Electronic contract encryption storage method based on national secret algorithm
Through the electronic contract encryption storage method based on the Guomi algorithm, adaptive slice granularity and logical breakpoint segmentation, combined with differentiated encryption and index table construction, the security and access efficiency of electronic contracts in the existing technology are solved, and efficient structural identification and controllable access are achieved.
Patent Information
- Application Number
- CN202510864373.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-26
AI Technical Summary
The existing electronic contract encryption technology lacks a differentiated processing mechanism based on content complexity and structural characteristics, and it is difficult to ensure the security of sensitive data while taking into account access efficiency and system scalability. Especially in large-scale electronic contract archiving and review scenarios, security and refined management capabilities are insufficient.
Based on the contract content structure, complexity feature vectors are extracted, and slice sequences are generated through adaptive slice granularity and logical breakpoint segmentation, and differentiated Guoxin algorithm is used to perform independent encryption on each slice to construct an archive index table to achieve refined management.
It improves the structural recognition capability, encryption flexibility and access controllability of electronic contracts in the encrypted storage process, enhances the anti-attack ability and confidentiality level, and ensures the logical integrity of the contract and the granularity processing capability of information.
Smart Images

Figure CN120354437A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of contract encryption storage, and in particular to an electronic contract encryption storage method based on national cryptography algorithms. Background Art
[0002] With the continuous acceleration of the digitalization process, electronic contracts, as an important form replacing traditional paper contracts, have been widely used in many fields such as e-commerce, financial services, and enterprise management. Electronic contracts have the advantages of high efficiency, convenience, and easy filing and retrieval, but they also face key security challenges such as the risk of data tampering, leakage of sensitive information, and difficulty in access control. To address the above problems, current technical paths generally adopt methods such as file encryption, digital signature, access control, and segmented management to achieve the confidentiality and integrity protection of electronic contracts. However, existing solutions mostly process contract data in ways such as overall encryption and fixed segmentation, lacking a differential processing mechanism based on content complexity and structural characteristics, and it is difficult to balance access efficiency and system scalability while ensuring the security of sensitive data. Especially in the scenarios of large-scale electronic contract filing and retrieval, their security and refined management capabilities are still insufficient.
[0003] CN114239038A discloses an electronic contract data encryption management system, and its core technical path is: after physically splitting the electronic contract file to be encrypted, setting access permissions for each part, uniformly encapsulating them into a digital envelope, and then the encryption software executes the encryption process, and embeds the generated encryption key into the digital envelope for centralized management. This method introduces the idea of regionalized confidentiality management, enabling different permission subjects to only access the corresponding content in the contract, thus alleviating the risk of information leakage to a certain extent. However, this technology does not deeply analyze the content structure of electronic contracts, does not consider the heterogeneous characteristics brought by content complexity and hierarchical nesting, its cutting strategy is only physical segmentation, lacking logical breakpoint control and semantic association indexing, and it is difficult to meet the security and manageability requirements of high-sensitivity contracts in slice granularity control and access path construction.
[0004] CN112948882A proposes an electronic contract encryption method, device, and storage medium, mainly by obtaining the contract signing time and using a time encryption algorithm to generate a unique time identifier, and embedding it into the contract, thereby improving the uniqueness and anti-tampering ability of electronic contracts. This scheme takes the signing time as the core encryption factor, and can indeed achieve the non-repudiation of the contract signing behavior and the uniqueness of the time identifier. However, its focus is mainly on the encryption of the signing behavior rather than the structural security of the contract content itself. For the protection of sensitive clauses and hierarchical nested parts in the contract content, this scheme does not provide targeted processing methods and cannot handle the differentiated confidentiality requirements inside the contract document and the multi-department collaborative management scenario. Summary of the Invention
[0005] In view of the problems existing in the existing electronic contract encryption and management technologies in dealing with the heterogeneity of contract content structures, the present invention is proposed.
