An electronic contract encryption storage method based on national secret algorithm

Through the electronic contract encryption method based on the Guomi algorithm, the slice particle size is dynamically adjusted and logical breakpoint segmentation is combined to realize differentiated encryption processing of electronic contracts, improving the security and access efficiency of electronic contracts, and solving the problem of insufficient security and scalability in the existing technology.

CN120354437BActive Publication Date: 2025-08-22JIANGSU SMART DIGITAL CERTIFICATION CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510864373.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-08-22
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

The existing electronic contract encryption technology lacks a differentiated processing mechanism based on content complexity and structural characteristics, and it is difficult to ensure the security of sensitive data while taking into account access efficiency and system scalability. Especially in large-scale electronic contract archiving and review scenarios, security and refined management capabilities are insufficient.

Method used

Based on the Guomi algorithm, by extracting the complexity feature vector of electronic contracts, dynamically adjusting the slice particle size, and combining logical breakpoints to slice to generate a slice sequence. Differentiated Guomi algorithm parameters are used to perform independent encryption on each slice, and an archive index table is constructed to achieve efficient retrieval and decryption.

Benefits of technology

It improves the structural recognition capability, encryption flexibility and access controllability of electronic contracts in the encrypted storage process, enhances the anti-attack ability and confidentiality level, and ensures logical integrity and information granularity processing capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354437B_ABST
    Figure CN120354437B_ABST
Patent Text Reader

Abstract

The present invention discloses an electronic contract encryption storage method based on a national secret algorithm, and relates to the technical field of contract encryption storage. The method comprises extracting a complexity feature vector based on the structure of the contract content, and calculating a slice granularity parameter based on the complexity feature vector; performing structural slicing processing on the target electronic contract data based on the slice granularity parameter, performing logical breakpoint segmentation in combination with the chain structure transfer node index within the contract, and generating a contract slice sequence; generating slice metadata for the contract slice sequence, and selecting a differentiated national secret algorithm parameter group based on the complexity feature vector, and performing independent encryption on each contract slice; binding and encapsulating the encrypted contract slice with the corresponding slice metadata into a slice archiving unit, and constructing an archiving index table based on the transfer node index and paragraph path information. The present invention significantly improves the structural recognition capability, encryption flexibility, and access controllability of electronic contracts during the encrypted storage process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of contract encryption storage, and in particular to an electronic contract encryption storage method based on a national secret algorithm. Background Art

[0002] With the continuous acceleration of the digitalization process, electronic contracts, as an important form of replacing traditional paper contracts, have been widely used in many fields such as e-commerce, financial services, and corporate management. Electronic contracts have the advantages of high efficiency, convenience, and easy archiving and retrieval, but they also face key security challenges such as the risk of data tampering, leakage of sensitive information, and difficulty in access control. In response to the above problems, current technical paths generally use file encryption, digital signatures, permission control, and segmented management to achieve confidentiality and integrity protection of electronic contracts. However, existing solutions mostly process contract data through overall encryption and fixed segmentation, lacking differentiated processing mechanisms based on content complexity and structural characteristics. It is difficult to balance access efficiency and system scalability while ensuring the security of sensitive data. Especially in large-scale electronic contract archiving and retrieval scenarios, its security and refined management capabilities are still insufficient.

[0003] CN114239038A discloses an electronic contract data encryption management system, the core technology of which is: after physically dividing the electronic contract file to be encrypted, setting access rights for each part and uniformly encapsulating them into a digital envelope, the encryption software then executes the encryption process and embeds the generated encryption key into the digital envelope for centralized management. This method introduces a regionalized confidentiality management approach, so that different authorized entities can only access the corresponding content in the contract, thereby alleviating the risk of information leakage to a certain extent. However, this technology does not conduct an in-depth analysis of the content structure of the electronic contract, and does not consider the heterogeneous characteristics brought about by the complexity of the content and the hierarchical nesting. Its cutting strategy is only physical segmentation, lacking logical breakpoint control and semantic association indexing, making it difficult to meet the security and manageability requirements of highly sensitive contracts in terms of slice granularity control and access path construction.

