Intelligent seal safety control method and system based on hybrid cloud

Through the intelligent seal security control method based on hybrid cloud, the compatibility, security and high operation and maintenance costs of traditional seal management are solved, and the full process digital closed-loop management and traceable printing records are realized, improving the safety and efficiency of enterprise printing.

CN120474757AInactive Publication Date: 2025-08-12HUANENG NANJING GAS TURBINE POWER GENERATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510573430.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional seal management methods cannot meet the needs of modern enterprises for safe, efficient and compliant printing. They have problems such as poor system compatibility, insufficient security protection, high operation and maintenance costs, and single biometric technology. Especially in the take-out printing scenarios, there is a risk of misappropriation and difficult to trace responsibility.

Method used

The intelligent seal security control method based on hybrid cloud is adopted, and multi-level approval is carried out by obtaining the application information for printing, safe transmission of instructions by using hybrid cloud platform, biometric information is collected for verification, combined with intelligent file comparison and video recording, electronic ledgers are generated, and the entire process digital closed-loop management is realized.

Benefits of technology

It realizes the digital closed-loop and safety control of seal management, improves the safety and operational efficiency of printing, meets the control capabilities and internal control requirements of full-scene printing and signing, and provides a traceable operation record throughout the process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474757A_ABST
    Figure CN120474757A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of enterprise seal management, in particular to an intelligent seal safety control method and system based on hybrid cloud. The method comprises the following steps: acquiring seal application information; performing multi-level approval on the application information; the approval result is sent to the seal terminal in the form of a security instruction through the hybrid cloud platform; biological characteristic information of an operator is collected and verified; performing intelligent comparison on the files to be printed to confirm the consistency; the seal unlocking equipment executes seal operation; and collecting sealing video data and generating an electronic standing book. According to the invention, secure connection of the internal and external networks is realized through the hybrid cloud architecture, identity cheating is prevented by adopting dual biological feature verification, file tampering is prevented by utilizing OCR intelligent comparison, visual recording and tracing of the whole stamping process are realized, and a complete exception handling mechanism is designed. According to the system, the safety, compliance and operation efficiency of seal management are remarkably improved, and the system is particularly suitable for seal using scene requirements in the digital transformation process of modern enterprises.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of enterprise seal management, and in particular to a hybrid cloud-based intelligent seal security management and control method and system. Background Art

[0002] As enterprises advance their digital transformation, traditional seal management methods are no longer able to meet the demands of modern businesses for secure, efficient, and compliant seal use. Traditional seal-use processes primarily rely on paper-based signature approvals, lacking electronic approval and full-process traceability, making it difficult to achieve digital closed-loop management. This is especially true for off-site seal use, where seal supervision is insufficient, posing significant risks such as theft and fraudulent use. Furthermore, the lack of video and electronic evidence during traditional seal use makes it difficult to define responsibility and hinders subsequent tracing.

[0003] While existing intelligent printing control systems have seen some improvements, they still face numerous issues. First, the system suffers from poor compatibility, with most systems consisting of modular devices requiring dedicated printing control consoles for use, making them unsuitable for mobile office or on-the-go scenarios. Second, security measures are insufficient, lacking hybrid cloud-based secure command transmission capabilities and posing the security risk of man-in-the-middle attacks. Third, operational and maintenance costs are high, with modular devices requiring frequent component replacements, implicitly increasing maintenance costs for businesses. Furthermore, the existing system utilizes a single biometric recognition technology with low accuracy, making it susceptible to fraud by forged biometric features, increasing security risks associated with seal use. Summary of the Invention

[0004] In view of the problems existing in the prior art, the present invention is proposed.

[0005] Therefore, the problem to be solved by the present invention is how to solve the following technical problems:

[0006] Achieve digital closed-loop management of the entire seal-using process, including approval, stamping, and evidence storage, to meet the internal control needs of modern enterprises;

[0007] Provides full-scenario printing and signature management capabilities, covering various printing scenarios such as fixed, mobile, and takeaway;

[0008] A hybrid cloud architecture enables secure data storage and remote instruction transmission, resolving system security issues.

[0009] Improve seal security by adopting intranet remote commands and multiple biometric collection to prevent illegal use;

[0010] Provide video recording and electronic ledger functions for the entire stamping process to meet internal control and audit requirements and achieve full traceability of stamping behavior;

[0011] Optimize the abnormal situation handling mechanism to improve system stability and reliability.

[0012] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0013] In a first aspect, an embodiment of the present invention provides a hybrid cloud-based smart seal security management and control method, which includes obtaining seal application information, wherein the seal application information includes applicant information, application document information, and seal type;

[0014] Conduct multi-level approval on the seal application information and generate a seal approval result;

[0015] The seal approval result is sent to the seal terminal device in the form of a security instruction through the hybrid cloud platform;

[0016] Collect the biometric information of the operator using the seal and compare and verify it with the preset biometric database;

[0017] After the biometric verification is passed, the document to be used for stamping is intelligently compared to confirm the consistency of the document;

[0018] Unlock the seal terminal device and perform the stamping operation;

[0019] Video data of the stamping process is collected, an electronic ledger is generated, and the video data and the electronic ledger are archived and stored through a hybrid cloud platform.

[0020] As a preferred solution of the hybrid cloud-based smart seal security management and control method of the present invention, wherein: the biometric information includes: fingerprint feature information and facial feature information;

[0021] The biometric verification is performed through a preset feature matching algorithm, including detail feature point extraction and a three-level comparison mechanism.

[0022] As a preferred solution of the hybrid cloud-based smart seal security management method of the present invention, the multi-level approval of seal application information includes:

[0023] Generate file hash values to ensure file integrity; conduct automatic preliminary review through the intranet management platform; assign approval process routes based on preset rules; perform multi-level manual approval; and generate security instructions after approval.

[0024] As a preferred solution of the hybrid cloud-based smart seal security management and control method of the present invention, the hybrid cloud platform includes:

[0025] Intranet management server, used to process seal applications, approvals and document archiving; secure intranet boundary, including firewalls and security isolation devices; hybrid cloud management platform, including private cloud and public cloud cache areas; secure transmission Internet channel, used for encrypted command transmission.

[0026] As a preferred solution of the hybrid cloud-based smart seal security management method of the present invention, wherein: sending the seal approval result in the form of a security instruction to the seal terminal device through the hybrid cloud platform includes:

[0027] Perform quantum encryption on security instructions; transmit instructions through VPN secure channel; the seal terminal receives instructions through 4G / Wi-Fi communication module; the seal terminal decrypts and verifies the instructions.

