Cross-department electronic file sharing evidence storage and credibility authentication method and system based on block chain
By using modular decoupling design and blockchain technology with a unified application layer interface, the security and compatibility issues in cross-departmental electronic document sharing are solved, enabling secure and reliable sharing and efficient collaboration of cross-departmental data.
Patent Information
- Application Number
- CN202511090996.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-11-18
AI Technical Summary
Existing blockchain technology has limitations in cross-departmental electronic document sharing, including limitations in uploading unstructured data to the chain, insufficient security requirements, poor adaptability, and limited network domain compatibility. These issues make it difficult to meet the security, trust establishment, and adaptability requirements of cross-departmental data sharing.
It adopts a modular and decoupled design, provides a unified application layer interface, uses blockchain technology to achieve data tamper-proof and traceability, combines fine-grained permission management, adapts to heterogeneous environments and meets the requirements of domestic IT innovation, and achieves secure sharing in a one-way access policy network through specific data interaction methods.
It enables secure and reliable sharing of electronic documents across departments, improves data security and collaboration efficiency, reduces the difficulty of connecting the system to the blockchain, meets the needs of information technology innovation, and adapts to complex network environments.
Smart Images

Figure CN120979712A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a method and system for cross-departmental electronic file sharing, evidence storage and credibility authentication based on blockchain. BACKGROUND
[0002] In government organizations, cross-departmental collaboration has become the norm. However, the secure sharing, long-term storage and credible verification of data and electronic files between different departments still face many challenges. Traditional sharing and data exchange methods often have weak security, are easily tampered with, have difficulty in tracing and establishing trust between departments. In recent years, blockchain technology, as a decentralized and tamper-proof distributed ledger technology, has inherent data transparency, traceability and high security, providing new ideas and solutions to solve the bottleneck problems in the field of data security sharing and credible evidence storage.
[0003] Existing solutions have taken advantage of blockchain features to some extent, but still have significant limitations.
[0004] First, there are still limitations in uploading unstructured data. Most current blockchain solutions are designed for structured data and lack a general and complete mechanism for uploading and managing unstructured data. Even if some solutions support uploading unstructured data, the functions of existing solutions are usually limited to specific data uploading, querying and verifying operations, making it difficult to fully meet the needs of cross-institutional departmental secure sharing of general unstructured data.
[0005] Second, data security and access control granularity need to be improved. Existing solutions focus on the data itself and do not consider the security needs of unstructured data. The data permission control granularity is coarse and cannot fully meet the fine-grained read and write permission control needs of data owners for individual data.
[0006] Third, the adaptability is poor. On the one hand, it is highly dependent on specific blockchain systems, algorithms and file storage, lacking the ability to adapt to diverse needs. On the other hand, it lacks compatibility with the China's information technology industry, making it difficult to meet the needs of software and hardware adaptation in the domestic and China's information technology environment, and making it difficult and costly to transform existing information systems to blockchain.
[0007] Fourth, network domain adaptation is limited. It is difficult to effectively deal with complex network security domain environments such as government departments. Limited by security policies, it usually only allows "business private network domain" to initiate to "external network security domain", and cross-departmental data sharing needs to be transferred through "external network security domain". SUMMARY
[0008] The application aims to provide a blockchain-based cross-department electronic file sharing, evidence storage and credibility authentication method and system, which utilizes blockchain technology to realize data tamper-proofing, traceability, ensure a safe and reliable data sharing environment, and secure on-chain and fine-grained permission management of unstructured data. Through module decoupling, the system's compatibility and scalability are enhanced, making it adaptable to heterogeneous environments and meeting the requirements of the national security and informatization strategy. In addition, the application provides a unified application layer interface that shields the details of the underlying blockchain complex algorithm, thereby reducing the difficulty of existing information systems accessing the blockchain. More critically, the application can safely expose business private network services in a one-way access strategy network environment, thereby promoting cross-department collaboration and sharing.
[0009] To solve the above technical problems, the application provides a blockchain-based cross-department electronic file sharing, evidence storage and credibility authentication method, comprising the following steps:
[0010] The external department application system submits a file evidence storage request to the file evidence storage agent service of the home department; the original file of the file evidence storage request contains a file stream to be stored, a Hash value, metadata and file permission information;
[0011] The file evidence storage agent service encrypts the file stream and metadata according to the file evidence storage request and caches the encrypted file in the extranet area as a cache file; at the same time, the file evidence storage agent service pushes the file storage file evidence storage request to the message queue;
[0012] The file evidence storage service pulls the file evidence storage request from the message queue;
[0013] The file evidence storage service transfers the corresponding cache file in the extranet area to the intranet storage according to the file evidence storage request, saves the file storage address, and synchronously deletes the corresponding cache file in the extranet area;
[0014] The file evidence storage service generates an evidence unique identifier and connects to the blockchain system, calls the smart contract pre-deployed on the blockchain, and completes the on-chain operation of the Hash value of the original file, the evidence unique identifier, the metadata of the encrypted file and the timestamp information;
[0015] The file evidence storage service returns the evidence information to the external department application system through the file evidence storage agent service via the message queue; the evidence information includes the evidence unique identifier and the file storage address;
[0016] The external department application system saves the evidence information;
[0017] The external department application system initiates a credible authentication request to the file evidence storage service through the file evidence storage agent service according to the evidence information and the original file;
[0018] The file storage service is based on the storage information and original file of the trusted authentication request, and finds the corresponding storage data through a blockchain smart contract to perform authentication service.
