A method for storing evidence of a trade secret
By constructing a multi-level project management structure and permission hierarchy, combined with blockchain evidence storage and dual-mode encryption, the fragmentation and judicial recognition problems of traditional trade secret evidence storage systems have been solved, enabling the secure, intact, and rapid response capabilities to infringement of trade secrets.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUNAN HAISEN INTELLIGENT TECHNOLOGY CO LTD
- Filing Date
- 2025-06-03
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional encryption systems cannot meet the requirements for judicial recognition, electronic evidence storage systems fail to fully cover the dynamic operational behavior of trade secrets, resulting in fragmented collection of secret information, and blockchain evidence storage is only for static files.
A multi-level project management structure and permission hierarchy are constructed. Encrypted documents are managed based on work order task cards, operation logs are recorded and hash values are calculated, and incremental uploads are performed on a blockchain evidence storage platform at regular intervals. Combined with dual-mode encryption and email and meeting management, a multi-dimensional evidence package is generated.
It enables the orderly organization and precise control of trade secrets, ensures data security and integrity, provides a clear trace of infringement, meets judicial confidentiality requirements, and enables rapid response to infringement disputes.
Smart Images

Figure CN120582857B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, specifically a method for preserving trade secrets. Background Technology
[0002] Trade secrets refer to commercial information such as technical and operational information that is not publicly known, has commercial value, and has been protected by the rights holder through appropriate confidentiality measures. Traditional encryption systems cannot meet the judicial requirements for the recognition of confidentiality measures, lack evidence of the correlation between operation logs and permission changes, and their electronic evidence storage systems are not deeply integrated with project management processes, resulting in fragmented collection of confidential information; blockchain evidence storage only applies to static files and does not cover the dynamic evidence storage chain of document operation behavior.
[0003] Although Chinese patents CN202411275147.1 "A Trade Secret Preservation Supervision and Management System", CN202411472617.3 "Evidence Data Preservation Method and Device", and CN202411477120.0 "Evidence Data Preservation Method and Device" have all made improvements to the preservation of evidence, none of them can meet the requirements for judicial recognition.
[0004] In summary, there is an urgent need for a new technical solution for the preservation of trade secrets, so as to ensure that the preservation of trade secrets meets the requirements for judicial recognition, thereby enhancing the ability to protect trade secrets. Summary of the Invention
[0005] The purpose of this application is to provide a method for preserving trade secrets in order to solve the technical problems mentioned in the background section.
[0006] To achieve the above objectives, this application discloses the following technical solution: a method for preserving trade secrets, the method comprising the following steps:
[0007] S1: Construct a secure environment that automatically encrypts generated trade secrets and generates encrypted documents based on pre-deployed encryption software;
[0008] S2: Construct a multi-level project management structure and permission hierarchy to manage the encrypted document. The multi-level project management structure includes work order task cards. The work order task cards are configured to: assign work tasks to different departments based on the work order task cards, and authorize different permission levels to different employees accordingly.
[0009] S3: Collect all encrypted documents and corresponding operation logs based on the work order task card, and calculate the corresponding hash value;
[0010] S4: Perform email management and meeting management. The email management is used to manage the outgoing channels of encrypted documents. The meeting management is configured to calculate the hash value corresponding to the meeting record when there is a meeting record on the work order task card.
[0011] S5: Periodically and incrementally upload the hash values of all encrypted documents, the hash values of the operation logs corresponding to all encrypted documents, and the hash values of meeting minutes to the blockchain evidence storage platform.
[0012] Preferably, the multi-level project management structure also includes special projects and sub-projects;
[0013] The permission hierarchy is configured to dynamically generate the storage path of the encrypted document based on the work order task card, and automatically set different permission levels. The permission hierarchy includes at least a special administrator level, a sub-project manager level, and a task executor level, wherein different permission levels have different operation permissions for the encrypted document.
[0014] Preferably, S3 specifically includes:
[0015] In response to a work order task card being triggered, the local synchronization folder corresponding to the work order task card is forcibly set;
[0016] In response to the completion of a work order task card, the work result file is automatically uploaded to the work order task card. At the same time, a log file is created for each encrypted document. The log file records all operation logs of the encrypted document, the contact evidence of the task executor, and the hash value of the encrypted document and the hash value of the corresponding operation log.