[0004] CN112948882A proposes an electronic contract encryption method, device, and storage medium. This method primarily obtains the contract signing time and uses a time encryption algorithm to generate a unique time identifier, which is then embedded in the contract, thereby improving the uniqueness and tamper-proofing of the electronic contract. This solution uses the signing time as the core encryption factor, and can indeed achieve non-repudiation and time uniqueness of the contract signing behavior, but its focus is primarily on the encryption of the signing behavior rather than the structural security of the contract content itself. This solution does not provide a targeted approach to protecting sensitive clauses and hierarchically nested sections within the contract content, and is unable to address the differentiated confidentiality requirements within the contract document and multi-department collaborative management scenarios. Summary of the Invention

[0005] In view of the problems existing in existing electronic contract encryption and management technologies in dealing with the heterogeneity of contract content structure, the present invention is proposed.

[0006] Therefore, the problem to be solved by the present invention is how to improve the structural recognition capability, encryption flexibility and access controllability of electronic contracts during the encryption storage process.

[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0008] In the first aspect, the present invention provides an electronic contract encryption and storage method based on a national secret algorithm, which includes obtaining target electronic contract data, extracting a complexity feature vector based on the contract content structure, including the number of sensitive entities, nesting levels, and key clause distribution density, and calculating a slice granularity parameter based on the complexity feature vector; performing structural slicing processing on the target electronic contract data according to the slice granularity parameter, performing logical breakpoint segmentation in combination with the chain structure transfer node index within the contract, and generating a contract slice sequence; generating slice metadata for the contract slice sequence, and selecting a differentiated national secret algorithm parameter group based on the complexity feature vector, and performing independent encryption on each contract slice; binding and encapsulating the encrypted contract slice with the corresponding slice metadata into a slice archiving unit, and constructing an archiving index table based on the transfer node index and paragraph path information.

[0009] As a preferred solution of the electronic contract encryption and storage method based on the national secret algorithm described in the present invention, the extraction of the complexity feature vector includes: decomposing the target electronic contract data into semantic unit groups according to the structural label, and taking a sensitive entity set for each semantic unit; calculating the nesting level value of each semantic unit, the nesting level value is based on the node depth of the semantic unit in the XML or JSON representation, and is adjusted to a weighted nesting level in combination with the number of field references to the upper-level semantic unit; calculating the key clause density sequence for the semantic unit group, wherein the key clause density sequence is the number of key constraint phrases contained in a unit number of characters, and constructing a clause density vector according to the key clause density of each semantic unit as a key content distribution feature of the contract; and sequentially combining the count of sensitive entities, the weighted nesting level and the key clause density into a complexity feature vector.

[0010] As a preferred solution of the electronic contract encryption storage method based on the national secret algorithm described in the present invention, the calculation of the slice granularity parameter includes: constructing a global feature matrix based on the complexity feature vectors of all semantic units, calculating the variance of each complexity feature vector according to the global feature matrix, and generating the slice granularity parameter by averaging the variance.

[0011] As a preferred solution of the electronic contract encryption and storage method based on the national secret algorithm described in the present invention, the structural slicing processing of the target electronic contract data includes: organizing the semantic unit group into a structural sequence, and setting the initial slice window width based on the slice granularity parameter; in the structural sequence, sliding the slice window backward from the starting position in sequence, and performing local change rate analysis on the weighted nesting level and key clause density of the semantic unit in each slice window, and dynamically adjusting the slice boundary position; delineating the structural slice group according to the boundary position of each slice.

[0012] As a preferred solution of the electronic contract encryption storage method based on the national secret algorithm described in the present invention, the logical breakpoint segmentation includes: for each structure slice, constructing a field reference graph based on the reference relationship between internal fields, extracting a strongly connected subgraph forming a closed jump loop, defining it as a chain structure transfer graph, and extracting field pairs that are jump paths to each other as a logical transfer index set; further refining the structure slice into contract slices according to the logical transfer index set, and recording the logical source and destination fields for each contract slice.

