File traceability management method and device in offline mode

By configuring a fingerprint blockchain table and a historical version relationship table for each server, the problems of file consistency and version traceability when data files are exchanged between servers in offline mode are solved, realizing file ownership confirmation and version traceability, and ensuring the security and integrity of data files.

CN120910916APending Publication Date: 2025-11-07BEIJING INST OF ENVIRONMENTAL FEATURES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510968192.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In offline mode, when data files are imported and exported between servers, it is difficult to confirm file consistency and integrity, and version tracing is difficult.

Method used

Configure a fingerprint blockchain table and a historical version relationship table for each server to record information about each version of the data file. Create the fingerprint blockchain table and historical version relationship table during import and perform ownership confirmation and version traceability through local query.

Benefits of technology

It enables file ownership confirmation, security, consistency, and version traceability in secure and confidential offline scenarios, ensuring the integrity and traceability of data files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120910916A_ABST
    Figure CN120910916A_ABST
Patent Text Reader

Abstract

The invention discloses a file traceability management method and device in an offline mode, and belongs to the field of information security. The method comprises the following steps: aiming at each server, decompressing and decrypting an imported target compression package to obtain all files in the target compression package; judging whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relation table or not; generating a fingerprint block chain table and a historical version relation table of the data file for the data file which does not carry the corresponding fingerprint block chain table and the historical version relation table; and for each data file carrying the corresponding fingerprint block chain table and the historical version relation table, querying the local fingerprint block chain table and the historical version relation table based on the carried fingerprint block chain table and the historical version relation table so as to carry out right confirmation and version traceability of the data file. According to the scheme, the right confirmation and version traceability of the file in the offline mode can be realized, and the security, consistency and integrity of the file are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and particularly relates to a file traceability management method and device in offline mode. BACKGROUND

[0002] In the field of information security, there is a kind of data file stored in a main data server system and a plurality of sub data server systems, and there is no network connection between the main server system and each sub server system. The data file of the main server needs to be classified and authorized according to the level and then exported to a storage medium, and then sent to different sub data server systems in offline mode. The main data server system and the sub data server system can upload new data files or modify existing data files.

[0003] When the data file is imported and exported between servers, since the data file can be modified in each server, and each server is in offline mode and cannot modify the history through the network, it is difficult to confirm the consistency and integrity of the file and to trace the version.

[0004] Therefore, it is urgent to provide a file traceability management method and device in offline mode. SUMMARY

[0005] In order to solve the problem that the data file in offline mode is imported and exported between servers, the consistency and integrity of the file are difficult to confirm, and the version is difficult to trace, the present application provides a file traceability management method and device in offline mode.

[0006] On the one hand, a file traceability management method in offline mode is provided, and the method comprises:

[0007] For each server, the following is performed:

[0008] When the current server receives the imported target compressed package, the target compressed package is decompressed and decrypted to obtain all files in the target compressed package;

[0009] It is judged whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relationship table;

[0010] For the data file which does not carry the corresponding fingerprint block chain table and the historical version relationship table, a fingerprint block chain table and a historical version relationship table thereof are generated;

[0011] For each data file carrying the corresponding fingerprint block chain table and the historical version relationship table, a local fingerprint block chain table and a historical version relationship table are queried based on the fingerprint block chain table and the historical version relationship table carried thereby, so as to perform the right confirmation and version traceability of the data file.

[0012] In another aspect, a file provenance management device in an offline mode is provided for implementing the steps of any method embodiment described in the specification, the device comprising:

[0013] A decryption unit is arranged in each server for performing: when the current server receives an imported target compressed package, decompressing and decrypting the target compressed package to obtain all files in the target compressed package;

[0014] A judgment unit is configured to judge whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relationship table;

[0015] A generation unit is configured to generate a fingerprint block chain table and a historical version relationship table for a data file that does not carry a corresponding fingerprint block chain table and a historical version relationship table;

[0016] A management unit is configured to, for each data file carrying a corresponding fingerprint block chain table and a historical version relationship table, perform local fingerprint block chain table and historical version relationship table query based on the fingerprint block chain table and the historical version relationship table carried thereby, to perform the data file's right confirmation and version tracing.

[0017] In another aspect, a computer device is provided, the computer device comprising a memory and a processor, the memory being configured to store a computer program, and the processor being configured to execute the computer program stored in the memory to implement the steps of the above-described method.

[0018] In another aspect, a computer readable storage medium is provided, the storage medium storing a computer program, and the computer program being executed by a processor to implement the steps of the above-described method.

[0019] In another aspect, a computer program product is provided, comprising a computer program, and the computer program being executed by a processor to implement the steps of the above-described method.