[0028] As a preferred solution of the hybrid cloud-based smart seal security management method of the present invention, the intelligent comparison of the seal documents includes:

[0029] Use OCR technology to identify the title and content of the document to be printed; compare the recognition result with the document information in the application form;

[0030] When the recognition result is inconsistent with the application information, an alarm message is issued; when the recognition result is consistent with the application information, the stamping operation is allowed to continue.

[0031] As a preferred solution of the hybrid cloud-based smart seal security management method of the present invention, the video data of the stamping process is collected, including:

[0032] The entire stamping process is recorded in real time through a built-in high-definition camera; the video data is locally encrypted and stored;

[0033] The encrypted video data is uploaded to the intranet server through a secure link; the video data is automatically associated with the seal usage record to form an electronic ledger.

[0034] As a preferred solution of the hybrid cloud-based smart seal security management and control method of the present invention, it also includes an abnormal situation handling process:

[0035] When biometric verification fails continuously for more than a preset number of times, a security lock is triggered; when the approval process times out, an upgrade mechanism or a backup approval chain is activated; when network transmission is interrupted, it automatically switches to a local secure storage area and caches whitelist instructions; when device hardware fails, a fault code is generated and a maintenance work order is pushed.

[0036] In a second aspect, an embodiment of the present invention provides a hybrid cloud-based intelligent seal security management and control system, which includes an application processing module for obtaining seal application information, wherein the seal application information includes applicant information, application document information, and seal type;

[0037] An approval management module is used to perform multi-level approval on the seal application information and generate a seal approval result;

[0038] An instruction transmission module is used to send the seal approval result in the form of a security instruction to the seal terminal device through the hybrid cloud platform;

[0039] Identity verification module, used to collect the biometric information of the operator using the seal and compare and verify it with the preset biometric database;

[0040] The document comparison module is used to perform intelligent comparison of the stamped documents to confirm the consistency of the documents after the biometric verification is passed;

[0041] The seal control module is used to unlock the seal terminal device and perform the stamping operation;

[0042] The data recording module is used to collect video data of the stamping process, generate an electronic ledger, and archive and store the video data and the electronic ledger through a hybrid cloud platform.

[0043] The embodiment of the present invention provides a hybrid cloud-based smart seal security management and control system, which includes a terminal layer, including a smart seal device, wherein the smart seal device includes a biometric module, a high-definition camera, an automatic ink supply device, and a communication module;

[0044] The platform layer includes a hybrid cloud management platform, which is composed of public and private clouds and is used to achieve secure communication between the intranet and the intranet;

[0045] The application layer, including the mobile app and PC management backend, is used to provide functions such as seal application, approval, query and statistics;

[0046] Secure transport layer, including VPN tunnel and encryption transmission mechanism, to ensure the secure transmission of seal instructions and data;

[0047] The terminal layer exchanges data with the platform layer through the secure transport layer, and the application layer implements remote control and management of the seal device through the platform layer.

[0048] The beneficial effects of the present invention are as follows: the hybrid cloud-based intelligent seal security management and control method and system of the present invention realizes the digital closed loop and safe control of seal management. From the technical architecture level, the innovative hybrid cloud design is adopted to deploy the approval process in the intranet to ensure data security, and at the same time, a reliable connection with the external network seal equipment is achieved through a secure channel, overcoming the limitations of the single scenario of the traditional system. In terms of identity authentication, through the multimodal fusion recognition of biometric features such as fingerprints and faces, prosthesis deception and unauthorized use are effectively prevented. In terms of business processes, the entire process of seal use is digitally controlled, from application submission, multi-level approval, intelligent file comparison, safe seal use to full-process video evidence storage, forming a complete operation record chain, eliminating management blind spots. In terms of data security, AES-256 encryption and blockchain technology are used to ensure the security of data storage and transmission, ensuring that electronic evidence cannot be tampered with. In terms of operation and maintenance guarantee, the perfect exception handling mechanism and disaster recovery backup strategy ensure the stable operation of the system 7×24 hours a day, and the fault recovery time (RTO) is controlled within 15 minutes. Compared with the existing technology, this invention significantly improves the security, compliance and operational efficiency of seal management, and provides all-round technical support for corporate seal management. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0050] Figure 1 This is a flow chart of the hybrid cloud-based smart seal security management and control method;

[0051] Figure 2 A diagram of computer equipment for a hybrid cloud-based smart seal security management and control method;

[0052] Figure 3 This is a system deployment diagram of the hybrid cloud-based smart seal security management method. DETAILED DESCRIPTION

[0053] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0054] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0055] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it constitute a separate or selective embodiment that is mutually exclusive with other embodiments.

[0056] Example 1

[0057] Reference Figures 1 and 2 , which is the first embodiment of the present invention, provides a hybrid cloud-based smart seal security management and control method, including:

[0058] S100: Acquire seal application information, which includes applicant information, application document information, and seal type; perform multi-level approval on the seal application information and generate a seal approval result;

[0059] S200: The seal approval result is sent to the seal terminal device in the form of a secure instruction through the hybrid cloud platform;

[0060] S300: collecting the biometric information of the operator using the seal and comparing it with the preset biometric database for verification;

[0061] S400: After the biometric verification is passed, the document to be used for stamping is intelligently compared to confirm the consistency of the document;

[0062] S500: Unlock the stamp terminal device and perform the stamping operation;

[0063] S600: Collect video data of the stamping process, generate an electronic ledger, and archive and store the video data and electronic ledger through the hybrid cloud platform.

[0064] Traditional corporate seal management faces multiple security risks and efficiency challenges. First, the approval process for corporate seals is lengthy, and paper approvals are easily lost and untraceable, resulting in a lack of effective oversight of the use of seals for important documents. Second, the lack of real-time monitoring and verification mechanisms for seals used outside of the company creates a high risk of seal theft, fraudulent use, and application to unauthorized documents. Third, the lack of comprehensive record keeping during the seal use process makes it difficult to identify responsible parties and operational procedures in the event of a dispute. Fourth, existing modular seal control equipment suffers from high maintenance costs, poor compatibility, and limited cross-platform and cross-scenario adaptability. Fifth, traditional seal control systems are often limited to corporate intranet use and cannot support the secure use of seals in remote working environments. They also lack secure transmission and storage mechanisms based on hybrid cloud architectures. Finally, seal terminal devices have limited security protection mechanisms and biometric recognition technology lacks accuracy, posing the risk of fraudulent signatures. Therefore, a comprehensive, intelligent seal security management system based on a hybrid cloud architecture, equipped with multiple security verification capabilities and comprehensive record keeping, is urgently needed to achieve standardized, digitized, and traceable management of corporate seal use.