[0013] As a preferred solution of the electronic contract encryption and storage method based on the national secret algorithm described in the present invention, the method comprises: selecting a differentiated national secret algorithm parameter group and performing independent encryption on each contract slice, including: generating a unique number for each contract slice, and combining it according to the starting offset position and the structural slice group to which it belongs in the electronic contract text to form a paragraph path for identifying the paragraph position, and integrating it into a slice metadata data set; dividing the complexity classification of the contract slices according to the judgment rules based on the number of sensitive entities and the weighted nesting level; calling the encryption strategy mapping table based on the complexity classification of the contract slices, retrieving the corresponding national secret algorithm parameter group, performing independent encryption processing on the contract slices, and generating ciphertext slices.

[0014] As a preferred solution of the electronic contract encryption storage method based on the national secret algorithm described in the present invention, wherein: the national secret algorithm parameter group includes the encryption parameter configuration predefined in SM4, SM2 or SM9.

[0015] As a preferred solution of the electronic contract encryption storage method based on the national secret algorithm described in the present invention, the construction of the archiving index table includes: encapsulating each ciphertext slice and the corresponding slice metadata to form a slice archiving unit; extracting the paragraph path and transfer node index in each slice metadata to construct the fragment location information, and forming an archiving mapping pair with the slice archiving unit; constructing the archiving index table according to the order of the archiving mapping pairs and the transfer node index to which they belong.

[0016] In a second aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, the steps of the electronic contract encryption storage method based on the national secret algorithm as described in the first aspect of the present invention are implemented.

[0017] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, the steps of the electronic contract encryption storage method based on the national secret algorithm as described in the first aspect of the present invention are implemented.

[0018] The beneficial effects of the present invention are as follows: the present invention adaptively adjusts the slice granularity based on the structural characteristics and semantic characteristics of the contract, and performs precise segmentation through logical breakpoints, ensuring the logical integrity of the contract while greatly improving the information granularity processing capability, which is beneficial to subsequent authority management and data retrieval; by applying differentiated national secret algorithm parameters to each contract slice for independent encryption processing, the overall data's anti-attack capability and confidentiality level are enhanced, avoiding the risk of information leakage under a single-point breakthrough in traditional contract encryption methods; at the same time, the archiving unit binding and index table construction mechanism is adopted to achieve efficient retrieval and decryption operations without exposing the plaintext content. In summary, the present invention significantly improves the structural recognition capability, encryption flexibility, and access controllability of electronic contracts during the encrypted storage process. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0020] Figure 1 This is a flowchart of the electronic contract encryption storage method based on the national secret algorithm;

[0021] Figure 2 This is a flowchart for performing independent encryption on each contract slice in the electronic contract encryption storage method based on the national secret algorithm. DETAILED DESCRIPTION

[0022] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0023] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0024] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0025] As mentioned in the background technology above, current technologies generally employ methods such as file encryption, digital signatures, permission control, and segmented management to protect the confidentiality and integrity of electronic contracts. However, existing solutions often process contract data through methods such as overall encryption and fixed segmentation. These methods lack differentiated processing mechanisms based on content complexity and structural characteristics, making it difficult to balance access efficiency and system scalability while ensuring the security of sensitive data. This is particularly true for large-scale electronic contract archiving and retrieval scenarios, where security and refined management capabilities remain insufficient.

[0026] Figure 1 FIG is a flowchart of a method for encrypting and storing electronic contracts based on a national secret algorithm according to an embodiment of the present invention. Figure 1 As shown, the electronic contract encryption storage method based on the national secret algorithm includes:

[0027] S1: Obtain the target electronic contract data, extract the complexity feature vector based on the contract content structure, including the number of sensitive entities, nesting levels, and distribution density of key clauses, and calculate the slice granularity parameter based on the complexity feature vector.

[0028] Among them, the complexity feature vector includes the number of sensitive entities , nested levels and key terms distribution density .