[0006] Therefore, the problem to be solved by the present invention is how to improve the structure recognition ability, encryption flexibility and access controllability of electronic contracts during the encryption storage process.
[0007] To solve the above technical problems, the present invention provides the following technical solutions: In a first aspect, the present invention provides an electronic contract encryption storage method based on the national cryptographic algorithm, which includes obtaining target electronic contract data, extracting complexity feature vectors based on the contract content structure, including the number of sensitive entities, nesting levels, and the distribution density of key clauses, and calculating slice granularity parameters according to the complexity feature vectors; performing structure slicing on the target electronic contract data according to the slice granularity parameters, combining the logical breakpoint splitting with the in-contract chained structure transfer node index to generate a contract slice sequence; generating slice metadata for each of the contract slice sequences, and selecting a differentiated national cryptographic algorithm parameter group according to the complexity feature vectors, and performing independent encryption on each contract slice; binding and encapsulating the encrypted contract slices with the corresponding slice metadata into slice archive units, and constructing an archive index table based on the transfer node index and paragraph path information.
[0008] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the extraction of the complexity feature vectors includes: decomposing the target electronic contract data into a semantic unit group according to structure tags, and obtaining a set of sensitive entities for each semantic unit; calculating the nesting level value of each semantic unit, the nesting level value being based on the node depth of the semantic unit in the XML or JSON representation, and adjusting it to a weighted nesting level in combination with the number of field references to the upper-layer semantic unit; calculating the key clause density sequence for the semantic unit group, where the key clause density sequence is the number of key constraint phrases contained within the unit character count, and constructing a clause density vector based on the key clause density of each semantic unit as the contract key content distribution feature; combining the count of sensitive entities, weighted nesting level, and key clause density in sequence into a complexity feature vector.
[0009] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the calculation of the slice granularity parameters includes: constructing a global feature matrix based on the complexity feature vectors of all semantic units, calculating the variance of each complexity feature vector according to the global feature matrix, and generating slice granularity parameters with the average variance.
[0010] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the structural slicing process of the target electronic contract data includes: organizing the semantic unit group into a structural sequence, and setting the initial slicing window width based on the slicing granularity parameter; in the structural sequence, sliding the slicing window backward sequentially from the starting position, and performing local change rate analysis on the weighted nesting level and key clause density of the semantic units in each slicing window, and dynamically adjusting the slicing boundary position; defining the structural slice group according to each slicing boundary position.
[0011] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the logical breakpoint splitting includes: for each structural slice, constructing a field reference graph based on the reference relationship between internal fields, extracting the strongly connected subgraph forming a closed jump loop therein, defining it as a chained structure transfer graph, and extracting the field pairs that are jump paths to each other as the logical transfer index set; further refining the structural slice into contract slices according to the logical transfer index set, and recording the logical source and destination fields for each contract slice.
[0012] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the selection of the differentiated national cryptographic algorithm parameter group and the independent encryption of each contract slice include: generating a unique number for each contract slice, and combining it with the starting offset position in the electronic contract text and the belonging structural slice group to form a paragraph path for identifying the paragraph position, and integrating it into the slice metadata set; classifying the complexity of the contract slice according to the determination rule based on the number of sensitive entities and the weighted nesting level; calling the encryption policy mapping table based on the contract slice complexity classification, retrieving the corresponding national cryptographic algorithm parameter group, and performing independent encryption processing on the contract slice to generate ciphertext slices.
[0013] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the national cryptographic algorithm parameter group includes the predefined encryption parameter configurations in SM4, SM2 or SM9.
[0014] As a preferred solution of the electronic contract encryption storage method based on the national cryptographic algorithm of the present invention, wherein: the construction of the archive index table includes: encapsulating to form a slice archive unit according to each ciphertext slice and the corresponding slice metadata; extracting the paragraph path and transfer node index in each slice metadata to construct the fragment position information, and forming an archive mapping pair with the slice archive unit; constructing the archive index table according to the order of the archive mapping pairs and the belonging transfer node index.