[0017] Preferably, recording all operation logs of the encrypted document in the log file specifically includes:
[0018] Record the operation log corresponding to the operation behavior of the encrypted document. The operation behavior includes at least: the creation, modification, download and external distribution of the encrypted document, the operator, operation time and approver, and the document information of the document being operated on.
[0019] The encrypted documents and the operation behaviors are stored in a structured manner to obtain the corresponding operation chain.
[0020] Preferably, the generation of the encrypted document specifically includes:
[0021] Trade secrets are protected by dual-mode encryption, which includes transparent encryption for editable documents and sandbox encryption for non-editable environments. The sandbox encryption setting only allows data to be written to a one-way data channel on the intranet.
[0022] Preferably, the hash value uploaded by the blockchain evidence storage platform also includes the hash value of the operation chain of the encrypted document.
[0023] Preferably, the evidence package includes at least a non-public knowledge proof document, a confidentiality measure proof document, and an access probability proof document; wherein: the non-public knowledge proof document includes a blockchain evidence storage timeline and access permission records; the confidentiality measure proof document includes an encryption policy configuration table and hardware control logs; and the access probability proof document includes an operational behavior graph and email correspondence evidence.
[0024] Preferably, the email management specifically includes:
[0025] Anonymously bind the recipient whitelist and the system outbox to the work order task card;
[0026] Emails are configured to not open or download attachments via web browser;
[0027] The email sending program is configured to be the only one that can automatically decrypt and send email attachments in the background;
[0028] The email recipient is configured as a recipient in the whitelist that is linked to the approval of the work order containing the attached file.
[0029] Preferably, when an encrypted document is leaked, the suspected infringed encrypted document and its corresponding operation chain are retrieved based on the multi-level project management structure and the encrypted document's file name. The meeting information and related meeting minutes documents that the encrypted document was opened are also retrieved. An evidence package is generated based on the encrypted document and its corresponding operation chain, the meeting information and related meeting minutes documents.
[0030] Preferably, the meeting management specifically includes:
[0031] During the meeting, the encrypted documents generated during the meeting are stored in a structured manner on the work order task card where the meeting is located. Meeting information is obtained, and encrypted documents related to the meeting are generated or updated at the same time. The access of participants to the encrypted documents is recorded, and the access information is used as proof of access probability.
[0032] Beneficial effects: The method for preserving trade secrets in this application is based on building a multi-level project management structure, which enables the orderly organization of trade secrets and precise control of permissions, thereby improving management efficiency; the mandatory synchronization mechanism of encrypted documents ensures that the data is timely, complete, and tamper-proof, enhancing data security; the operation chain record provides a clear trajectory for infringement tracing, facilitating rights protection; the combination of dual-mode encryption and unidirectional data channels effectively prevents data leakage and meets judicial confidentiality requirements; blockchain-based evidence preservation and the generation of multi-dimensional evidence packages guarantee the authenticity of data and the integrity of evidence, enabling rapid response to infringement disputes; and the closed-loop email management and meeting management mechanisms strengthen the protection of trade secrets in different scenarios. Attached Figure Description
[0033] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 A flowchart illustrating a method for preserving trade secrets provided in this application embodiment. Detailed Implementation
[0035] The technical solutions in the embodiments of this application will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0036] In this document, the term "comprising" is intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0037] This embodiment discloses, as follows: Figure 1 The method for preserving trade secrets, as shown, includes the following steps:
[0038] S1: Construct a secure environment that automatically encrypts generated trade secrets and generates encrypted documents based on pre-deployed encryption software;
[0039] S2: Construct a multi-level project management structure and permission hierarchy to manage encrypted documents. This multi-level project management structure includes work order task cards. The work order task cards are configured to: assign work tasks to different departments based on the work order task cards, and authorize different permission levels to different employees accordingly.