[0020] The technical solution provided by the present application can at least bring the following beneficial effects:

[0021] Each data file is configured with a fingerprint block chain table and a historical version relationship table, so as to record the information of each version of the data file. When any server is imported each time, a fingerprint block chain table and a historical version relationship table are created for the first uploaded data file, and for the data file for which the two tables have been created, local query is performed according to the fingerprint block chain table and the historical version relationship table carried thereby, to perform the data file's right confirmation and version tracing. The present solution is applied in a secure and confidential offline scenario, and solves the problems of file right confirmation, security, consistency and version tracing when the file is exchanged between multiple fields. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.

[0023] Figure 1 is a file traceability management method flowchart provided by an embodiment of the present application in offline mode;

[0024] Figure 2 is a file traceability management device structure diagram provided by an embodiment of the present application in offline mode;

[0025] Figure 3 is a hardware architecture diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0026] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort fall within the scope of protection of the present application.

[0027] The following describes the specific implementation of the above concept.

[0028] Please refer to Figure 1 The file traceability management method provided by the embodiments of the present application in offline mode comprises:

[0029] Step 100: For each server, when the current server receives an imported target compressed package, the target compressed package is decompressed and decrypted to obtain all files in the target compressed package.

[0030] Step 102: Determine whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relationship table.

[0031] Step 104: Generate a fingerprint block chain table and a historical version relationship table for a data file that does not carry a corresponding fingerprint block chain table and a historical version relationship table.

[0032] Step 106: For each data file carrying a corresponding fingerprint blockchain table and historical version relationship table, a local fingerprint blockchain table and historical version relationship table are queried based on the fingerprint blockchain table and historical version relationship table carried by the data file, so as to perform the authorization and version tracing of the data file.

[0033] In the embodiment of the application, a fingerprint blockchain table and a historical version relationship table are configured for each data file to record the information of each version of the data file. When any server is imported each time, the fingerprint blockchain table and the historical version relationship table are created for the first uploaded data file, and for the data file for which the two tables are created, a local query is performed according to the fingerprint blockchain table and the historical version relationship table carried by the data file, so as to perform the authorization and version tracing of the data file. The scheme is applied in a secure and secret offline scene, and solves the problems of authorization, security, consistency and version tracing of the data file when the data file is exchanged between multiple scenes.

[0034] In some embodiments, the fingerprint blockchain table contains operation fingerprint information of each version of the data file, and the operation fingerprint information is composed of at least a hash value of the version data file, a file operator and an operation time; and the historical version relationship table contains a hash value of each version of the data file and a version tree composed of the hash value of each version.

[0035] In the embodiment, in order to distinguish each version of the data file, the hash value of the data file is taken as a unique identity and stored in the fingerprint blockchain table, and the hash value is used to compose the version tree. The reason why the operation fingerprint information contains not only the hash value but also the file operator and the operation time is that there is a case that two persons export the data file from the master server and modify the data file after being exported to different sub-servers to obtain the same new version data file, which is easy to cause system errors or difficult to authorize. Therefore, the operation fingerprint information contains the file operator and the operation time to ensure the effective authorization of the data file.

[0036] The reason why the version tree is not placed in the fingerprint blockchain table and a historical version relationship table is separately created is that when a person outside the unit looks up a data file, the person is not a staff of the unit and has no right to view more information such as the modification person, so that the person is only given the data file and the historical version relationship table without the fingerprint blockchain table to prevent information leakage. Therefore, the historical version relationship table is set to improve the security.

[0037] In some embodiments, the data file is exported by the following way:

[0038] The hash value of the data file is used to determine the corresponding fingerprint blockchain table and historical version relationship table;

[0039] The data file, the fingerprint blockchain table and the historical version relationship table of the data file are encrypted and packaged and compressed for export.

[0040] In the embodiment, by packing the fingerprint blockchain table and the historical version relationship table of the data file together when exporting the data file, the data file can be easily authenticated and version traced when imported into other servers.

[0041] For steps 100, 102 and 104:

[0042] In the embodiment, in order to ensure that each version of the data file is recorded, when the data file is imported, it is necessary to determine whether the fingerprint blockchain table and the historical version relationship table of the data file are carried in the compressed package, if not, the hash value of the data file is generated, the file operator and operation time are added, the fingerprint information is generated, the fingerprint blockchain table and the historical version relationship table of the data file are created, and the data file, the fingerprint blockchain table and the historical version relationship table of the data file are encrypted and saved to the server.

