668878A
Data display method
WO2020133477A1