[0065] The hybrid cloud-based smart seal security management and control method proposed in claim 1 builds a complete closed-loop seal management system by integrating the approval process, identity authentication, file comparison and operation records. This method first obtains complete seal application information to achieve comprehensive records of seal use activities; with the help of a multi-level approval process, it ensures that seal use activities are compliant and orderly; uses a hybrid cloud platform to securely transmit instructions, which not only ensures the security of intranet data but also meets the needs of taking seals out; accurately identifies the identity of operators through multi-dimensional biometric comparison and verification; combines file intelligent comparison technology to prevent file tampering or replacement; records the entire process of stamping videos and generates electronic ledgers to achieve traceability afterwards. This method not only solves the security risks in traditional seal management, but also improves the efficiency of seal use. At the same time, it realizes flexible deployment and full-scenario adaptation through a hybrid cloud architecture, effectively meeting the core needs of modern enterprises for digital, secure and standardized seal management.

[0066] Example 2

[0067] Reference Figure 1-Figure 3 , which is the second embodiment of the present invention.

[0068] In the embodiment of the present application, in step S100, the seal application information is subject to multi-level approval to generate a seal approval result, including the following steps A1-A5:

[0069] A1: Multi-level approval of seal application information includes:

[0070] Generate file hash values to ensure file integrity; conduct automatic preliminary review through the intranet management platform; assign approval process routes based on preset rules; perform multi-level manual approval; and generate security instructions after approval.

[0071] A1: Generates a file hash value to ensure file integrity;

[0072] In an optional implementation, file hash values can be generated using the SHA-256 algorithm, which performs a digital digest on the original file to generate a fixed-length hash value. The file hash value generation process first preprocesses the original file, dividing it into fixed-size data blocks. A cryptographic hash function is then used to calculate the hash value for each data block. These hash values are then concatenated to obtain the final file hash value. This process ensures that even minor changes to the file content will result in a significantly different final hash value, effectively preventing file tampering.

[0073] For example, the file hash value can be stored in the approval record as a basis for document integrity verification. When the stamping operation is executed, the system will recalculate the hash value of the document to be stamped and compare it with the hash value at the time of application to ensure that the document has not been modified.

[0074] It should be noted that generating a file hash value not only ensures the integrity of the file during transmission and storage, but also serves as a crucial component of the electronic evidence chain, contributing to the establishment of a comprehensive seal-use audit tracking system. In particular, when using seals for sensitive documents such as important contracts and financial vouchers, hash value verification can effectively prevent unauthorized file substitution.

[0075] A2: Automatic preliminary review through the intranet management platform;

[0076] Specifically, automated preliminary review checks include, but are not limited to, verification of applicant identity and permissions, checking the compatibility of application document type with the intended purpose, detecting anomalies in seal usage frequency, and identifying sensitive terms. The system generates a score for each check and, based on the overall score, determines whether the application passes preliminary review or is flagged for manual review.

[0077] For example, for routine applications for seals on internally circulated documents, a lower risk threshold can be set for automatic initial review; while for highly sensitive documents such as external contracts and financial vouchers, stricter review standards are set, and they are automatically transferred to the manual review process when necessary.

[0078] A3: Assign approval process routes based on preset rules;

[0079] In one optional implementation, the approval process is automatically generated based on a multi-dimensional decision matrix. Decision dimensions include, but are not limited to, factors such as document importance, seal type, application department, amount, and business type. Based on these factors, the system matches the most appropriate approval process, ensuring that the approval process meets organizational control requirements while maintaining reasonable approval efficiency.

[0080] Specifically, routing rules can use a combination of conditional branching and weighted calculations. For example, for contract documents, the system automatically categorizes approval levels based on the contract value: amounts below 100,000 yuan are directly approved by the department manager, amounts between 100,000 and 500,000 yuan require additional review by the finance department, and amounts above 500,000 yuan require approval from senior management. The system also dynamically adjusts approval paths based on factors such as document sensitivity and historical seal usage.

[0081] For example, for a purchase contract worth 500,000 yuan, the system will automatically generate a complete approval chain including the applicant's department head, the purchase department review, the legal department review, the finance department review, and the final approval by the company's vice president.

[0082] It should be noted that intelligent approval routing not only ensures the standardization and integrity of the approval process but also allows for flexible adjustments based on actual business needs, avoiding the efficiency losses associated with a one-size-fits-all approval model. Furthermore, by automatically assigning approval processes, the system reduces the potential for human intervention and enhances the objectivity and fairness of the approval process.

[0083] A4: Implement multi-level manual approval;

[0084] In an optional implementation, multi-level manual approval utilizes a hybrid model combining parallel and serial approval. For matters requiring co-signatures from multiple departments, the system simultaneously sends approval requests to the relevant reviewers, enabling parallel approval. For matters requiring progressive approval, approvals are advanced sequentially according to a pre-set approval sequence, ensuring rigorous approval.

[0085] Specifically, during the approval process, approvers can add comments, modify approval conditions, or request additional supporting documents. Each level of approval operation is recorded by the system, including approver information, operation time, approval comments, and operation behavior, forming a complete approval log. The system also provides approval reminders, timeout warnings, and expedited approvals to ensure a smooth approval process.

[0086] For example, in special emergency situations, the system also provides approval delegation and emergency approval channels. Approval delegation allows the approver to temporarily delegate approval authority to a designated agent while away from work; the emergency approval channel activates a fast-track approval process under specific conditions (such as major business opportunities or urgent needs from important customers), shortening approval time.

[0087] A5: A safety instruction will be generated after approval.

[0088] In an optional implementation, security instructions are generated using a combination of multi-layer encryption and digital signatures to ensure security and credibility. Security instructions contain core elements such as a seal authorization code, scope of operation permissions, validity window, designated executor information, and file signatures.

[0089] Specifically, the instruction generation process first serializes the approval result information, digitally signs it with an intranet private key, and then encrypts the entire instruction package using a quantum encryption algorithm. Each instruction has a unique identifier and is tied to a specific seal device and operator, preventing the instruction from being copied or replayed.

[0090] For example, a typical security instruction contains the following fields: instruction ID, initiation time, authorizer, executor, file hash value, operation type, seal ID, validity period, usage limit, digital signature, etc. This information is encrypted to form the final security instruction data package, which is securely transmitted to the target seal device via the hybrid cloud platform.

[0091] In another optional embodiment, step S100 may also include intelligent approval assistance features, such as automatic text analysis and risk warnings. The system intelligently scans and analyzes the application documents, identifying potentially risky clauses, non-standard wording, or content that is inconsistent with company policies. These are then highlighted within the approval interface to alert the approver to their particular attention. This assistance feature helps improve approval quality and reduce risks caused by human error.