[0029] In this solution, the API is preferentially used to select fully structurally annotated contract texts from the electronic contract repository to ensure the accuracy and stability of subsequent semantic unit extraction and feature vector construction. Furthermore, to ensure consistent data processing, the present invention performs operations such as standardizing the contract data encoding format, removing redundant characters, and performing structural conversion on unstructured contract texts during the data preprocessing phase.

[0030] In this embodiment of the present invention, step S1 specifically includes:

[0031] S1.1: Decompose the target electronic contract data into semantic unit groups according to the structural tags, and obtain the sensitive entity set for each semantic unit.

[0032] Specifically, first pass the structure tag (such as <clause> 、 <section>, clauses, responsibilities and obligations, etc.) to semantically group the contract into multiple semantic unit groups, where each semantic unit represents a clause or sentence with independent meaning.

[0033] S1.2: Calculate the nesting level value of each semantic unit. The nesting level value is based on the node depth of the semantic unit in the XML or JSON representation, and is adjusted to a weighted nesting level based on the number of field references to the upper semantic unit.

[0034] The nesting level value refers to the depth of the semantic unit in the entire contract semantic tree.

[0035] However, the complexity of a contract structure isn't solely determined by the depth of the hierarchy. Many clauses, though located at shallower levels, can also exhibit high actual complexity due to their multiple cross-layer references (e.g., a general clause referenced in multiple specific clauses). To address this, this paper proposes a weighted nested hierarchy index to modify the original hierarchy value.

[0036] S1.3: Calculate the key clause density sequence for the semantic unit group, where the key clause density sequence is the number of key constraint phrases contained in a unit character number, and construct a clause density vector based on the key clause density of each semantic unit as the distribution feature of the key content of the contract.

[0037] When calculating key clause density, each semantic unit text is scanned, the number of key phrases appearing is counted, and the result is divided by the total number of characters in the paragraph to obtain the constraint density per character. For example, a 500-character clause with 10 key phrases would have a calculated density of 0.02. All semantic unit densities are sequentially organized into a vector, which is called the clause density vector.

[0038] S1.4: Combine the counts of sensitive entities, weighted nesting levels, and key term densities sequentially into a complexity feature vector.

[0039] It is worth noting that this combination method is extensible, allowing new complexity dimensions (such as reference chain length, responsibility overlap, etc.) to be added in the future without destroying the existing structure.

[0040] S1.5: Construct a global feature matrix based on the complexity feature vectors of all semantic units, calculate the variance of each complexity feature vector based on the global feature matrix, and generate the slice granularity parameter by averaging the variance.

[0041] Specifically, the global feature matrix is ​​formed by stacking the complexity feature vectors of all semantic units vertically. The variance of each column (i.e., each feature dimension) of the global feature matrix is ​​then calculated to assess volatility across the entire contract. The arithmetic mean is then taken as the final slicing granularity parameter.

[0042] The role of the slice granularity parameter is to determine how many semantic units each slice should cover in subsequent content fragmentation. If the slice granularity parameter value is high, it means that the complexity of the contract content fluctuates greatly, and a finer-grained slicing strategy is needed to ensure content continuity; if the slice granularity parameter value is low, it means that the contract structure is relatively uniform, and coarse-grained slicing can be appropriately adopted to improve processing efficiency. The present invention proposes this dynamic parameter adjustment mechanism to solve the problems of fixed granularity and poor adaptability of traditional contract segmentation methods, making contract slices more consistent with the semantics and structural characteristics of the content.

[0043] S2: Structural slicing is performed on the target electronic contract data according to the slicing granularity parameters, and logical breakpoint segmentation is performed in combination with the chain structure transfer node index within the contract to generate a contract slice sequence.

[0044] S2.1: Structural slicing of the target electronic contract data includes the following steps:

[0045] First, the semantic unit groups are organized into structure sequences, and the initial slicing window width is set based on the slicing granularity parameter.