[0015] In a second aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program instructions are executed by the processor, the steps of the electronic contract encryption storage method based on the national cryptography algorithm as described in the first aspect of the present invention are implemented.
[0016] In a third aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program instructions are executed by the processor, the steps of the electronic contract encryption storage method based on the national cryptography algorithm as described in the first aspect of the present invention are implemented.
[0017] The beneficial effects of the present invention are as follows: The present invention adaptively adjusts the slicing granularity based on the structural and semantic features of the contract, and performs precise slicing through logical breakpoints, significantly improving the information granularity processing ability while ensuring the logical integrity of the contract, which is beneficial for subsequent permission management and data access; by applying different national cryptography algorithm parameters to each contract slice for independent encryption processing, the anti-attack ability and confidentiality level of the overall data are enhanced, avoiding the risk of information leakage under a single-point breakthrough of the traditional contract encryption method; at the same time, by adopting the mechanism of binding the archiving unit and constructing the index table, efficient retrieval and decryption operations can be realized without exposing the plaintext content. In summary, the present invention significantly improves the structural recognition ability, encryption flexibility, and access controllability of electronic contracts during the encryption storage process. Description of the Drawings
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 It is a flowchart of the electronic contract encryption storage method based on the national cryptography algorithm; Figure 2 It is a flowchart of performing independent encryption on each contract slice in the electronic contract encryption storage method based on the national cryptography algorithm. Detailed Embodiments
[0020] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will give a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification.
[0021] Many specific details are set forth in the following description to facilitate a thorough understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0022] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure or characteristic that may be included in at least one implementation manner of the present invention. The phrase "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it an individual or alternative embodiment that is mutually exclusive with other embodiments.
[0023] As mentioned in the above background art, the current technical path generally adopts methods such as file encryption, digital signature, permission control and segmented management to achieve the confidentiality and integrity protection of electronic contracts. However, existing solutions mostly process contract data in ways such as overall encryption and fixed segmentation, lacking a differential processing mechanism based on content complexity and structural characteristics, and it is difficult to balance access efficiency and system scalability while ensuring the security of sensitive data. Especially in the scenarios of large-scale electronic contract archiving and retrieval, their security and refined management capabilities are still insufficient.
[0024] Figure 1 It is a flowchart of an electronic contract encryption storage method based on the national cryptographic algorithm according to an embodiment of the present invention. As Figure 1 shown, in the electronic contract encryption storage method based on the national cryptographic algorithm, it includes: S1: Obtain the target electronic contract data, extract the complexity feature vector based on the contract content structure, including the number of sensitive entities, nesting levels and the distribution density of key clauses, and calculate the slice granularity parameter according to the complexity feature vector.
[0025] Among them, the complexity feature vector includes the number of sensitive entities , nesting levels and the distribution density of key clauses .
[0026] In the solution of the present invention, the API method is preferably used to select the contract text with complete structure annotation from the electronic contract storage warehouse to ensure the accuracy and stability of subsequent semantic unit extraction and feature vector construction. In addition, to ensure the consistency of data processing, the present invention will perform operations such as unifying the encoding format of contract data, clearing redundant characters, etc. in the data preprocessing stage, and perform structure conversion on the contract text in unstructured format.
[0027] In the embodiment of the present invention, step S1 specifically includes: S1.1: Decompose the target electronic contract data into a semantic unit group according to the structure label, and obtain the set of sensitive entities for each semantic unit.
[0028] Specifically, first, through the structure label (such as <clause> 、 <section>, group the contract semantically according to clauses, liabilities, obligations, etc. into multiple semantic unit groups, where each semantic unit represents a clause or sentence segment with independent meaning.
[0029] S1.2: Calculate the nested level value of each semantic unit. The nested level value is based on the node depth of the semantic unit in the XML or JSON representation and adjusted to a weighted nested level in combination with the number of field references to the upper-level semantic unit.
