File downloading approval system and method based on approval code identification and external signature confirmation mechanism

By adopting a file download approval method based on approval code recognition and external signature confirmation mechanism, the feasibility of remote approval in a highly secure intranet isolation environment is solved, realizing the authenticity, security and traceability of remote approval, and improving the collaborative efficiency of multi-location distributed teams.

CN120934792APending Publication Date: 2025-11-11BEIJING DONGFANG AOSHEN TECH & TRADE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511019641.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In a highly secure, isolated intranet environment, remote or off-site employees cannot directly access the company's intranet to preview or download files, which disrupts the approval process and affects work efficiency.

Method used

The document download approval method adopts an approval code recognition and external signature confirmation mechanism. By generating an approval code and remotely recognizing and signing, it ensures the authenticity and security of the approval operation and enables remote approval without violating the enterprise's security isolation strategy.

Benefits of technology

It achieves the authenticity, security, and traceability of remote approval without compromising the enterprise's security isolation strategy, solves the problem of collaborative efficiency for personnel distributed across multiple locations, and supports compatibility with various terminal formats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934792A_ABST
    Figure CN120934792A_ABST
Patent Text Reader

Abstract

The invention discloses a file downloading examination and approval system and method based on examination and approval code identification and an external signature confirmation mechanism, and the method comprises the steps: an applicant initiates an examination and approval process in an intranet system, and the system generates unique examination and approval application record information and generates an examination and approval code, the applicant sends the approval code to an approver through a communication mode allowed by an enterprise; an approver uses an external approval client or a special identification tool in a remote environment to identify approval code information, and after approval is agreed, a personal private key and a system public key are used for encryption to generate a unique approval passing identifier and return the unique approval passing identifier to the applicant; the applicant logs in the intranet system and inputs the unique identification of approval passing, the system verifies the validity of the signature and matches the approval application, and after all necessary approval passes, the applicant is allowed to preview or download the file. According to the invention, on the premise of not destroying the security isolation strategy of the enterprise, remote examination and approval at different places are realized, and the authentication, security and traceability of the examination and approval operation are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of enterprise document security management technology, and in particular to a document download approval system and method based on approval code recognition and external signature confirmation mechanism. Background Technology

[0002] In traditional enterprise internal document management systems, for data security reasons, the system is often deployed on the enterprise intranet, prohibiting any form of external access, including network proxies and intranet penetration. However, when approvers are in remote or off-site work environments (such as in Hainan or Xinjiang), they cannot directly access the intranet system to perform approval operations such as document previewing and downloading. This disrupts the approval process in actual business operations and seriously affects work efficiency. Summary of the Invention

[0003] The purpose of this invention is to provide a file download approval system and method based on approval code recognition and external signature confirmation mechanism, so as to solve the technical problem in the prior art that it is impossible to access the enterprise intranet from the outside or to perform intranet penetration or proxy access in a high-security isolation environment of the intranet.

[0004] To address the aforementioned technical problems, this invention provides a file download approval method based on approval code recognition and external signature confirmation mechanisms, comprising the following steps: S1. The applicant initiates the approval process in the intranet system and generates an approval code; S2. The approver performs approval identification and signature in a remote environment, generating a unique identifier for approval approval; S3. The applicant confirms the approval in the intranet system.

[0005] Preferably, step S1 specifically includes: The applicant initiates a file download request through the intranet system; The system generates a unique approval application record. The system generates an approval code based on the approval application record information; The applicant sends the approval code to the approver via a communication method permitted by the company.

[0006] Preferably, step S2 specifically comprises: Approver uses an external approval client or dedicated identification tool in a remote environment to identify the approval code information; After the approver agrees to the approval, they use their personal private key and the system's public key to encrypt and generate a unique identifier for approval. The approver will return a unique approval identifier to the applicant.

[0007] Preferably, step S3 specifically comprises: The applicant logs into the intranet system and enters the unique identifier for approval; The system verifies the signature's validity and matches it with the approval application; Once all necessary approvals have been granted, the system allows the applicant to preview or download the documents.

[0008] Preferably, the approval code generation step is as follows: Information collection: The system collects all key information required for approval. Data encapsulation: The system encapsulates the collected information in a structured manner according to a predetermined format; Encryption / signature: To prevent information from being tampered with or forged, the packaged data is encrypted and signed. Encoding / transcoding involves encoding encrypted data to facilitate cross-platform transmission and recognition. An approval code is generated, which allows the applicant to send it to the approver through various channels.

[0009] Preferably, the approval application record information includes a unique document identifier, approval process number, list of approvers and their roles, approval deadline, reason for application or remarks, and anti-counterfeiting verification code.