[0046] If the granularity parameter value is large, a smaller window should be selected for finer segmentation; if the granularity parameter is small, a larger window can be used to avoid over-segmentation and semantic fragmentation. Compared to a fixed window strategy, this method can adapt to the structural characteristics of contracts of different complexity, thereby improving the accuracy and applicability of slicing.

[0047] Secondly, in the structural sequence, the slice window is slid backward from the starting position in sequence, and the weighted nesting level and key term density of the semantic unit in each slice window are analyzed for local change rate, the slice boundary position is dynamically adjusted, and the structural slice group is delineated according to the boundary position of each slice.

[0048] Specifically, for each sliding window, the local rate of change of the weighted nesting level of semantic units and the density of key terms is calculated. This local rate of change can be calculated using the local standard deviation, sliding difference, or first-order derivative (not limited to this in this embodiment), reflecting whether the semantic structure within the window has undergone significant changes. For example, if the density of key terms changes dramatically in an area where terms are clustered, the window boundaries should be adjusted to separate them into separate slices.

[0049] Such a local adjustment process helps to ensure that the internal semantics of each structural slice are continuous and the boundaries are clear.

[0050] Next, based on the dynamic analysis results, the boundaries of each structural slice are determined and structural slice groups are delineated. During the structural delineation process, it is necessary to ensure that the slice boundaries do not destroy the integrity of the semantic units. That is, each structural slice should contain a complete semantic unit, without cross-unit truncation. In addition, the starting and ending indexes of each structural slice in the structural sequence must be recorded to facilitate subsequent logical breakpoint segmentation.

[0051] This structural slicing mechanism, which is driven by both granularity parameters and local structural fluctuations, has stronger adaptability and accuracy than the traditional fixed segmentation method by chapter or paragraph. It is particularly suitable for electronic contract data processing scenarios with long texts and complex nested structures.

[0052] S2.2: Logical breakpoint segmentation includes the following steps:

[0053] First, for each structure slice, a field reference graph is constructed based on the reference relationship between internal fields, and a strongly connected subgraph forming a closed jump loop is extracted, defined as a chain structure transfer graph, and field pairs that are jump paths to each other are extracted as a logical transfer index set.

[0054] It should be noted that this step aims to identify logical jumps and field reference paths in structural slices, further refine the slice boundaries, and make each contract slice not only semantically complete but also capable of logical closure when processed independently.

[0055] To do this, we first need to construct a field reference graph for each structure slice. A field reference graph is a directed graph built within a structure slice based on the reference relationships between fields. Each node represents a field, and edges represent references or dependencies between fields (for example, "The payment amount in this article should be consistent with the amount shown in Article 4" is a reference). The method for constructing the field reference graph is to traverse the field expressions in all semantic units in the structure slice, identify keywords for the reference relationship (such as "see," "based on," and "as above"), and use natural language processing techniques to match the reference field locations with the target field indexes, thereby forming a graph structure.

[0056] Furthermore, in this embodiment of the present invention, a strongly connected subgraph refers to a graph in which any two nodes are reachable by a path, indicating the presence of jump links between fields that reference each other or form logical loops. This is a key indicator of contract logical coherence. By identifying these subgraphs, it is possible to determine which groups of fields must be included in the same contract slice to maintain logical coherence, thus providing a basis for further slice refinement.

[0057] Secondly, the structural slices are further refined into contract slices based on the logical transfer index set, and the logical source and destination fields are recorded for each contract slice.

[0058] Specifically, during the refinement process, slice boundaries are redefined based on the field paths indicated by the logical transition index set, ensuring that all fields that serve as jump paths to each other are concentrated in the same slice, avoiding logical disconnects. Compared to traditional purely structural segmentation methods, the proposed logical breakpoint segmentation strategy offers greater logical consistency and processing flexibility, making it particularly suitable for applications such as intelligent compliance review, automatic archiving indexing, and multi-version contract comparison.

[0059] S3: Generate slice metadata for each contract slice sequence, select differentiated national encryption algorithm parameter groups based on the complexity feature vector, and perform independent encryption on each contract slice.