[0030] Among them, the nested level value refers to the position depth of the semantic unit in the entire contract semantic tree.
[0031] However, the complexity of the contract structure is not only determined by the level depth. Many clauses, although at relatively shallow nodes, have a high actual complexity because they are called across layers multiple times (for example, a general clause is cited in multiple sub-clauses). Therefore, the present invention proposes a weighted nested level index to correct the original level value.
[0032] S1.3: Calculate the critical clause density sequence for the semantic unit group. Among them, the critical clause density sequence is the number of critical constraint phrases contained within the number of characters per unit, and a clause density vector is constructed based on the critical clause density of each semantic unit as the distribution feature of the key content of the contract.
[0033] Among them, when calculating the critical clause density, the text of each semantic unit is scanned to count the number of critical phrases that appear, and then divided by the total number of characters in the paragraph to obtain the constraint language density per unit character. For example, a clause containing 500 characters with 10 critical phrases appears, and the calculated density is 0.02. The densities of all semantic units are arranged in order to form a vector, which is called the clause density vector.
[0034] S1.4: Combine the count of sensitive entities, weighted nested level, and critical clause density in order to form a complexity feature vector.
[0035] It should be noted that this combination method is scalable, allowing new complexity dimensions (such as reference chain length, responsibility overlap degree, etc.) to be added in the future without destroying the existing structure.
[0036] S1.5: Construct a global feature matrix based on the complexity feature vectors of all semantic units, and calculate the variance of each complexity feature vector according to the global feature matrix to generate a slice granularity parameter with the average variance.
[0037] Specifically, the global feature matrix refers to a matrix formed by vertically stacking the complexity feature vectors of all semantic units. Subsequently, the variance of each column (i.e., each feature dimension) of the global feature matrix is calculated to evaluate the volatility in the entire contract. Finally, the arithmetic mean is taken as the final slice granularity parameter.
[0038] The role of the slice granularity parameter is to determine how many semantic units each slice should cover in subsequent content slicing. If the value of the slice granularity parameter is high, it indicates that the complexity of the contract content fluctuates greatly, and a finer-grained slicing strategy needs to be adopted to ensure content continuity; if the value of the slice granularity parameter is low, it means that the contract structure is relatively uniform, and a coarser-grained slice can be appropriately adopted to improve processing efficiency. The present invention proposes this dynamic parameter adjustment mechanism, which solves the problems of fixed granularity and poor adaptability of traditional contract segmentation methods, making the contract slicing more in line with the semantic and structural characteristics of the content.
[0039] S2: Perform structural slicing on the target electronic contract data according to the slice granularity parameter, and perform logical breakpoint splitting in combination with the in-contract chained structure transfer node index to generate a contract slice sequence.
[0040] S2.1: The structural slicing process of the target electronic contract data includes the following operation steps: First, organize the semantic unit group into a structural sequence, and set the initial slice window width based on the slice granularity parameter.
[0041] If the value of the granularity parameter is large, a smaller window should be selected for finer slicing; if the granularity parameter is small, a larger window can be used to avoid semantic fragmentation caused by excessive slicing. Compared with the fixed window strategy, this method can adapt to the structural characteristics of contracts with different complexities, thereby improving the accuracy and applicability of slicing.
[0042] Secondly, in the structural sequence, slide the slice window backward sequentially from the starting position, and perform local change rate analysis on the weighted nesting level and key clause density of the semantic units in each slice window, dynamically adjust the slice boundary position, and delimit the structural slice group according to each slice boundary position.
[0043] Specifically, for each sliding window, calculate the local change rate of the weighted nesting level and key clause density of the semantic units therein. Among them, the local change rate can be calculated in the form of local standard deviation, sliding difference or first derivative (this embodiment is not limited to a single form), which is used to reflect whether there is an obvious change in the semantic structure within the window. For example, in an area where clauses are concentrated, if the change in key clause density is drastic, the window boundary should be adjusted to make it a separate slice.