[0043] For step 104:

[0044] In some embodiments, the step 104 of "querying the local fingerprint blockchain table and the historical version relationship table based on the carried fingerprint blockchain table and the historical version relationship table to authenticate and version trace the data file" includes:

[0045] determining the hash value of the current data file from the carried fingerprint blockchain table, and querying whether the hash value exists in the local fingerprint blockchain table of the current server;

[0046] if it exists, prompting that the data file already exists, and comparing whether the operation fingerprint information of the hash value in the carried fingerprint blockchain table is consistent with the operation fingerprint information corresponding to the hash value in the local fingerprint blockchain table of the current server to authenticate the data file, and based on the historical version relationship table carried and the version tree in the local historical version relationship table, the version trace is merged after authentication;

[0047] if it does not exist, the hash values of other version data files in the carried fingerprint blockchain table are queried in the current server, if at least one is queried, the carried historical version relationship table and the historical version relationship table in the current server are displayed to merge the version tree;

[0048] if none is queried, the data file and the carried fingerprint blockchain table and the historical version relationship table are saved to the current server.

[0049] In the embodiment, if the data file in the target compressed package carries two tables, it is necessary to determine whether the data file and its historical versions exist in the server based on the two carried tables. If they exist, it is necessary to determine the right and merge the version trees. If they do not exist, it is directly saved, so as to solve the right determination and traceability of distributed off-site files.

[0050] Specifically, the fingerprint blockchain table of the local server is queried based on the hash value of the current data file to determine whether the current data file exists. If it exists, it is necessary to determine whether the operation fingerprint information of the current version data file carried and the local operation fingerprint information are consistent. If they are consistent, it indicates that the current version data file has no problem, and the carried version tree and the local version tree can be merged to ensure the integrity and traceability of the data file modification history data. If they are inconsistent, the right arbitration is performed by the import user according to the system business approval process, the two tables are modified after the right determination, and the version tree is merged. It can be understood that after the right determination and merging, the data file and the modified two tables are saved to the current server.

[0051] If they do not exist, the hash values of other version data files in the fingerprint blockchain table carried are queried in the current server to determine whether the historical versions of the data file exist in the current server. If at least one is queried, the local fingerprint blockchain table and the historical version relationship table of the data file in the current server are located to perform the version tree merging.

[0052] If none of them is queried, it means that the data file is imported into the current system for the first time, and it is not necessary to determine the right and merge the version tree. The data file and the fingerprint blockchain table and the historical version relationship table carried are directly saved to the current server. It can be seen that the present scheme can realize the right determination and version traceability of the file in the offline mode, and ensure the security, consistency and integrity of the file.

[0053] In some embodiments, the data file is modified in the following manner:

[0054] The user-selected data file is decrypted and stored in the temporary folder of the database to enter the modification mode.

[0055] After the new version data file is obtained after the modification, the hash value of the new version data file is determined, and the file operator and the operation time are added to form the operation fingerprint information of the new version.

[0056] The operation fingerprint information of the new version is appended to the fingerprint blockchain table of the data file, and the hash value of the new version data file is appended to the version tree of the historical version relationship table of the data file.

[0057] The new version data file is encrypted and stored in the database.

[0058] In the embodiment, the fingerprint information is generated each time the modification is made, and the fingerprint block chain table and the historical version relationship table are updated, so as to facilitate the right confirmation and traceability management.

[0059] In some embodiments, each sub-server only interacts with the main server data, and the data interaction is not directly performed between the sub-servers, so that each time the data file is modified, the modification is finally summarized and combined in the main server, and the information of all data files is based on the main server, so that the integrity of the data file in the main system can be ensured.

[0060] Please refer to Figure 2 The embodiment of the application provides a file traceability management device in an offline mode, which is used for realizing the steps of any method embodiment in the specification, and the device comprises:

[0061] The decryption unit 201 is arranged in each server and is used for performing: when the current server receives the imported target compressed package, the target compressed package is decompressed and decrypted to obtain all files in the target compressed package.

[0062] The judgment unit 202 is used for judging whether each data file contained in the current target compressed package carries the corresponding fingerprint block chain table and the historical version relationship table.

[0063] The generation unit 203 is used for generating the fingerprint block chain table and the historical version relationship table of the data file which does not carry the corresponding fingerprint block chain table and the historical version relationship table.

[0064] The management unit 204 is used for performing the query of the local fingerprint block chain table and the historical version relationship table based on the carried fingerprint block chain table and the historical version relationship table of each data file which carries the corresponding fingerprint block chain table and the historical version relationship table, so as to perform the right confirmation and version traceability of the data file.

[0065] It should be noted that the file traceability management device in the offline mode provided in the above embodiment is only exemplified by the division of the above functional units, and in actual application, the above functions can be completed by different functional units according to needs, that is, the internal structure of the device is divided into different functional units to complete all or part of the above described functions. In addition, the device embodiment and the method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0066] The embodiment of the application further provides a computer device, please refer to Figure 3The computer device includes a processor and a memory, and the memory stores at least one instruction, at least one program, a code set or an instruction set, which are loaded and executed by the processor to implement the file traceability management method in the offline mode provided by the above method embodiments.

[0067] Embodiments of the present application also provide a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, which are loaded and executed by the processor to implement the file traceability management method in the offline mode provided by the above method embodiments.