[0060] In the embodiment of the present invention, a differentiated national encryption algorithm parameter group is selected, such as Figure 2 As shown, performing independent encryption on each contract slice includes:

[0061] Step 1: Generate a unique number for each contract slice, and combine it according to the starting offset position in the electronic contract text and the structural slice group to which it belongs to form a paragraph path for identifying the paragraph position, and integrate it into a slice metadata set.

[0062] Step 2: Based on the number of sensitive entities and the weighted nesting level, the contract slice complexity classification is divided according to the judgment rules. Based on the contract slice complexity classification, the encryption strategy mapping table is called to retrieve the corresponding national secret algorithm parameter group, and independent encryption processing is performed on the contract slice to generate a ciphertext slice. Among them, the national secret algorithm parameter group includes the encryption parameter configuration predefined in SM4, SM2, or SM9.

[0063] Furthermore, in an embodiment of the present invention, the determination rules include:

[0064] For each contract slice, the sensitive terms involved are first annotated and their distribution characteristics in the text paragraphs are counted to determine whether they appear concentrated in specific sentence clusters or are interspersed and scattered. At the same time, combined with the structural position of the contract slice, the syntactic nesting depth is analyzed, that is, whether it contains nested clause references, conditional restrictions, or multi-level expressions. If the sensitive fields in the contract slice are densely distributed in multiple semantic fragments and the nesting depth presents a nonlinear progression, then the contract slice is judged to have the dual characteristics of high information concentration and complex expression. If the sensitive fields are not concentrated, but the structural nesting path is significantly deepened, or the fields are relatively dense but the structure is linearly expanded, then it is classified as a state of coexistence of semantic expansion and security risks. If neither of the above two types of characteristics is significant, and the field distribution is relatively simple and the structure is shallow, then the contract slice is considered to have the attributes of low structural embedding and low semantic risk.

[0065] For example, according to the statement nesting depth, sensitive field density and spatial distribution entropy of sensitive fields of each contract slice, its discreteness is measured through the weighted normalized value range, and the contract slices are divided into three categories: high complexity slices, medium complexity slices and low complexity slices.

[0066] After completing the above judgment, a corresponding complexity identifier is assigned to each contract slice. High-complexity slices will call a combination of national encryption algorithms that support multi-level keys, mixed symmetric and asymmetric encryption (such as SM4+SM2). Medium-complexity slices use the standard SM4 key strategy, while low-complexity slices use a streamlined SM4 parameter group with less resource overhead. The above is only an example and needs to be set according to actual conditions.

[0067] Based on the above mapping strategy, the national secret algorithm encryption operation is independently performed on each contract slice, and the encrypted ciphertext, the selected algorithm parameter group number, and the slice metadata are integrated into the final encrypted slice package. This package will serve as the basic unit for subsequent storage, retrieval, and transmission.

[0068] Through the above-mentioned multi-dimensional feature extraction and mapping mechanism, the present invention realizes differentiated security protection of electronic contract content, effectively balances the contradiction between encryption strength and computational overhead, and improves the refined security management capability of contract data in a multi-terminal, multi-role environment.

[0069] S4: Bind and encapsulate the encrypted contract slice and the corresponding slice metadata into a slice archiving unit, and build an archiving index table based on the transfer node index and paragraph path information.

[0070] S4.1: Based on each ciphertext slice and the corresponding slice metadata, encapsulate to form a slice archiving unit.

[0071] During the specific encapsulation operation, the unique number, original position starting offset value, and paragraph path associated with the current ciphertext slice will be extracted from the slice metadata dataset first. As a key field for structural positioning, the paragraph path is usually composed of the structural slice group identification code, the contract paragraph number, and the subsection number. This ensures that even when the contract structure is dynamically adjusted or different contract versions are compared horizontally, the consistency of the original positioning semantics can be retained. On this basis, the slice metadata and ciphertext content are packaged and processed through a unified data encapsulation protocol to generate a formatted archiving unit object. This object will serve as the minimum operation unit for subsequent index construction and remote migration. Its encapsulation format supports fast unpacking and lightweight field access, improving overall archiving performance.