[0092] In another optional implementation, step S100 can also integrate with the organization's business process management (BPM) system to achieve seamless integration of the approval process with the business process. For example, for a seal application for a procurement contract, the system can automatically link the historical records of the procurement approval process to verify that pre-approval has been completed. For a seal application for a financial voucher, the system can automatically link the relevant data in the financial system to ensure that the seal application is consistent with the financial records. This integration significantly improves cross-departmental collaboration efficiency and reduces duplicate review work.

[0093] In the embodiment of the present application, step S200 sends the seal approval result in the form of a security instruction to the seal terminal device through the hybrid cloud platform, including the following steps B1-B7:

[0094] B1: Hybrid cloud platform includes:

[0095] Intranet management server, used to process seal applications, approvals and document archiving; secure intranet boundary, including firewalls and security isolation devices; hybrid cloud management platform, including private cloud and public cloud cache areas; secure transmission Internet channel, used for encrypted command transmission.

[0096] Specifically, the intranet management server is responsible for four primary functions: seal application processing and form verification, approval process engine, security instruction generation, and electronic file management. The server regularly performs security scans and vulnerability checks to ensure system security. Furthermore, all operation logs utilize distributed storage and blockchain technology for tamper-proof recording, ensuring reliable audit traceability.

[0097] For example, the intranet management server can be deployed in the core area of the enterprise data center and maintain moderate integration with other business systems such as OA, ERP, etc., so as to share the necessary organizational structure and authority data while maintaining the independent security of the seal system.

[0098] It should be noted that the intranet management server, as the core of the entire seal management system, bears the important responsibilities of processing approval data, enforcing business rules, and implementing security policies. Its security and stability directly impact the reliable operation of the entire system, so a multi-layered security protection and disaster recovery mechanism is required to ensure its continuous availability.

[0099] B2: Sending the seal approval results to the seal terminal device in the form of a secure instruction through the hybrid cloud platform includes:

[0100] Perform quantum encryption on security instructions; transmit instructions through VPN secure channel; the seal terminal receives instructions through 4G / Wi-Fi communication module; the seal terminal decrypts and verifies the instructions.

[0101] B3: Hybrid cloud management platform design, including private cloud and public cloud cache areas;

[0102] In one alternative implementation, the hybrid cloud management platform adopts a "private core, public edge" architecture. Core data and critical business logic are deployed in the enterprise's private cloud, ensuring data sovereignty and business security. Non-sensitive data and edge computing tasks utilize public cloud resources, improving system scalability and availability.

[0103] Specifically, the private cloud utilizes containerization technology and a microservices architecture to achieve flexible resource allocation and high service availability. Core components such as data encryption, identity authentication, secure command management, and audit logging are deployed within the private cloud environment. The public cloud cache is primarily used for command storage, state synchronization, and non-sensitive data transfer. A regionalized deployment strategy is employed to ensure data transmission efficiency and compliance.

[0104] For example, in actual deployment, core functions such as seal instruction generation and user rights management can be deployed in a private cloud, while auxiliary functions such as device status monitoring and basic message push can be deployed on a public cloud. These two components exchange strictly controlled data through a secure API gateway, ensuring that core business data is not exposed to the public network.

[0105] It should be noted that the hybrid cloud platform provides a balance of flexibility and security for seal management systems. By rationally demarcating the responsibilities of private and public clouds, it can fully leverage the infrastructure advantages and global coverage of public clouds while ensuring the security and controllability of critical business data and core logic. This makes it particularly suitable for large enterprises with extensive geographical distribution.

[0106] B4: Secure transmission Internet channel design for encrypted instruction transmission;

[0107] In an optional implementation, the secure transmission internet channel utilizes a multi-layered secure communication mechanism. At the transport layer, TLS 1.3 is used to establish an encrypted channel to ensure confidentiality. At the application layer, two-way authentication and message-level encryption are implemented to ensure end-to-end data security. At the session layer, one-time tokens and session verification are introduced to prevent replay attacks and session hijacking.

[0108] Specifically, the secure transmission process first establishes a trusted connection through certificate authentication, then uses the Diffie-Hellman key exchange algorithm to generate a session key. The transmitted content is then encrypted using AES-256-GCM, and finally, an HMAC message authentication code is added to ensure data integrity. This entire process forms a complete cryptographic protection chain, ensuring that data cannot be eavesdropped or tampered with during transmission.

[0109] For example, when transmitting seal instructions, the system generates a unique transmission identifier and timestamp for each instruction, which is then combined with the unique identifier of the receiving device to form a dedicated encrypted transmission channel. Even if the communication data is intercepted, the instruction content cannot be retrieved or used without the correct decryption key and identity authentication.

[0110] B5: Quantum encryption of security instructions;

[0111] In an alternative implementation, the quantum cryptography process utilizes quantum key distribution (QKD) technology combined with traditional encryption algorithms. First, a true random key is generated and shared via a quantum channel. This key is then used as a seed key to generate the actual encryption key through a key derivation function. Finally, these keys are used to perform multi-level encryption of secure instructions.

[0112] Specifically, the quantum encryption process includes three main steps: first, the instruction content is encrypted using AES-256; second, the ECC (elliptic curve cryptography) algorithm is used for digital signature to ensure the authenticity of the instruction source; finally, the entire encrypted instruction package is encrypted using a quantum key with a one-time pad (One-Time Pad) to provide information security level protection.

[0113] For example, in actual applications, for particularly important printing instructions (such as those involving major contracts or sensitive financial documents), the system will automatically increase the security level and enable the complete quantum encryption process; for general daily printing instructions, a simplified encryption scheme may be used to balance security requirements and system performance.

[0114] B6: Transmit instructions through VPN secure channel;

[0115] In one optional implementation, the VPN secure channel utilizes a hybrid mode combining IPSec and SSL VPN. IPSec VPN is used for secure connections between fixed locations, providing strong encryption protection at the network layer; SSL VPN is used for mobile device access, offering more flexible application-layer security access. These two VPN technologies work together to ensure secure access to the seal management system for all types of terminal devices.

[0116] Specifically, the VPN tunnel establishment process consists of three main phases: identity authentication, key negotiation, and security policy matching. Identity authentication utilizes a two-factor authentication mechanism combining digital certificates and device fingerprints. Key negotiation uses Perfect Forward Secrecy (PFS) technology to ensure that even if a session key is compromised, it will not affect the security of other communications. Security policies automatically adapt to the device type and network environment, optimizing encryption parameters and transmission performance.

[0117] For example, for fixed seal devices in corporate branches, the system will establish a normalized IPSec VPN channel to provide a stable and secure connection; while for mobile seal devices used outside, an on-demand SSL VPN will be used to activate the secure channel only when instructions need to be received or data needs to be uploaded, saving device energy consumption and reducing unnecessary network exposure.