[0068] Embodiments of the present application also provide a computer program product, which includes a computer program, and the processor of the computer device reads the computer program from the computer readable storage medium, and the processor executes the computer program to enable the computer device to execute the file traceability management method in the offline mode of any of the above embodiments.

[0069] For the convenience of description, the above system or device is described as various modules or units in terms of functions respectively. Of course, the functions of each unit can be implemented in one or more software and / or hardware in the implementation of the present application.

[0070] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware platforms. Based on such an understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of the various embodiments or some parts of the embodiments.

[0071] Finally, it needs to be pointed out that, in this article, the relationship terms such as first, second, third and fourth, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the term "include", "contain" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0072] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can also be made, which should be considered as the protection scope of the present application.

Claims

1. A method for file provenance management in offline mode, characterized in that, The method comprises the following steps: For each server, the following steps are performed: When the current server receives the imported target compressed package, the target compressed package is decompressed and decrypted to obtain all files in the target compressed package; It is judged whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relationship table; For each data file carrying a corresponding fingerprint block chain table and a historical version relationship table, local fingerprint block chain table and historical version relationship table are queried based on the fingerprint block chain table and the historical version relationship table carried by the data file to perform the data file's right confirmation and version tracing. The fingerprint block chain table contains operation fingerprint information of each version of the data file, and the operation fingerprint information is composed of at least a hash value of the data file of the version, a file operator and an operation time; the historical version relationship table contains a hash value of each version of the data file and a version tree composed of the hash value of each version.

2. The method of claim 1, wherein, The local fingerprint block chain table and the historical version relationship table are queried based on the fingerprint block chain table and the historical version relationship table carried by the data file to perform the data file's right confirmation and version tracing, which comprises the following steps:

3. The method of claim 2, wherein, The hash value of the current data file is determined from the fingerprint block chain table carried by the data file, and it is queried whether the hash value exists in the local fingerprint block chain table of the current server; If the hash value exists, it is prompted that the data file already exists, and it is compared whether the operation fingerprint information of the hash value in the fingerprint block chain table carried by the data file is consistent with the operation fingerprint information corresponding to the hash value in the local fingerprint block chain table of the current server to perform the data file's right confirmation, and after the right confirmation, the version tracing is performed based on the historical version relationship table carried by the data file and the version tree in the local historical version relationship table to perform the version tracing merging; If the hash value does not exist, the hash values of other version data files in the fingerprint block chain table carried by the data file are queried in the current server, if at least one is queried, the historical version relationship table carried by the data file and the historical version relationship table in the current server are displayed to perform the version tree merging; If none of the data files is queried, the data file and the fingerprint block chain table and the historical version relationship table carried by the data file are saved to the current server. The data file is exported by the following method:

4. The method of claim 1, wherein, The corresponding fingerprint block chain table and historical version relationship table are determined by using the hash value of the data file; The data file, the fingerprint block chain table and the historical version relationship table of the data file are encrypted and packaged and compressed for export. The data file is modified by the following method:

5. The method of claim 1, wherein, The user-selected data file is decrypted and stored in the temporary folder of the database to enter the modification mode; After the new version data file is obtained after the modification is completed, the hash value of the new version data file is determined, and the file operator and the operation time are added to form the operation fingerprint information of the new version; The operation fingerprint information of the new version is appended to the fingerprint block chain table of the data file, and the hash value of the new version data file is appended to the version tree of the historical version relationship table of the data file. ​ The new version of the data file is encrypted and stored in the database.

6. The method of claim 1, wherein, Each sub-server only interacts with the main server data, and the sub-servers do not directly interact with each other, and all data file information is based on the main server.

7. A file provenance management apparatus in an offline mode for implementing the steps of the method of any of claims 1-6, characterized in that, Comprise: A decryption unit is arranged on each server, and is used for: when the current server receives the imported target compressed package, decompressing and decrypting the target compressed package to obtain all files in the target compressed package; A judgment unit is used for judging whether each data file contained in the current target compressed package carries a corresponding fingerprint block chain table and a historical version relationship table; A generation unit is used for generating a fingerprint block chain table and a historical version relationship table for a data file which does not carry a corresponding fingerprint block chain table and a historical version relationship table; A management unit is used for, for each data file carrying a corresponding fingerprint block chain table and a historical version relationship table, querying a local fingerprint block chain table and a historical version relationship table based on the fingerprint block chain table and the historical version relationship table carried by the data file, to perform authorization and version tracing of the data file.

8. A computer device, comprising: The computer device comprises a memory and a processor, the memory is used for storing a computer program, and the processor is used for executing the computer program stored on the memory to realize the steps of the method of any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to realize the steps of the method of any one of claims 1-6.

10. A computer program product, characterised in that, The computer program is executed by the processor to realize the steps of the method of any one of claims 1-6.