[0072] S4.2: Extract the paragraph path and transfer node index in each slice metadata to construct the fragment location information, and form an archive mapping pair with the slice archive unit.

[0073] It's important to note that the construction logic of the archive index table follows the principle of balancing semantic adjacency and transfer controllability: First, the semantic segment location is extracted based on the paragraph path information recorded in the archive unit, and the logical paragraph or clause group to which it belongs is determined. Second, the transfer node index generated by the contract structure parser is used to determine the boundary demarcation and home node of each slice during future data migration and cross-platform calls. For example, if the home node index of a ciphertext slice is TX_03, it means that it belongs to the contract module constrained by the third type of migration policy rules.

[0074] The construction of an archive mapping pair involves binding each slice archive unit to the extracted paragraph path and transition node index, forming a complete location information identification structure. Physically, such mapping pairs are typically stored as key-value pairs, where the key is a synthetic field (e.g., "paragraph path#transition node index") and the value is the corresponding slice archive unit object. This approach enables each ciphertext slice within the archive system to be rapidly indexed, reversibly located, and migrated across modules, significantly enhancing controllability and traceability during subsequent encrypted contract transfers, access audits, and distributed parsing.

[0075] S4.3: Construct an archive index table according to the order of the archive mapping pairs and the index of the transfer node to which they belong.

[0076] After all mapping pairs are constructed, they are sorted and organized according to the logical paragraph order and the transfer node's attribution weight, ultimately generating a structured archiving index table. This index table records each slice's archiving path, confidentiality level label, content complexity indicator, and the decryption interface pointer required for invocation in the form of an ordered structure. This ensures that even on heterogeneous platforms or chained storage environments, key contract information sections can be quickly located, and the minimum accessible fragment can be securely released based on the principle of least privilege.

[0077] This embodiment also provides a computer device, which is suitable for the electronic contract encryption storage method based on the national secret algorithm, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the electronic contract encryption storage method based on the national secret algorithm proposed in the above embodiment.

[0078] The computer device may be a terminal, comprising a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs. The internal memory provides an environment for the operating system and computer programs stored in the non-volatile storage media. The communication interface of the computer device is used to communicate with external terminals via wired or wireless communication. Wireless communication may be achieved via Wi-Fi, a carrier network, NFC (near-field communication), or other technologies. The display of the computer device may be a liquid crystal display or an electronic ink display. The input device may be a touchscreen overlay on the display, buttons, a trackball, or a touchpad on the computer device housing, or an external keyboard, touchpad, or mouse.

[0079] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the electronic contract encryption storage method based on the national secret algorithm proposed in the above embodiment is implemented.

[0080] In summary, the present invention adaptively adjusts the slice granularity based on the structural and semantic features of the contract, and performs precise segmentation through logical breakpoints, ensuring the logical integrity of the contract while greatly improving the information granularity processing capability, which is beneficial to subsequent authority management and data retrieval; by applying differentiated national secret algorithm parameters to each contract slice for independent encryption processing, the overall data's anti-attack capability and confidentiality level are enhanced, avoiding the risk of information leakage under a single-point breakthrough in traditional contract encryption methods; at the same time, the archiving unit binding and index table construction mechanism is adopted to achieve efficient retrieval and decryption operations without exposing the plaintext content. In summary, the present invention significantly improves the structural recognition capability, encryption flexibility, and access controllability of electronic contracts during the encrypted storage process.