[0040] S3: Collect all encrypted documents and corresponding operation logs based on the work order task card, and calculate the corresponding hash value;
[0041] S4: Perform email management and meeting management. Email management is used to manage the outgoing channels of encrypted documents. Meeting management is configured to calculate the hash value corresponding to a meeting record when there is a meeting record on the work order task card.
[0042] S5: Periodically and incrementally upload the hash values of all encrypted documents, the hash values of the operation logs corresponding to all encrypted documents, and the hash values of meeting minutes to the blockchain evidence storage platform.
[0043] It should be noted that the blockchain evidence storage platform in this embodiment is a legally valid platform built on existing blockchain technology for evidence storage, such as the Internet Court blockchain evidence storage system.
[0044] Specifically, a multi-level project management structure also includes projects and sub-projects;
[0045] The permission hierarchy is configured to dynamically generate the storage path of encrypted documents based on the work order task card and automatically set different permission levels. The permission hierarchy includes at least the special administrator level, the sub-project manager level, and the task executor level, where different permission levels have different operation permissions for encrypted documents.
[0046] In a specific implementation example, a private cloud-deployed business secret information management system is used to structure and create work orders for various confidential departments within the enterprise. Work orders for each task node are created using a fixed three-tier structure: project, sub-project, and work order task card. Each work order is assigned a task executor, a sub-project manager for its sub-project, and a project administrator for its project. The relevant personnel are those authorized to access all documents associated with the work order. A multi-level project management structure is used to create and maintain the document collection and organization path structure and document access permission system, thereby achieving standardized business secret management.
[0047] Specifically, S3 includes:
[0048] In response to a work order task card being triggered, the local synchronization folder corresponding to the work order task card is forcibly set;
[0049] In response to the completion of a work order task card, the work result file is automatically uploaded to the work order task card. At the same time, a log file is created for each encrypted document. The log file records all operation logs of the encrypted document, the contact evidence of the task executor, and the hash value of the encrypted document and the hash value of the corresponding operation log.
[0050] In a specific implementation example, the attendance management subsystem of the business confidential information management system triggers work order task cards, creating a clock-in / clock-out recording function on the work order, thereby triggering mandatory synchronization of encrypted documents when a work order task card is triggered. As a preferred implementation of this embodiment, the attendance management subsystem forces each person performing the task to set a local storage folder for work order documents (i.e., in response to the triggering of a work order task card). Each time get off work ends, the relevant work documents for the completed work order tasks are automatically uploaded to a system-created work order folder (i.e., in response to the completion of a work order task card). All uploaded files cannot be modified the following day. The hash value of the uploaded documents is calculated, redundant upload results are removed, and the incremental new document upload results are reported to the superior.
[0051] By linking attendance records with work orders and synchronizing folder settings, the system enables seamless automated uploading of daily work results files and daily uploading result reporting. This allows for automated uploading and structured organization of employee work documents, as well as centralized collection, organization, and access control management of confidential business documents.
[0052] Specifically, the log file records all operation logs for the encrypted document, including:
[0053] Record the operation log corresponding to the operation behavior of the encrypted document. The operation behavior includes at least: the creation, modification, download and external distribution of the encrypted document, the operator, operation time and approver, and the document information of the document being operated on.
[0054] The corresponding operation chain is obtained by storing encrypted documents and operation behaviors in a structured manner in a one-to-one correspondence.
[0055] The structured storage of the operation chain enables unified management of all document information and document access operation information created, modified, and accessed by all employees involved in classified matters during their work at the company, providing a data foundation for the generation of evidence packages.
[0056] Specifically, the generation of encrypted documents includes:
[0057] Trade secrets are protected by dual-mode encryption, which includes transparent encryption for editable documents and sandbox encryption for non-editable environments. The sandbox encryption setting only allows data to be written to a one-way data channel on the intranet.
[0058] In a specific implementation example, through the establishment of systems and office conditions, employees are restricted to creating work documents only on encrypted computers equipped with encryption software or sandbox software. Utilizing existing document encryption systems, confidential documents are encrypted without affecting work. For example, when an employee creates a technical document on a secure computer, the system triggers a transparent encryption program, generating a 256-bit AES encrypted file, ensuring the file cannot be opened on systems outside the organization. For work environments that do not support encrypted files, existing sandbox encryption techniques are used to securely control network and internet access. This ensures that files cannot be freely sent out over the network; data files can only enter, not leave, the enterprise intranet system. Furthermore, document encryption software or sandbox encryption software blocks all hardware interfaces that could potentially copy files, such as USB ports. Sandbox encryption software prevents files in the sandbox security zone from being uploaded to unauthorized devices via any transmission method. Based on this, encrypted documents are obtained by encrypting trade secrets.