[0044] Such a local adjustment process helps to ensure that the semantics within each structural slice is continuous and the boundaries are clear.
[0045] Next, based on the above dynamic analysis results, clarify the boundary positions of each structural slice and delimit the structural slice group. During the process of structure delimitation, it is necessary to ensure that the slice boundaries do not damage the integrity of semantic units, that is, each structural slice should contain complete semantic units without cross-unit truncation. In addition, it is necessary to record the start and end indexes of each structural slice in the structure sequence for subsequent logical breakpoint slicing.
[0046] This structural slicing mechanism jointly driven by granularity parameters and local structure fluctuations has stronger adaptability and accuracy compared with the traditional fixed slicing methods by chapter and by section, and is particularly suitable for the processing scenarios of electronic contract data with long texts and many complex nested structures.
[0047] S2.2: The logical breakpoint slicing includes the following operation steps: First, for each structural slice, construct a field reference graph based on the reference relationships between internal fields, extract the strongly connected subgraphs that form closed jump loops in it, define them as chained structure transfer graphs, and extract the field pairs that are mutual jump paths as the logical transfer index set.
[0048] It should be noted that the purpose of this step is to identify the logical jumps and field reference paths in the structural slice, further refine the slice boundaries, so that each contract slice is not only semantically complete but also has the logical closed-loop ability when processed independently.
[0049] For this purpose, first, a field reference graph needs to be constructed for each structural slice. Among them, the field reference graph refers to a directed graph established based on the reference relationships between fields within the structural slice. Each node represents a field, and the edge represents the reference or dependence between fields (for example, "the payment amount in this article should be the same as the amount shown in Article 4" is a kind of reference). The method for constructing the field reference graph is as follows: traverse the field expressions in all semantic units in the structural slice, identify the keywords of the reference relationship (such as see, according to, as above, etc.), and match the reference field position and the target field index through natural language processing technology to form a graph structure.
[0050] Furthermore, in the embodiment of the present invention, a strongly connected subgraph refers to that any two nodes in the graph are reachable by paths, indicating that there is a mutual reference or logical loop jump link between fields, which is a key manifestation of the logical coherence of the contract. By identifying these subgraphs, it can be judged which field groups must be included in the same contract slice to maintain logical coherence, thereby serving as the basis for further refining the slice.
[0051] Secondly, further refine the structural slice into contract slices according to the logical transfer index set, and record the logical source and destination fields for each contract slice.
[0052] Specifically, during the refinement process, the slice boundaries are redefined according to the field path indicated by the logical transfer index set to ensure that all fields that are jump paths to each other are concentrated in the same slice to avoid logical disconnection. Compared with the traditional pure structure segmentation method, the logical breakpoint segmentation strategy of the present invention has stronger logical consistency and processing flexibility, and is particularly suitable for application scenarios such as intelligent compliance review, automatic archiving indexing and comparison of multiple versions of contracts.
[0053] S3: Generate slice metadata for each contract slice sequence, select differentiated national encryption algorithm parameter groups based on the complexity feature vector, and perform independent encryption on each contract slice.
[0054] In the embodiment of the present invention, a differentiated national encryption algorithm parameter group is selected, such as Figure 2 As shown, performing independent encryption on each contract slice includes: Step 1: Generate a unique number for each contract slice, and combine it according to the starting offset position in the electronic contract text and the structural slice group to which it belongs to form a paragraph path for identifying the paragraph position, and integrate it into a slice metadata set.
[0055] Step 2: Based on the number of sensitive entities and the weighted nesting level, the contract slice complexity classification is divided according to the judgment rules, and the encryption strategy mapping table is called based on the contract slice complexity classification, the corresponding national secret algorithm parameter group is retrieved, and the contract slice is independently encrypted to generate a ciphertext slice. Among them, the national secret algorithm parameter group includes the encryption parameter configuration predefined in SM4, SM2 or SM9.