[0081] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.< / section> < / clause>

Claims

1. A method for encrypting and storing electronic contracts based on a national secret algorithm, characterized by: include: Obtain target electronic contract data, extract complexity feature vectors based on the contract content structure, including the number of sensitive entities, nesting levels, and distribution density of key clauses, and calculate slicing granularity parameters based on the complexity feature vectors; Structural slicing of the target electronic contract data is performed according to the slicing granularity parameters, and logical breakpoint segmentation is performed in combination with the chain structure transfer node index within the contract to generate a contract slice sequence; Generate slice metadata for each contract slice sequence, select a differentiated national encryption algorithm parameter group based on the complexity feature vector, and perform independent encryption on each contract slice; Bind and encapsulate the encrypted contract slice and the corresponding slice metadata into a slice archiving unit, and build an archiving index table based on the transfer node index and paragraph path information; Extracting the complexity feature vector includes: decomposing the target electronic contract data into semantic unit groups according to structural tags, and extracting a sensitive entity set for each semantic unit; calculating the nesting level value of each semantic unit, wherein the nesting level value is based on the node depth of the semantic unit in the XML or JSON representation and is adjusted to a weighted nesting level in combination with the number of field references to the upper semantic unit; calculating a key clause density sequence for the semantic unit group, wherein the key clause density sequence is the number of key constraint phrases contained in a unit number of characters, and constructing a clause density vector based on the key clause density of each semantic unit as a key content distribution feature of the contract; sequentially combining the count of sensitive entities, the weighted nesting level, and the key clause density into a complexity feature vector; performing structural slicing processing on the target electronic contract data includes: organizing the semantic unit group into a structural sequence and setting an initial slicing window width based on a slicing granularity parameter; sliding the slicing window backward from the starting position in the structural sequence, performing a local change rate analysis on the weighted nesting level and key clause density of the semantic unit in each slicing window, and dynamically adjusting the slicing boundary position; and delineating structural slicing groups based on the slicing boundary position.

2. The electronic contract encryption storage method based on the national secret algorithm according to claim 1 is characterized in that: The calculation of the slice granularity parameters includes: A global feature matrix is ​​constructed based on the complexity feature vectors of all semantic units. The variance of each complexity feature vector is calculated based on the global feature matrix, and the slice granularity parameter is generated by the average variance.

3. The electronic contract encryption storage method based on the national secret algorithm according to claim 2 is characterized in that: The logical breakpoint segmentation includes: For each structure slice, a field reference graph is constructed based on the reference relationship between internal fields. Strongly connected subgraphs that form closed jump loops are extracted and defined as chain structure transfer graphs. Field pairs that are jump paths to each other are extracted as logical transfer index sets. The structure slices are further refined into contract slices based on the logical transfer index set, and the logical source and destination fields are recorded for each contract slice.

4. The electronic contract encryption storage method based on the national secret algorithm according to claim 1 is characterized in that: The selection of a differentiated national encryption algorithm parameter group and the independent encryption of each contract slice include: Generate a unique number for each contract slice, and combine it according to the starting offset position in the electronic contract text and the structural slice group to which it belongs to form a paragraph path for identifying the paragraph position, and integrate it into a slice metadata set; Based on the number of sensitive entities and weighted nesting levels, the contract slice complexity classification is divided according to the judgment rules; Based on the complexity classification of the contract slice, the encryption strategy mapping table is called to retrieve the corresponding national encryption algorithm parameter group, and independent encryption processing is performed on the contract slice to generate a ciphertext slice.

5. The electronic contract encryption storage method based on the national secret algorithm according to claim 4 is characterized in that: The national secret algorithm parameter group includes the encryption parameter configuration predefined in SM4, SM2 or SM9.

6. The electronic contract encryption storage method based on the national secret algorithm according to claim 1 is characterized in that: The construction of the archiving index table includes: According to each ciphertext slice and the corresponding slice metadata, a slice archiving unit is encapsulated; Extract the paragraph path and transfer node index in each slice metadata to construct segment location information, and form an archive mapping pair with the slice archive unit; An archiving index table is constructed according to the order of the archiving mapping pairs and the corresponding transfer node indexes.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the electronic contract encryption storage method based on the national secret algorithm described in any one of claims 1 to 6 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the electronic contract encryption storage method based on the national secret algorithm described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Electronic contract encryption method and device and storage medium

    CN112948882A

  • Electronic contract content intelligent encryption method based on sequence decomposition

    CN116032476A

  • SIMD instruction-oriented SM4 fine-grained slice optimization method and system

    CN117272337A