[0059] Specifically, the hash values uploaded by the blockchain evidence storage platform also include the hash values of the operation chain of the encrypted document.
[0060] It should be noted that the hash value calculation in this embodiment is independent. The hash value calculation process does not change the encrypted document and operation chain, and only the calculated hash values are saved to the blockchain evidence storage platform. As a preferred implementation of this embodiment, the risk of trade secret leakage is quantified using a dual hash value linkage risk calculation formula. Based on the quantified risk of trade secret leakage, a corresponding early warning is issued, and this early warning provides support for the evidence storage process, thereby providing a more logical evidence package in infringement litigation. The specific dual hash value linkage risk calculation formula is as follows:
[0061] R = α*(β) C +β B +γ*|β C -β B |)
[0062] in:
[0063] R is the calculated risk quantification value for the disclosure of trade secrets;
[0064] α is a preset risk amplification factor, which is set according to the sensitivity level of the trade secret. The sensitivity level of the trade secret is an empirical value known to those skilled in the art. For example, α = 1.5 for core technology and α = 1 for general business information.
[0065] β C This is a hash value change factor for encrypted documents. It is 1 when the hash value of the current encrypted document's content is different from the previous version, and 0 when they are the same.
[0066] β B This is the hash value change factor for the operation chain. It is 1 when the hash value of the current operation chain is different from the previous record, and 0 when they are the same.
[0067] γ is a two-dimensional inconsistency penalty factor, which only applies if β C =β B When γ = 0;
[0068] || is the absolute value operator.
[0069] In a simple example, the content is modified and the entire operation is recorded; at this point, |β C -β B | = 0, γ = 0, R = 2α, indicating consistent changes, manageable risk, compliance with modification and recording procedures, and a low-risk state. If the content is altered but there is no record of the action, then |β C -β B |=1,R=α*(1+γ) indicates that the inconsistency penalty item accurately captures the anomaly of content changes but missing behavior records, directly pointing to malicious leakage, which is in a high-risk state.
[0070] Based on the above, the calculation of hash values using existing technology connects technical evidence preservation and judicial evidence presentation. Through real-time verification, deduplication optimization, and blockchain evidence preservation, a reliable record of the entire process of trade secrets from creation to rights protection is achieved. This effectively solves the problems of high data tampering risk and high evidence presentation costs in traditional evidence preservation, significantly improving the technical compliance and judicial effectiveness of trade secret protection. Furthermore, the dual-hash value linked risk calculation formula realizes a two-dimensional risk assessment of content and operation, solving the industry pain points of incomplete content evidence preservation and difficulty in linking behavioral trajectories. This provides a quantitative tool for trade secret protection that combines technological breakthroughs and legal compliance, significantly improving the ability to protect trade secrets.
[0071] Specifically, the evidence package includes at least non-public knowledge proof documents, confidentiality measure proof documents, and access possibility proof documents; among which: non-public knowledge proof documents include blockchain storage timeline and access permission records; confidentiality measure proof documents include encryption policy configuration table and hardware control log; access possibility proof documents include operation behavior graph and email correspondence evidence.
[0072] In a specific implementation example, when an infringement lawsuit occurs, an evidence package is automatically generated that includes the following to meet judicial requirements:
[0073] A report on the rigor of the confidential document management measures of the infringed organization, including the archival records of training meetings on confidentiality measures and methods for confidential positions, archival records of employee labor contracts and confidentiality agreements, and archival certificates of confidentiality system documents;
[0074] A confidentiality report on the confidential document management technology system of the infringed organization, including automatic document encryption protection strategy, network and hardware copy port control strategy, document access control setting strategy, and measures to prevent external approval and prevent handling personnel from causing damage.