[0118] B7: The seal terminal receives the instruction through the 4G / Wi-Fi communication module; the seal terminal decrypts and verifies the instruction.

[0119] Specifically, the 4G module uses a dedicated APN (Access Point Name) connection to establish a private network channel, avoiding the public internet. The Wi-Fi module uses the enterprise-grade security protocol (WPA3-Enterprise), supports 802.1X authentication, and connects to a RADIUS server, ensuring that only authorized devices can access the enterprise wireless network. Both connection methods are equipped with data encryption and transmission protection mechanisms to prevent communication from being eavesdropped or tampered with.

[0120] For example, when the seal device is used within the company, Wi-Fi is preferred to save data and increase transmission speed. When the device is used outside or the Wi-Fi signal is poor, it automatically switches to 4G network to ensure communication reliability. For particularly important seal instructions, the system transmits them simultaneously through both network channels to provide dual security.

[0121] It should be noted that decryption and verification after receiving the command is a key component of the seal terminal's security mechanism. The terminal first verifies the command's digital signature to confirm the legitimacy of the source; then checks the command's timestamp and serial number to prevent replay attacks; then verifies that the device ID in the command matches the local device to prevent cross-device use of the command; finally, decrypts the command content and performs format and integrity checks to ensure it has not been tampered with. Only commands that pass all verification steps are accepted and executed by the terminal.

[0122] In another optional embodiment, step S200 may also include a transmission quality assurance mechanism, such as segmented transmission and automatic retry. For larger instruction packets (such as complex instructions containing file signature data), the system will segment them into multiple data segments and append verification information to each segment. The receiving end recovers the complete instruction through verification and reassembly. If a transmission error is detected, the receiving end automatically requests retransmission of the corresponding segment, ensuring reliable instruction transmission even in unstable network environments.

[0123] In the embodiment of the present application, step S300 collects the biometric information of the operator using the seal and compares and verifies it with the preset biometric database, including the following steps C1-C2:

[0124] C1: Biometric information includes fingerprint information and facial feature information;

[0125] In an optional embodiment, biometric acquisition utilizes multimodal fusion technology to simultaneously acquire fingerprint and facial information, combined with time-series verification to ensure the subject is alive. Fingerprint acquisition utilizes a capacitive fingerprint sensor with adaptive gain control, automatically adjusting acquisition parameters based on finger wetness, ensuring high-quality fingerprint images in a variety of environmental conditions. Facial acquisition utilizes dual-light source technology, using both visible and infrared light sources, and multispectral imaging to improve acquisition quality and interference resistance.

[0126] Specifically, the fingerprint collection process consists of four steps: fingerprint pre-scanning, quality assessment, main collection, and post-processing. The pre-scanning stage quickly detects the presence of fingerprints and assesses their initial quality; the quality assessment stage calculates fingerprint clarity and integrity indicators; the main collection stage acquires a high-resolution fingerprint image; and the post-processing stage enhances and extracts features from the image to form a standardized fingerprint feature template.

[0127] The facial recognition process includes four steps: face detection, pose correction, illumination compensation, and feature extraction. Face detection uses a deep learning algorithm to quickly locate the face; pose correction achieves frontalization by locating key points; illumination compensation uses adaptive histogram equalization (CLAHE) technology to reduce the impact of lighting changes; and feature extraction uses a deep convolutional neural network to extract a 512-dimensional facial feature vector as the basis for identity verification.

[0128] For example, in actual applications, for the printing operation of important documents, the system will require the user to provide fingerprints of both thumbs and frontal facial information; while for general documents, it may only require a single-finger fingerprint and a simplified facial verification to balance security and convenience.

[0129] It should be noted that multimodal biometric collection significantly improves the security of identity verification, effectively preventing the risk of single-feature impersonation. Furthermore, quality control mechanisms during the collection process ensure the reliability of feature data, reduce the impact of environmental factors on verification accuracy, and provide high-quality foundational data for subsequent feature comparisons.

[0130] C2: Biometric verification is performed through a preset feature matching algorithm, including detail feature point extraction and a three-level comparison mechanism.

[0131] In an optional implementation, the feature matching algorithm uses a hierarchical fusion strategy, combining local feature matching and global feature comparison to achieve high-precision identity verification. For fingerprint features, a modified minutiae-based ASTM-INK algorithm is used to extract 12 types of topological structural features. For facial features, a feature extraction method based on a deep convolutional neural network (ResNet-152 framework) is used to obtain high-dimensional feature vectors.

[0132] Specifically, the three-level comparison mechanism includes feature-level comparison, decision-level comparison, and security level verification:

[0133] Feature-level comparison: Perform matching calculations on each biometric feature individually to obtain a preliminary similarity score;

[0134] Decision-level comparison: Fusion of matching results of multiple biometric features, and calculation of comprehensive similarity through weighted calculation;

[0135] Security level verification: Dynamically adjust the verification threshold according to the importance of the stamped document to achieve differentiated security control.

[0136] During the fingerprint matching process, the system first performs a quick pre-screening of fingerprint patterns (such as bow, tent, and bucket) to narrow the matching range. It then performs a local structural match of detailed feature points, calculating the consistency of the spatial relationships between them. Finally, it verifies the ridge flow direction to confirm the overall texture orientation match. This multi-layered matching strategy keeps the fingerprint recognition error rate below 0.001%.

[0137] The face matching process uses the feature vector cosine similarity calculation method, combined with adaptive threshold technology, which can effectively cope with the influence of factors such as facial expressions, lighting changes and aging, and maintain a high recognition accuracy.

[0138] For example, during the actual verification process, the system will automatically adjust the verification strategy based on the importance of the document. For example, for general documents, an 80% similarity threshold might be set; for high-value contracts or financial documents, the similarity requirement might be increased to 95%, and dual biometric verification might be mandatory.

[0139] It should be noted that the pre-set feature matching algorithm focuses not only on recognition accuracy but also on security and anti-counterfeiting capabilities. Through a three-level comparison mechanism, the false positive rate and the risk of fraud are effectively reduced. Verification strategies can be flexibly adjusted based on business security requirements, achieving a good balance between security and ease of use.

[0140] In the embodiment of the present application, after the biometric verification is passed in step S400, the document to be used for printing is intelligently compared to confirm the consistency of the document, including the following steps D1-D4:

[0141] D1: Intelligent comparison of stamped documents includes:

[0142] Use OCR technology to identify the title and content of the document to be printed; compare the recognition result with the document information in the application form;

[0143] When the recognition result is inconsistent with the application information, an alarm message is issued; when the recognition result is consistent with the application information, the stamping operation is allowed to continue.