[0056] Furthermore, in the embodiment of the present invention, the determination rules include: For each contract slice, the sensitive terms involved are first annotated and processed, and the distribution characteristics in the text paragraphs are counted to determine whether they appear in a specific sentence cluster or are interspersed and scattered; at the same time, combined with the structural position of the contract slice, the syntactic nesting depth is analyzed, that is, whether it contains nested clause references, conditional restrictions or multi-level expressions. If the sensitive fields in the contract slice are densely distributed in multiple semantic fragments and the nesting depth presents a non-linear progression, it is determined that the contract slice has the dual characteristics of high information concentration and complex expression; if the sensitive fields are not concentrated, but the structural nesting path is significantly deepened, or the fields are dense but the structure is linearly expanded, it is classified as a state of coexistence of semantic expansion and security risks; if the above two types of features are not significant, and the field distribution is relatively simple and the structure is shallow, it is considered that the contract slice presents the attributes of low structural embedding and low semantic risk.
[0057] Exemplarily, according to the statement nesting depth, sensitive field density, and spatial distribution entropy of sensitive fields of each contract slice, its discreteness is measured through a weighted and normalized value range, and the contract slices are divided into three categories: high-complexity slices, medium-complexity slices, and low-complexity slices.
[0058] After the above judgments are completed, corresponding complexity identifiers are assigned to each contract slice. Among them, high-complexity slices will call the national cryptography algorithm combination that supports multi-level keys and hybrid symmetric and asymmetric encryption (such as SM4+SM2), medium-complexity slices adopt the standard SM4 key strategy, and low-complexity slices use a streamlined SM4 parameter group with less resource overhead, etc. The above are only examples and need to be set according to the actual situation.
[0059] According to the above mapping strategy, the national cryptography algorithm encryption operation is independently performed on each contract slice, and the encrypted ciphertext, the selected algorithm parameter group number, and the slice metadata are integrated into the final encrypted slice package. This package will be used as the basic unit for subsequent storage, retrieval, and transmission.
[0060] Through the above multi-dimensional feature extraction and mapping mechanism, the present invention realizes the differential protection of the security of electronic contract content, effectively balances the contradiction between encryption intensity and computing overhead, and improves the refined security management ability of contract data in a multi-terminal and multi-role environment.
[0061] S4: Bind and encapsulate the encrypted contract slice with the corresponding slice metadata into a slice archiving unit, and construct an archiving index table according to the transfer node index and paragraph path information.
[0062] S4.1: According to each ciphertext slice and the corresponding slice metadata, encapsulate to form a slice archiving unit.
[0063] In the specific encapsulation operation, the unique number, the starting offset value of the original position, and the paragraph path associated with the current ciphertext slice are preferentially extracted from the slice metadata set. The paragraph path, as a key field for structure positioning, usually consists of the structure slice group identification code, the contract paragraph number, and the subsection number, ensuring that even when the contract structure is dynamically adjusted or different contract versions are compared horizontally, the consistency of the original positioning semantics can still be retained. On this basis, the slice metadata and the ciphertext content are packaged through a unified data encapsulation protocol to generate a formatted archiving unit object. This object will be used as the smallest operation unit for subsequent index construction and remote migration, and its encapsulation format supports fast unpacking and lightweight field access, improving the overall archiving performance.
[0064] S4.2: Extract the paragraph path and transfer node index in each slice metadata to construct the fragment position information, and form an archiving mapping pair with the slice archiving unit.
[0065] It should be noted that the construction logic of the archiving index table follows the principle of emphasizing both semantic adjacency and transmission controllability: First, extract the semantic fragment positions according to the paragraph path information recorded in the archiving unit, and determine the logical paragraphs or clause groups to which they belong; Second, determine the boundary division and ownership nodes of each slice in future data migration and cross-platform calls based on the transfer node index generated by the contract structure parser. For example, if the ownership node index of a ciphertext slice is TX_03, it means it belongs to the contract module restricted by the 3rd type of migration strategy rule.