[0010] Another technical solution provided in this application is: A file download approval system based on approval code recognition and external signature confirmation mechanism includes: The approval application and management module is used to collect application information, generate approval application records and approval codes; The approval code recognition module is used to identify and restore approval application record information; The file access control module is used to control the preview and download permissions of approval documents; The logging and auditing module is used to record all approval operations, signatures, and key verification behaviors for easy traceability and auditing. The User and Access Management module is used to manage applicants, approvers, role assignments, and access control. Interface and communication modules are used to support integration and communication with external systems.

[0011] Compared with the prior art, the beneficial effects of the present invention are: This invention provides a file download approval system and method based on approval code recognition and external signature confirmation mechanisms. It enables remote, off-site approval without compromising enterprise security isolation strategies, ensuring the authenticity, security, and traceability of approval operations. It also offers the following technical advantages: 1. Isolation environment compatibility: Enable remote approval without compromising the internal network's security. 2. Approval code recognition mechanism: The approval information is encapsulated into a portable "approval code" for easy transmission across networks; 3. Unique Identifier for Approval: The approval process is digitally signed, ensuring immutability and traceability; 4. No external network access required: All approval operations are completed on an external client, without the need to access the internal network; 5. Facilitates cross-regional collaboration: Solves the problem of distributed personnel approval in multiple locations and improves collaboration efficiency; 6. Supports multiple terminals: compatible with APP, web page, RemoteApp and other terminal formats. Attached Figure Description

[0012] Figure 1 This is a flowchart of the method steps of the present invention; Figure 2 This is a schematic diagram of the system modules of the present invention. Detailed Implementation

[0013] In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified. All directional indications (such as up, down, left, right, front, back, top, bottom, etc.) in the embodiments of this application are only used to explain the relative positional relationships and movement of the components in a specific posture (as shown in the figures). If the specific posture changes, the directional indication will also change accordingly. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or IoT terminal that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or IoT terminals.

[0014] Furthermore, the reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0016] The purpose of this invention is to provide a file download approval system and method based on approval code recognition and external signature confirmation mechanism, which enables remote approval without violating the enterprise's security isolation strategy, and ensures the authenticity, security and traceability of the approval operation.

[0017] The system environment constraints for this application are: 1. The document management system is deployed on the company's intranet and cannot be accessed from the public network; 2. Access via proxies, VPNs, or intranet penetration technologies is not permitted; 3. File previews and downloads must go through an approval process.

[0018] Example 1, like Figure 1 As shown, this invention provides a file download approval method based on approval code recognition and external signature confirmation mechanism, including the following steps: Step 1: The applicant initiates the approval process in the intranet system and generates an approval code.

[0019] Specifically, the following steps are included: The applicant (e.g., Zhang San) initiates a file download request in the intranet system; The system generates a unique approval application record, including document information, timestamp, applicant identity, etc. The system generates an approval code (which can be a QR code, string, etc.) based on the approval application record information; the system collects key information required for approval, encapsulates the information, performs signature encoding, and generates a unique anti-counterfeiting verification code.

[0020] The applicant (e.g., Zhang San) sends the approval code to the approver (e.g., Li Si, Wang Wu) through a communication method permitted by the enterprise.

[0021] Step 2: The approver performs approval identification and signature in a remote environment, generating a unique identifier for approval.

[0022] Specifically, the following steps are included: Approver uses an external approval client or a dedicated identification tool in a remote environment to identify the approval code information; the external approval client is compatible with APP, web page, and RemoteApp.

[0023] The approval code recognition module can reconstruct approval application record information, including: the initiator's identity, the initiation time, and the content of the application documents. Specifically, the approval application record information includes a unique document identifier, approval process number, a list of approvers and their roles, approval deadline, reason for application or remarks, and anti-counterfeiting verification code.

[0024] Once the approver agrees to the approval, they will use their personal private key and the system's public key to encrypt and generate a unique identifier for approval (digital signature or dynamic verification code). The approver will return a unique approval identifier to the applicant.

[0025] Step 3: The applicant completes the approval process in the intranet system.

[0026] Specifically, the following steps are included: The applicant logs into the company's intranet system; Enter the unique approval identifier provided by the approver; The system verifies the signature's validity and matches it with the approval application; Once all necessary approvals have been granted, the system allows the applicant to preview or download the documents.

[0027] Furthermore, the approval code generation step is as follows: 1. Information gathering The system collects all the key information required for this approval (such as applicant, documents, time, approval process number, etc.).

[0028] 2. Data encapsulation The above information is structured and encapsulated according to a predetermined format (such as JSON, XML, fixed-length string, etc.).

[0029] 3. Encryption / Signature To prevent information from being tampered with or forged, the packaged data can be encrypted and signed.

[0030] 4. Encoding / Transcoding Encode the encrypted data (such as Base64, QR code, short link, etc.) to facilitate cross-platform transmission and recognition.

[0031] 5. Generate approval code The final generated approval code allows the applicant to send it to the approver through various channels.