[0144] In one optional implementation, OCR technology uses a hybrid approach combining deep learning with traditional image processing to accurately recognize a wide range of document formats and layouts. The system first pre-processes the document image, including noise reduction, deskew, and contrast enhancement, to improve image quality. It then uses a deep convolutional neural network to detect text regions and recognize characters. Finally, post-processing utilizes natural language processing techniques to correct recognition errors and extract document structured information.

[0145] Specifically, the document OCR process consists of four main steps: document layout analysis, text region localization, character recognition, and semantic understanding. The layout analysis phase segments the document into different areas, such as the title, body text, tables, and images. The text localization phase precisely marks the location of the text to be recognized. The character recognition phase converts the text in the image into computer-processable text. The semantic understanding phase analyzes the text content and extracts key information, such as the document title, contract amount, and contracting parties.

[0146] The system uses specially optimized recognition models for different document types. For example, for contracts, the focus is on identifying key information such as the contract name, contracting parties, amount, and date; for financial vouchers, the emphasis is on identifying the voucher number, amount, and accounting subject; and for official documents, the focus is on elements such as the document number, title, and primary addressee.

[0147] For example, when the system processes a purchase contract, the OCR module automatically recognizes and extracts key information such as the title of "Purchase Contract", the contract number (such as "CG-2023-0125"), the supplier name (such as "XXX Co., Ltd."), and the total contract amount (such as "¥1,250,000") for subsequent file comparison and verification.

[0148] It should be noted that OCR technology is fundamental to intelligent document comparison, and its recognition accuracy directly impacts the reliability of subsequent comparison results. Through the application of deep learning technology, the system can continuously learn and optimize from a large number of actual documents, continuously improving its ability to handle various complex documents and providing high-quality text input for document consistency verification.

[0149] D2: Compare the recognition result with the document information in the application form;

[0150] In an optional implementation, document comparison utilizes a multi-layered similarity calculation method, combining exact and fuzzy matching techniques, to comprehensively assess the consistency between the document to be stamped and the application information. The comparison is not limited to the document title but also includes multiple indicators such as document type, key content, contracting party information, and monetary value, forming a comprehensive profile of the document's characteristics.

[0151] Specifically, the comparison process is divided into three levels:

[0152] Exact match layer: checks key fields such as file names and numbers that require exact consistency;

[0153] Key information layer: compare core business information such as contract amount, party name, date, etc.

[0154] Content similarity layer: Calculates the text similarity of the main content of the file to determine whether the documents are substantially consistent.

[0155] The system uses a weighted scoring mechanism, assigning different weights to different comparison items based on their importance. For example, consistency in contract amounts may receive a higher weight, while differences in formatting details may receive a lower weight. Ultimately, a comprehensive score is used to determine the overall consistency of the documents, preventing misjudgments caused by a single discrepancy.

[0156] For example, when comparing a purchase contract, the system will pay special attention to the consistency of key fields such as the contract number, supplier name, purchase amount, and delivery date, while also calculating the similarity of the full text. If the key information is completely consistent and the full text similarity exceeds 95%, the documents are considered identical. If a key information mismatch is found, such as the amount on the requisition being 1 million yuan while the actual document shows 1.2 million yuan, the system will immediately detect an inconsistency and trigger an alarm.

[0157] It should be noted that the core value of the intelligent comparison mechanism lies in preventing fraudulent practices such as "applying for one document, stamping another." By comparing document features across multiple dimensions and layers, the system effectively identifies inconsistencies in substantive content, prevents unauthorized changes to terms, and ensures the compliance and security of seal usage. Furthermore, the flexible comparison strategy can tolerate minor differences in layout details, improving the system's practicality and user experience.

[0158] D3: When the recognition result is inconsistent with the application information, an alarm message is issued;

[0159] In one optional implementation, the alert mechanism employs a multi-level response strategy, employing differentiated alerting methods based on the severity and nature of the inconsistency. The system first categorizes and assesses inconsistencies, distinguishing between critical inconsistencies (e.g., amounts, changes in parties involved) and non-critical inconsistencies (e.g., formatting adjustments, spelling errors). The system then triggers different levels of alert response based on the assessment results, ensuring that significant risks are addressed promptly while avoiding excessive disruption to normal business processes.

[0160] Specifically, alarm responses are divided into three levels:

[0161] Level 1 Alarm (Red): Serious inconsistency in key information, such as a change of more than 10% in the amount, a change in the parties involved, or a replacement of core terms. The system immediately locks the seal device, suspends the seal application process, and sends an emergency notification to the security administrator and approver.

[0162] Level 2 Alarm (Yellow): Minor inconsistency in important information, such as an amount error within 5%, a minor adjustment in the date, etc. The system displays a warning message to the operator, requiring confirmation that the change is reasonable and recording the confirmation process.

[0163] Level 3 prompt (blue): There are discrepancies in non-critical information, such as format adjustments, text optimization of non-core terms, etc. The system displays a prompt message, allowing the operator to confirm and continue the operation.

[0164] The alert message includes a detailed description of the discrepancy, such as "Contract Amount Mismatch: Application Amount: 1 million RMB, Actual Document Amount: 1.2 million RMB, Discrepancy: +20%," helping personnel quickly understand the issue. The system also automatically saves comparison evidence, including document screenshots, OCR results, and comparison records, to facilitate subsequent investigation.

[0165] For example, when the system detects that the amount of a contract has changed from 5 million yuan at the time of application to 6 million yuan, it will trigger a level one alarm, immediately lock the seal device, and send an alarm notification to the financial director, legal director, and approval director at the same time, requiring manual confirmation and processing.

[0166] It should be noted that the differentiated alarm mechanism ensures security while also accommodating the flexibility of actual business needs. Through scientific risk assessment and graded response, the system can prioritize mitigation of key risks while allowing for reasonable, non-substantive adjustments, avoiding excessive rigidity that can lead to inefficient operations. Furthermore, comprehensive alarm records and evidence preservation provide valuable data for subsequent risk analysis and process optimization.

[0167] D4: When the recognition result is consistent with the application information, the stamping operation is allowed to continue.

[0168] In an optional implementation, authorization execution after consistency confirmation utilizes a two-factor authentication mechanism to ensure operational security and controllability. The system first presents the operator with detailed comparison results, including a list of matching items and a comprehensive similarity score, providing intuitive proof of consistency. The operator is then asked to provide final confirmation, clearly indicating their intention to use the seal. Finally, the system records the confirmation and generates an authorization execution instruction, activating the seal unlocking process.