[0075] Quickly retrieve documents containing suspected infringed confidential information and their corresponding operation log files by using the project-sub-project-work order task card and file name; quickly retrieve meeting information where suspected infringed confidential information was opened and related meeting record documents and their corresponding operation log files by using the project-sub-project-work order task card.
[0076] The system retrieves the evidence hash value of documents containing suspected infringed confidential information and their corresponding operation log files. Using the retrieved document hash value, the system queries the document evidence certificate (including blockchain timestamp and document hash value) of the corresponding file and file operation log on the blockchain evidence platform.
[0077] The document evidence is provided to the judicial appraisal authority for review and comparison of the substantive confidential information with the suspected espionage content to obtain a report on the substantive content of the infringement by the infringer; the corresponding log document of the document evidence is provided to the judicial appraisal authority for review and comparison of the log records of the infringer's access to the infringed document to obtain a report on the infringer's substantive access to the infringed confidential information.
[0078] Based on the above, this embodiment realizes the proactive collection of trade secrets based on the three-in-one architecture of work order-document-permission. Each work order task card automatically generates an independent document library, and access permissions are dynamically updated according to the work order status, providing a data foundation for the closed-loop evidence preservation of the entire process. In the closed-loop evidence preservation of the entire process, time-stamped operation logs are automatically generated at each stage (document creation, modification, and external distribution), and cross-verified with blockchain evidence preservation. Based on this, evidence data is provided for generating legally compliant evidence packages, thereby generating data packages that conform to the legal compliance orientation. The law can be, but is not limited to, the "Judicial Interpretation on Trade Secrets".
[0079] Specifically, email management includes:
[0080] Anonymously bind the recipient whitelist and the system outbox to the work order task card;
[0081] Emails are configured to not open or download attachments via web browser;
[0082] The email sending program is configured to be the only one that can automatically decrypt and send email attachments in the background;
[0083] The email recipient is configured as a recipient in the whitelist that is linked to the approval of the work order containing the attached file.
[0084] In a specific implementation example, based on an embedded, existing email management subsystem, the super administrator maintains the enterprise's outgoing mailbox and its identifier. Specialized administrators create whitelisted email addresses for sending specific documents, which are then approved and activated by the super administrator. Sub-project managers create unique pairings and bindings between the outgoing mailbox, incoming mailbox, and work orders. When sending an email, the sender can only see the outgoing and incoming mailbox identifiers and cannot access the password for the outgoing mailbox. Through encryption system configuration, the email sending program is set as a unique, controlled program capable of automatically decrypting and sending email attachments in the background. This controlled program can be any existing computer program capable of automatically decrypting and sending email attachments in the background. Controlled email management ensures that document outreach is only permitted through the system's email subsystem. All emails can only be sent to the whitelisted email addresses of recipients linked to the work order containing the attachment; the sender cannot view these emails outside the system. Based on this, the ability to protect trade secrets is enhanced from the perspective of email management.
[0085] Specifically, when an encrypted document is leaked, the system retrieves the suspected infringed encrypted document and its corresponding operation chain based on the multi-level project management structure and the encrypted document's filename. It also retrieves meeting information and related meeting minutes that the encrypted document was opened. An evidence package is then generated based on the encrypted document, its corresponding operation chain, meeting information, and related meeting minutes.
[0086] Based on the above, this embodiment further expands the data scope of available evidence packages in infringement litigation by managing meetings involving encrypted documents.
[0087] Specifically, meeting management includes:
[0088] During the meeting, the encrypted documents generated during the meeting are stored in a structured manner on the work order task card where the meeting is located. Meeting information is obtained, and encrypted documents related to the meeting are generated or updated at the same time. The access of participants to the encrypted documents is recorded, and the access information is used as proof of access probability.
[0089] In one specific implementation example, when a meeting is initiated on a work order task card, an operation log file is automatically generated, containing meeting attendance information, meeting minutes, screen recordings, live video recordings, and other related information, and document numbers are automatically assigned. Based on this, the ability to protect trade secrets is enhanced from the perspective of meeting management.