[0066] The construction of the archiving mapping pair is to jointly bind each slice archiving unit with the extracted paragraph path and transfer node index to form a complete location information identification structure. Such mapping pairs are usually stored in the form of key-value pairs in the physical structure, where the key is a composite field, such as "paragraph path # transfer node index", and the value is the corresponding slice archiving unit object. In this way, each ciphertext slice has the ability to be quickly indexed, reversely located, and migrated across modules in the archiving system, significantly enhancing the controllability and traceability capabilities in subsequent encrypted contract circulation, access auditing, and distributed parsing processes.
[0067] S4.3: Construct the archiving index table according to the order of the archiving mapping pairs and the belonging transfer node index.
[0068] After all mapping pairs are constructed, these mapping pairs will be sorted according to the logical paragraph order and the belonging weight of the transfer nodes, and finally a structured archiving index table will be generated. This index table records the archiving path, confidentiality level label, content complexity identification, and decryption interface pointer required for invocation of each slice in the form of an ordered structure, ensuring that even in heterogeneous platforms or chained storage environments, the key information paragraphs of the contract can be quickly located, and the secure release of the smallest accessible fragment can be completed according to the principle of least privilege.
[0069] This embodiment also provides a computer device applicable to the case of the electronic contract encryption storage method based on the national secret algorithm, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the electronic contract encryption storage method based on the national secret algorithm as proposed in the above embodiment.
[0070] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or may be a button, a trackball, or a touchpad provided on the housing of the computer device, or may also be an external keyboard, touchpad, or mouse, etc.
[0071] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for encrypting and storing an electronic contract based on the national cryptography algorithm as proposed in the above embodiment.
[0072] In summary, the present invention adaptively adjusts the slice granularity based on the structural and semantic characteristics of the contract, and performs precise segmentation through logical breakpoints, significantly improving the information granularity processing ability while ensuring the logical integrity of the contract, which is beneficial to subsequent permission management and data access; by applying different national cryptography algorithm parameters to each contract slice for independent encryption processing, the anti-attack ability and confidentiality level of the overall data are enhanced, and the risk of information leakage under a single-point breakthrough in the traditional contract encryption method is avoided; at the same time, by adopting the mechanism of binding the archiving unit and constructing the index table, efficient retrieval and decryption operations can be realized without exposing the plaintext content. In summary, the present invention significantly improves the structural recognition ability, encryption flexibility, and access controllability of electronic contracts during the encryption storage process.
[0073] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.< / section> < / clause>
Claims
1. An electronic contract encryption storage method based on national cryptographic algorithms, characterized in that: Including: Obtain target electronic contract data, extract a complexity feature vector based on the contract content structure, including the number of sensitive entities, the nesting level, and the distribution density of key terms, and calculate a slice granularity parameter according to the complexity feature vector; Perform a structural slicing process on the target electronic contract data according to the slice granularity parameter, combine the logical breakpoint splitting by the transfer node index in the contract internal chain structure, and generate a contract slice sequence; Generate slice metadata for each of the contract slice sequences respectively, and select a differentiated national cryptographic algorithm parameter group according to the complexity feature vector, and perform independent encryption on each contract slice; Bind and package the encrypted contract slices with the corresponding slice metadata into a slice archiving unit, and construct an archiving index table according to the transfer node index and paragraph path information.