[0169] Specifically, the authorization execution process includes three steps: result display, operation confirmation, and authorization execution. The result display step clearly presents the comparison results through a visual interface, marking the matching status of key information. The operation confirmation step requires the user to click the "Confirm Stamp" button and enter a personal security code or perform fingerprint verification. The authorization execution step generates an encrypted execution instruction, which is passed to the seal control module and records a complete operation log.

[0170] The system also performs a final security check before execution, verifying the stamp device status, network connection security, and operating environment compliance to ensure all execution conditions are met. For example, it checks whether the stamp device is in normal working order, the ink supply system is functioning properly, and the device is within the permitted geographical range.

[0171] For example, in actual operation, the system will display a prompt saying "File consistency verification passed, 98.7% similarity, 100% match of key information" and require the operator to provide final confirmation. After confirmation, the system issues an unlock signal and simultaneously begins preparing for video recording and electronic ledger generation, achieving a seamless transition from verification to execution.

[0172] It should be noted that authorized execution after consistency confirmation is the critical bridge between verification and actual stamping. Clear results presentation and operational confirmation provide users with a basis for decision-making and clarify operational responsibilities. Comprehensive pre-execution checks further reduce operational risks and ensure a safe and controllable stamping process. This design embodies the safety concept of "human-machine integration," retaining the final decision-making power of human judgment while maintaining automated verification, achieving the optimal synergy between technology and human factors.

[0173] In another optional implementation, step S400 can also incorporate blockchain technology to implement file version control and anti-tampering protection. The system can generate a unique hash identifier for each document submitted for approval and record it on the blockchain, forming an unalterable version history. Before executing the stamping operation, the system verifies that the hash value of the document to be stamped is consistent with the latest approved version recorded on the blockchain. This prevents unauthorized file replacement at the source and provides stronger technical support for file consistency verification.

[0174] In the embodiment of the present application, unlocking the seal terminal device in step S500 and performing the stamping operation include the following steps E1:

[0175] E1: Security unlocking mechanism for seal terminal equipment;

[0176] In one optional implementation, seal unlocking utilizes a multi-layered security design, combining hardware encryption, software verification, and mechanical interlocking to ensure the seal can only be unlocked and used when all security conditions are met. The unlocking system comprises an electronic lock control module, a security chip verification unit, and a mechanical interlocking mechanism, forming a comprehensive hardware and software security system.

[0177] Specifically, the unlocking process is divided into three stages: command verification, permission confirmation, and physical unlocking. The command verification stage cryptographically verifies the received unlocking command to confirm its source legitimacy and content integrity. The permission confirmation stage checks whether the current time, location, and operator meet the authorization scope specified in the command. The physical unlocking stage uses a sophisticated motor control system to release the mechanical locking mechanism, allowing the seal to physically contact the document to be stamped.

[0178] The system employs multiple security measures to prevent unauthorized unlocking. First, the unlock command is encrypted with the device's unique key, ensuring it cannot be forged. Second, built-in tamper and tilt sensors automatically lock the device if any abnormal operation is detected. Finally, a timeout mechanism ensures that the device will automatically revert to locked mode if the stamping operation is not completed within a specified time.

[0179] In the embodiment of the present application, step S600 collects video data of the stamping process, generates an electronic ledger, and archives and stores the video data and the electronic ledger through the hybrid cloud platform, including the following steps F1-F2:

[0180] F1: Video data collected during the stamping process includes:

[0181] The entire stamping process is recorded in real time through a built-in high-definition camera; the video data is locally encrypted and stored;

[0182] The encrypted video data is uploaded to the intranet server through a secure link; the video data is automatically associated with the seal usage record to form an electronic ledger.

[0183] F2: Also includes abnormal situation handling process:

[0184] When biometric verification fails continuously for more than a preset number of times, a security lock is triggered; when the approval process times out, an upgrade mechanism or a backup approval chain is activated; when network transmission is interrupted, it automatically switches to a local secure storage area and caches whitelist instructions; when device hardware fails, a fault code is generated and a maintenance work order is pushed.

[0185] For example, a complete electronic ledger record will include detailed information such as "Applicant for seal: Zhang San; Application department: Marketing Department; Application time: 2023-08-15 10:30; Approval process: Department Manager → Finance Manager → General Manager; Approval completion time: 2023-08-16 15:20; Seal operator: Li Si; Seal use time: 2023-08-17 09:45; Seal type: Contract seal; Seal document: "Product Sales Contract"; Number of stamped pages: Page 12; Video record: VID20230817094500.mp4", and provide quick access links to related evidence.

[0186] It should be noted that electronic ledgers not only provide a detailed record of seal usage but also serve as crucial evidence of corporate seal management compliance. By integrating and linking scattered data and evidence, a standardized, structured seal usage archive is formed. This allows managers to gain a comprehensive understanding of corporate seal usage, promptly identify unusual behavior, and provide comprehensive evidence support for potential legal disputes. Furthermore, intelligent ledger management simplifies compliance audits and improves the efficiency of corporate risk management.

[0187] In summary, the hybrid cloud-based intelligent seal security management and control method and system provided by the present invention realizes a comprehensive innovation in seal management through a multi-level security architecture. First, the hybrid cloud architecture breaks through the scenario limitations of the traditional seal control system and realizes seamless collaboration between internal and external networks, so that enterprises can not only ensure the security of core data, but also meet the needs of mobile office and take-out seals. Secondly, multi-level approval and biometric dual authentication form a closed-loop link of "approval-verification", which effectively prevents the risk of seal theft and tampering from the source and execution links. Third, OCR intelligent comparison and full video recording build a complete electronic evidence chain to ensure that the seal use process is traceable and provable, greatly reducing the risk of seal use disputes. Fourth, the hierarchical design of the exception handling mechanism improves the resilience and fault tolerance of the system in complex environments. Even in the face of emergencies such as network interruptions and hardware anomalies, it can maintain business continuity or safe downgrade operation. In summary, this invention not only solves the security, standardization and efficiency issues of traditional seal management, but also meets the new demands of enterprises for seal management in digital transformation through technological innovation, providing enterprises with a one-stop seal security management solution.

[0188] Example 3

[0189] The above is a schematic scheme of a hybrid cloud-based smart seal security management method. It should be noted that the technical solution of the hybrid cloud-based smart seal security management system and the technical solution of the hybrid cloud-based smart seal security management method are based on the same concept. For details not described in detail in the technical solution of the hybrid cloud-based smart seal security management system in this embodiment, please refer to the description of the technical solution of the hybrid cloud-based smart seal security management method.