[0090] In one example of indirect evidence storage based on this embodiment, the system automatically performs the following operations at 1:00 AM every day:
[0091] The system collects file information (including file name, timestamp, path, size, and hash value) of all successfully uploaded files from the previous day's upload tasks, as well as information on all modified log files from the previous day (such as log file hash values), forming a file information list file. Then, it calculates the hash value of this file information list file and uploads it to the blockchain notarization platform to complete the notarization operation, ensuring the authenticity and immutability of the file information. In specific applications, all successfully uploaded files can be, but are limited to: all new files uploaded via work orders, meeting minutes, audio and video recordings; all background information files for specific contracts; all employee resumes and confidentiality agreements; and all created and modified log file information.
[0092] In summary, the trade secret preservation method in this embodiment is based on a multi-level project management structure, which enables the orderly organization and precise control of trade secrets, thereby improving management efficiency. The mandatory synchronization mechanism of encrypted documents ensures that the data is timely, complete, and tamper-proof, enhancing data security. The operation chain record provides a clear trajectory for infringement tracing, facilitating rights protection. The combination of dual-mode encryption and a one-way data channel effectively prevents data leakage and meets judicial confidentiality requirements. Blockchain preservation and the generation of multi-dimensional evidence packages guarantee the authenticity of data and the integrity of evidence, enabling rapid response to infringement disputes. The closed-loop email management and meeting management mechanisms strengthen trade secret protection in different scenarios.
[0093] Furthermore, since blockchain evidence storage platforms limit the number of records that can be stored per account, a feasible solution is as follows: The Kaidao server collects information on newly added files daily, along with their corresponding hash values and the hash values of all changed operation log files. This information is then written to a daily updated file information list file (where the Kaidao server is an existing private cloud server). Further, to also store files generated in other enterprise information systems, a Kaidao system client can be installed on the file servers of those other systems. A specific folder on the client's server can be designated as the evidence monitoring target (where the Kaidao client is the software deployed on the Kaidao server). The Kaidao client monitors the newly added files in this folder daily, reads these new files, calculates their hash values, and writes this file information and corresponding hash values to the file information list file on the Kaidao server. The hash values of the file information list file generated the previous day are then stored on the blockchain evidence storage platform in the early morning of the following day. In this way, by storing a file information list file containing the file information and hash values of all newly generated data documents from the previous day on the blockchain evidence storage platform each day, the existence of all newly added files can be proven. In an example of indirect forensics based on this embodiment, if a trade secret leak occurs, the following operations are performed:
[0094] First, the leaked files and their log files are retrieved in the Kaidao system, and the hash value of the file information list file containing the above file information is obtained from the blockchain evidence storage platform.
[0095] Secondly, the list of documents containing the hash values of the leaked documents for that day is provided to a third-party certification authority, which calculates the hash value of the list and verifies its existence on a blockchain evidence storage platform.
[0096] At the same time, the leaked documents and their log files will be provided to a third-party certification authority, which will then calculate the hash values of the leaked documents and the log files.
[0097] Ultimately, a third-party certification body verifies whether the hash values of the leaked files and log files are recorded in the list of files stored on the blockchain evidence platform. If the verification is successful, it indirectly proves the objective existence of the leaked files and their log files, thereby proving the real existence of the leaked content and the responsibility of the leaker, and providing a basis for determining the leaked content and the responsibility of the leaker.
[0098] In the embodiments provided in this application, it should be understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, code, or any suitable combination thereof. For hardware implementation, the processor may be implemented in one or more of the following: application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, other electronic units designed to implement the functions described herein, or combinations thereof. For software implementation, some or all of the processes of the embodiments may be performed by a computer program instructing the associated hardware. During implementation, the program may be stored in a computer-readable storage medium or transmitted as one or more instructions or code on a computer-readable storage medium. Computer-readable storage media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media may be any available medium accessible to a computer. Computer-readable storage media may include, but are not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code having the form of instructions or data structures and accessible to a computer.