2. The method for encrypting and storing electronic contracts based on the national cryptographic algorithm according to claim 1, wherein: The extraction of the complexity feature vector includes: Decompose the target electronic contract data into a semantic unit group according to the structure tag, and obtain a set of sensitive entities for each semantic unit; Calculate the nesting level value of each semantic unit, where the nesting level value is based on the node depth of the semantic unit in the XML or JSON representation, and is adjusted to a weighted nesting level in combination with the number of field references to the upper-level semantic unit; Calculate the key term density sequence for the semantic unit group, where the key term density sequence is the number of key constraint phrases contained within the number of characters per unit, and construct a term density vector according to the key term density of each semantic unit as the distribution feature of the key content of the contract; Combine the count of sensitive entities, the weighted nesting level, and the key term density in sequence into a complexity feature vector.
3. The method for encrypting and storing an electronic contract based on the national cryptographic algorithm according to claim 2, wherein: The calculation of the slice granularity parameter includes: Construct a global feature matrix based on the complexity feature vectors of all semantic units, calculate the variance of each complexity feature vector according to the global feature matrix, and generate a slice granularity parameter with the average variance.
4. The method for encrypting and storing electronic contracts based on the national cryptographic algorithm according to claim 1, wherein: The structural slicing process on the target electronic contract data includes: Organize the semantic unit group into a structure sequence, and set the initial slice window width according to the slice granularity parameter; In the structure sequence, slide the slice window backward sequentially from the starting position, and perform a local change rate analysis on the weighted nesting level and key term density of the semantic units in each slice window, and dynamically adjust the slice boundary position; Define a structure slice group according to each slice boundary position.
5. The method for encrypting and storing electronic contracts based on the national cryptographic algorithm according to claim 4, wherein: The logical breakpoint splitting includes: For each structure slice, construct a field reference graph based on the reference relationship between internal fields, extract the strongly connected subgraph that forms a closed jump loop therein, define it as a chain structure transfer graph, and extract the field pairs that are mutual jump paths as a logical transfer index set; Further refine the structure slice into a contract slice according to the logical transfer index set, and record the logical source and destination fields for each contract slice.
6. The method for encrypting and storing electronic contracts based on national cryptographic algorithms according to claim 1, characterized in that: The selection of a differentiated national cryptographic algorithm parameter group and the performance of independent encryption on each contract slice includes: Generate a unique number for each contract slice, and combine it according to the starting offset position in the electronic contract text and the belonging structure slice group to form a paragraph path for identifying the paragraph position, and integrate it into a slice metadata set; Based on the number of sensitive entities and the weighted nesting level, classify the complexity of the contract slice according to the determination rule; Based on the complexity classification of contract slices, call the encryption policy mapping table, retrieve the corresponding national cryptography algorithm parameter group, perform independent encryption processing on the contract slices, and generate ciphertext slices.
7. The method for encrypting and storing an electronic contract based on the national cryptographic algorithm according to claim 6, wherein: The national cryptography algorithm parameter group includes predefined encryption parameter configurations in SM4, SM2, or SM9.
8. The electronic contract encryption storage method based on the national secret algorithm according to claim 1, characterized in that: The construction of the archive index table includes: According to each ciphertext slice and the corresponding slice metadata, encapsulate to form a slice archive unit; Extract the paragraph path and transfer node index in each slice metadata to construct fragment position information, and form an archive mapping pair with the slice archive unit; Construct an archive index table according to the order of the archive mapping pairs and the belonging transfer node index.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the national cryptography algorithm-based electronic contract encryption and storage method described in any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the national cryptography algorithm-based electronic contract encryption and storage method described in any one of claims 1 to 8.
Citation Information
Patent Citations
Loan contract online signing system based on block chain
CN114792270A
Electronic contract content intelligent encryption method based on sequence decomposition
CN116032476A
SIMD instruction-oriented SM4 fine-grained slice optimization method and system
CN117272337A
Supply chain security risk identification method and system
CN118427829A
METHOD FOR AUTOMATICALLY GENERATING ELECTRONIC CONTRACT WITH VARIABLE TERMS IN B-to-C E-COMMERCE TRADE
US20140052575A1
Cited By
Encrypted data transmission method and system
CN120880814A