[0190] This embodiment also provides a hybrid cloud-based smart seal security management and control system, including:

[0191] The application processing module is used to obtain seal application information, which includes applicant information, application document information and seal type;

[0192] The approval management module is used to conduct multi-level approval of seal application information and generate seal approval results;

[0193] The instruction transmission module is used to send the seal approval results in the form of secure instructions to the seal terminal device through the hybrid cloud platform;

[0194] Identity verification module, used to collect the biometric information of the operator using the seal and compare and verify it with the preset biometric database;

[0195] The document comparison module is used to perform intelligent comparison of the stamped documents to confirm the consistency of the documents after the biometric verification is passed;

[0196] The seal control module is used to unlock the seal terminal device and perform the stamping operation;

[0197] The data recording module is used to collect video data of the stamping process, generate electronic ledgers, and archive and store the video data and electronic ledgers through the hybrid cloud platform.

[0198] The terminal layer includes smart seal equipment, which includes a biometric module, a high-definition camera, an automatic ink supply device, and a communication module;

[0199] The platform layer includes a hybrid cloud management platform, which is composed of public and private clouds and is used to achieve secure communication between the intranet and the intranet.

[0200] The application layer, including the mobile app and PC management backend, is used to provide functions such as seal application, approval, query and statistics;

[0201] Secure transport layer, including VPN tunnel and encryption transmission mechanism, to ensure the secure transmission of seal instructions and data;

[0202] The terminal layer exchanges data with the platform layer through the secure transport layer, and the application layer realizes remote control and management of the seal equipment through the platform layer.

[0203] This embodiment also provides an electronic device suitable for hybrid cloud-based smart seal security management and control, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the hybrid cloud-based smart seal security management and control method proposed in the above embodiment.

[0204] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for implementing hybrid cloud-based smart seal security management and control proposed in the above embodiment is implemented.

[0205] The storage medium proposed in this embodiment and the method for implementing hybrid cloud-based smart seal security management and control proposed in the above embodiment belong to the same inventive concept. Technical details not fully described in this embodiment can be found in the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.

[0206] Through the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented with the help of software and necessary general hardware, and of course can also be implemented by hardware. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.

[0207] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A hybrid cloud-based smart seal security management and control method, characterized by: The method includes obtaining seal application information, wherein the seal application information includes applicant information, application document information, and seal type; Conduct multi-level approval on the seal application information and generate a seal approval result; The seal approval result is sent to the seal terminal device in the form of a security instruction through the hybrid cloud platform; Collect the biometric information of the operator using the seal and compare and verify it with the preset biometric database; After the biometric verification is passed, the document to be used for stamping is intelligently compared to confirm the consistency of the document; Unlock the seal terminal device and perform the stamping operation; Video data of the stamping process is collected, an electronic ledger is generated, and the video data and the electronic ledger are archived and stored through a hybrid cloud platform.

2. The hybrid cloud-based smart seal security management and control method according to claim 1, characterized in that: The biometric information includes: fingerprint feature information and facial feature information; The biometric verification is performed through a preset feature matching algorithm, including detail feature point extraction and a three-level comparison mechanism.

3. The hybrid cloud-based smart seal security management and control method according to claim 2, characterized in that: The multi-level approval of seal application information includes: Generate file hash values to ensure file integrity; conduct automatic preliminary review through the intranet management platform; assign approval process routes based on preset rules; perform multi-level manual approval; and generate security instructions after approval.

4. The hybrid cloud-based smart seal security management and control method according to claim 3, characterized in that: The hybrid cloud platform includes: Intranet management server, used to process seal applications, approvals and document archiving; secure intranet boundary, including firewalls and security isolation devices; hybrid cloud management platform, including private cloud and public cloud cache areas; secure transmission Internet channel, used for encrypted command transmission.

5. The hybrid cloud-based smart seal security management and control method according to claim 4, characterized in that: The sending of the seal approval result in the form of a security instruction to the seal terminal device through the hybrid cloud platform includes: Perform quantum encryption on security instructions; transmit instructions through VPN secure channel; the seal terminal receives instructions through 4G / Wi-Fi communication module; the seal terminal decrypts and verifies the instructions.

6. The hybrid cloud-based smart seal security management and control method according to claim 5, characterized in that: The intelligent comparison of the seal documents includes: Use OCR technology to identify the title and content of the document to be printed; compare the recognition result with the document information in the application form; When the recognition result is inconsistent with the application information, an alarm message is issued; when the recognition result is consistent with the application information, the stamping operation is allowed to continue.

7. The hybrid cloud-based smart seal security management and control method according to claim 6, characterized in that: The video data of the stamping process includes: The entire stamping process is recorded in real time through a built-in high-definition camera; the video data is locally encrypted and stored; The encrypted video data is uploaded to the intranet server through a secure link; the video data is automatically associated with the seal usage record to form an electronic ledger.

8. The hybrid cloud-based smart seal security management and control method according to claim 7, characterized in that: It also includes the abnormal situation handling process: When biometric verification fails continuously for more than a preset number of times, a security lock is triggered; when the approval process times out, an upgrade mechanism or a backup approval chain is activated; when network transmission is interrupted, it automatically switches to a local secure storage area and caches whitelist instructions; when device hardware fails, a fault code is generated and a maintenance work order is pushed.

9. A hybrid cloud-based smart seal security management and control system, based on the hybrid cloud-based smart seal security management and control method according to any one of claims 1 to 8, characterized in that: It also includes an application processing module for obtaining seal application information, wherein the seal application information includes applicant information, application document information and seal type; An approval management module is used to perform multi-level approval on the seal application information and generate a seal approval result; An instruction transmission module is used to send the seal approval result in the form of a security instruction to the seal terminal device through the hybrid cloud platform; Identity verification module, used to collect the biometric information of the operator using the seal and compare and verify it with the preset biometric database; The document comparison module is used to perform intelligent comparison of the stamped documents to confirm the consistency of the documents after the biometric verification is passed; The seal control module is used to unlock the seal terminal device and perform the stamping operation; The data recording module is used to collect video data of the stamping process, generate an electronic ledger, and archive and store the video data and the electronic ledger through a hybrid cloud platform.

10. A hybrid cloud-based smart seal security management and control system, based on the hybrid cloud-based smart seal security management and control method according to any one of claims 1 to 8, characterized in that: It also includes a terminal layer, including a smart seal device, wherein the smart seal device includes a biometric module, a high-definition camera, an automatic ink supply device and a communication module; The platform layer includes a hybrid cloud management platform, which is composed of public and private clouds and is used to achieve secure communication between the intranet and the intranet; The application layer, including the mobile app and PC management backend, is used to provide functions such as seal application, approval, query and statistics; Secure transport layer, including VPN tunnel and encryption transmission mechanism, to ensure the secure transmission of seal instructions and data; The terminal layer exchanges data with the platform layer through the secure transport layer, and the application layer implements remote control and management of the seal device through the platform layer.