[0032] Example 2, Another technical solution provided in this application is: like Figure 2 As shown, a file download approval system based on approval code recognition and external signature confirmation mechanism includes: The approval application and management module is used to collect application information, generate approval application records and approval codes; The approval code recognition module is used to identify and restore approval application record information; The file access control module is used to control the preview and download permissions of approval documents; The logging and auditing module is used to record all approval operations, signatures, and key verification behaviors for easy traceability and auditing. The User and Access Management module is used to manage applicants, approvers, role assignments, and access control. Interface and communication modules are used to support integration and communication with external systems.

[0033] Example 3, A method and system for completing approval processes through external secure channels in an intranet-isolated environment are disclosed. This is suitable for high-security isolated environments where intranet penetration or proxy access is not possible. It is particularly applicable to the following scenarios: 1. Document management system for high-security organizations such as government, finance, and military industries; 2. Various local office platforms that do not have remote access capabilities; 3. Distributed team permission-based collaborative operations.

[0034] For example, after "Zhang San" initiates an approval application, a QR code is generated and sent to "Li Si" and "Wang Wu" via WeChat or email. After the approvers scan the code through the app, the approval details are displayed. After clicking "Agree," a dynamic verification code is generated. This verification code contains the approver's digital signature, which Zhang San then takes back to the internal network system and enters. This is considered as the approver's confirmation.

[0035] This application enables remote, off-site approval without compromising the company's security isolation strategy, and ensures the authenticity, security, and traceability of the approval process.

[0036] The basic principles of this application have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this application are merely examples and not limitations, and should not be considered as essential features of each embodiment of this application. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the application to the necessity of employing the specific details described above. The above description is provided to enable any person skilled in the art to make or use this application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this application. Therefore, this application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features of this application.

[0037] The above are merely preferred embodiments of this application and are not intended to limit the scope of this application. Any modifications or equivalent substitutions made within the spirit and principles of this application shall be included within the protection scope of this application.

[0038] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A file download approval method based on approval code recognition and external signature confirmation mechanism, characterized in that, Including the following steps: S1. The applicant initiates the approval process in the intranet system and generates an approval code; S2. The approver performs approval identification and signature in a remote environment, generating a unique identifier for approval approval; S3. The applicant confirms the approval in the intranet system.

2. The file download approval method based on approval code recognition and external signature confirmation mechanism according to claim 1, characterized in that, Step S1 specifically involves: The applicant initiates a file download request through the intranet system; The system generates a unique approval application record. The system generates an approval code based on the approval application record information; The applicant sends the approval code to the approver via a communication method permitted by the company.

3. The file download approval method based on approval code recognition and external signature confirmation mechanism according to claim 1, characterized in that, Step S2 specifically involves: Approver uses an external approval client or dedicated identification tool in a remote environment to identify the approval code information; After the approver agrees to the approval, they use their personal private key and the system's public key to encrypt and generate a unique identifier for approval. The approver will return a unique approval identifier to the applicant.

4. The file download approval method based on approval code recognition and external signature confirmation mechanism according to claim 1, characterized in that, Step S3 specifically involves: The applicant logs into the intranet system and enters the unique identifier for approval; The system verifies the signature's validity and matches it with the approval application; Once all necessary approvals have been granted, the system allows the applicant to preview or download the documents.

5. The file download approval method based on approval code recognition and external signature confirmation mechanism according to claim 1, characterized in that, The steps for generating the approval code are as follows: Information collection: The system collects all key information required for approval. Data encapsulation: The system encapsulates the collected information in a structured manner according to a predetermined format; Encryption / signature: To prevent information from being tampered with or forged, the packaged data is encrypted and signed. Encoding / transcoding involves encoding encrypted data to facilitate cross-platform transmission and recognition. An approval code is generated, which allows the applicant to send it to the approver through various channels.

6. The file download approval method based on approval code recognition and external signature confirmation mechanism according to claim 2, characterized in that, The approval application record information includes a unique document identifier, approval process number, list of approvers and their roles, approval deadline, reason for application or remarks, and anti-counterfeiting verification code.

7. A file download approval system based on approval code recognition and external signature confirmation mechanism, characterized in that, include: The approval application and management module is used to collect application information, generate approval application records and approval codes; The approval code recognition module is used to identify and restore approval application record information; The file access control module is used to control the preview and download permissions of approval documents; The logging and auditing module is used to record all approval operations, signatures, and key verification behaviors for easy traceability and auditing. The User and Access Management module is used to manage applicants, approvers, role assignments, and access control. Interface and communication modules are used to support integration and communication with external systems.

Citation Information

Patent Citations

  • Approval method and system based on mobile terminal

    CN104144413A

  • File signing method based on intelligent mobile terminal

    CN104636640A

  • Remote approval system for important files

    CN107169730A

  • All-in-one machine fraud judgment method, device, equipment and computer readable storage medium

    CN108537990A

  • An offline examination and approval method

    CN109359937A