[0099] Finally, it should be noted that the above description is only a preferred embodiment of this application and is not intended to limit this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for preserving trade secrets, characterized in that, The method includes the following steps: S1: Construct a secure environment that automatically encrypts generated trade secrets and generates encrypted documents based on pre-deployed encryption software; S2: Construct a multi-level project management structure and permission hierarchy to manage the encrypted document. The multi-level project management structure includes work order task cards. The work order task cards are configured to: assign work tasks to different departments based on the work order task cards, and authorize different permission levels to different employees accordingly. S3: Based on the work order task card, collect all encrypted documents and corresponding operation logs, and calculate the corresponding hash value; wherein, in response to the triggering of a work order task card, forcibly set the local synchronization folder corresponding to the work order task card; in response to the completion of a work order task card, automatically trigger the synchronous upload of the work result file to the work order task card, and at the same time create a log file for each encrypted document, recording all operation logs of the encrypted document, recording the contact evidence of the task executor, and recording the hash value of the encrypted document and the hash value of the operation log corresponding to the encrypted document in the log file; S4: Perform email management and meeting management. Email management is used to manage the outgoing channels of encrypted documents. Meeting management is configured to calculate the hash value corresponding to a meeting record when a meeting record exists on the work order task card. Specifically, email management includes: anonymously binding a whitelist of recipients and the system outbox to the work order task card; configuring emails to be unopenable via webpage and preventing attachment downloads; configuring the email sending program to be the only one that can automatically decrypt and send email attachments in the background; and configuring email recipients to be recipients in the whitelist of recipients bound to the work order approval where the attachment file is located. Meeting management specifically includes: during a meeting, structurally storing the encrypted document generated during meeting creation on the work order task card where the meeting is located, obtaining meeting information, simultaneously generating or updating encrypted documents related to the meeting, recording the participants' access to the encrypted document, and using this access information as proof of access probability. S5: Periodically and incrementally upload the hash values of all encrypted documents, the hash values of the operation logs corresponding to all encrypted documents, and the hash values of meeting minutes to the blockchain evidence storage platform; Specifically, when an encrypted document is leaked, the system retrieves suspected infringed encrypted documents and their corresponding operation chains based on the multi-level project management structure and the encrypted document's filename. It also retrieves meeting information and related meeting minutes that the encrypted document was opened. An evidence package is generated based on the encrypted document, its corresponding operation chain, meeting information, and related meeting minutes. This evidence package includes at least three documents: proof of non-public knowledge, proof of confidentiality measures, and proof of access probability. Specifically, the proof of non-public knowledge includes a blockchain-based timeline and access records; the proof of confidentiality measures includes an encryption policy configuration table and hardware control logs; and the proof of access probability includes an operational behavior graph and email correspondence.
2. The method for preserving trade secrets according to claim 1, characterized in that, The multi-level project management structure also includes special projects and sub-projects; The permission hierarchy is configured to dynamically generate the storage path of the encrypted document based on the work order task card, and automatically set different permission levels. The permission hierarchy includes at least a special administrator level, a sub-project manager level, and a task executor level, wherein different permission levels have different operation permissions for the encrypted document.
3. The method for preserving trade secrets according to claim 1, characterized in that, The aforementioned recording of all operation logs for encrypted documents in the log file specifically includes: Record the operation log corresponding to the operation behavior of the encrypted document. The operation behavior includes at least: the creation, modification, download and external distribution of the encrypted document, the operator, operation time and approver, and the document information of the document being operated on. The encrypted documents and the operation behaviors are stored in a structured manner to obtain the corresponding operation chain.
4. The method for preserving trade secrets according to claim 1, characterized in that, The generation of the encrypted document specifically includes: Trade secrets are protected by dual-mode encryption, which includes transparent encryption for editable documents and sandbox encryption for non-editable environments. The sandbox encryption setting only allows data to be written to a one-way data channel on the intranet.
5. The method for preserving trade secrets according to claim 1, characterized in that, The hash value uploaded by the blockchain evidence storage platform also includes the hash value of the operation chain of the encrypted document.
Citation Information
Patent Citations
Commercial secret evidence storage supervision management system
CN119228303A
Evidence data storage method and device
CN119449390A
Evidence data storage method and device
CN119583098A
Project management system
CN112884450A
Method, system and device for storing electronic archives based on block chain, and medium
CN115982764A