[0019] Preferably, the method further comprises the following steps:
[0020] The external application system modifies the stored file;
[0021] The external application system queries the stored file through the file storage agent service and the file storage service;
[0022] The external application system subscribes to the storage information it has access to through a subscription interface.
[0023] Preferably, the external application system modifies the stored file, specifically comprising the following steps:
[0024] The updated file and the original storage information are forwarded to the file storage service through the file storage agent service; the file storage service transfers the modified file in the extranet area to the intranet storage, and performs on-chain processing on the related modification information.
[0025] Preferably, the external application system queries the stored file through the file storage agent service and the file storage service, specifically comprising the following steps:
[0026] The file storage service will return the storage file and related information that meet the requirements to the external application system through the file storage agent service according to the permission verification result.
[0027] Preferably, the external application system subscribes to the storage information it has access to through a subscription interface, specifically comprising the following steps:
[0028] When new file storage information is uploaded, the file storage service will actively push the storage information that the external application system has read access to to the external application system through the file storage agent service.
[0029] Preferably, the file storage service is based on the storage information and original file of the trusted authentication request, and finds the corresponding storage data through a blockchain smart contract to perform authentication service, specifically comprising the following steps:
[0030] The file storage service finds the corresponding storage data through a blockchain smart contract based on the storage information, and verifies whether the requester has read access;
[0031] If the storage data authorizes the access system to read, the authentication service is obtained;
[0032] Based on the authentication service, the file storage service calculates the Hash value of the original file and compares it with the Hash value stored in the blockchain, while checking the storage unique identifier of the storage;
[0033] If the Hash value of the original file is consistent with the Hash value stored in the blockchain, and the storage unique identifier of the storage request is consistent with the storage unique identifier stored in the blockchain, it is confirmed that the data is trustworthy, and the authentication is successful; otherwise, the authentication fails.
[0034] Preferably, the following steps are further included:
[0035] After completing the chain operation, the blockchain system returns the transaction information and the corresponding file storage information to establish a trusted association.
[0036] Preferably, the following steps are further included before the file storage proxy service encrypts the received file stream and metadata:
[0037] The file storage proxy service performs compliance check on the file storage request;
[0038] If the file storage request is not compliant, it is rejected.
[0039] The application also provides a system for cross-departmental electronic file sharing storage and trusted authentication based on blockchain, comprising:
[0040] A submission request module is used for the external department application system to submit a file storage request to the file storage proxy service of the department; the original file of the file storage request includes a file stream to be stored, a Hash value, metadata, and file permission information;
[0041] An encryption cache module is used for the file storage proxy service to encrypt the file stream and metadata according to the file storage request, and cache the encrypted file in the extranet area as a cache file; at the same time, the file storage proxy service pushes the file storage request to the message queue;
[0042] A pulling module is used for the file storage service to pull the file storage request from the message queue;
[0043] An intranet storage module is used for the file storage service to transfer the corresponding cache file in the extranet area to the intranet storage according to the file storage request, save the file storage address, and synchronously delete the corresponding cache file in the extranet area;
[0044] A chain module is used for the file storage service to generate a storage unique identifier, connect the blockchain system, call the smart contract pre-deployed on the blockchain, and complete the Hash value of the original file, the storage unique identifier, the metadata of the encrypted file, and the timestamp information chain operation;
[0045] The file storage module is configured to return storage information to the external department application system via the file storage agent service through a message queue by the file storage service; the storage information includes a storage unique identifier and a file storage address.
[0046] The storage information preservation module is configured to preserve the storage information by the external department application system.
[0047] The authentication request module is configured to initiate a trusted authentication request to the file storage service by the file storage agent service according to the storage information and the original file by the external department application system.
[0048] The authentication module is configured to find corresponding storage data for authentication service by the file storage service based on the storage information and the original file of the trusted authentication request through a blockchain smart contract.
[0049] Compared with the prior art, the present application has the following advantages:
[0050] First, secure and trusted data sharing: the tamper-proof, traceable features of the blockchain technology, and the fine-grained permission control mechanism ensure the security and trustworthiness of the data sharing process across departments, effectively prevent data leakage and tampering risks, and provide trustworthiness verification, thereby ensuring the authenticity and integrity of the data.
[0051] Second, high flexibility of the system architecture: the present application adopts modular decoupling design, which can flexibly select different services and components according to actual needs, such as message queue, file storage system, cryptographic algorithm and blockchain underlying platform, etc., to meet the needs of different departments and application scenarios, and support domestic information creation requirements. By providing a unified application layer interface, the upper layer service is decoupled from the underlying blockchain, which shields the details of the complex algorithms of the underlying blockchain, significantly reduces the difficulty of accessing the blockchain for existing information systems, and effectively reduces the development and maintenance costs.
[0052] Third, secure sharing in a one-way network environment: for special network environments such as government affairs, the present application adopts a specific data interaction method and performs data compliance checks on the external department data, which breaks through the one-way access restriction under the premise of meeting strict security policies, realizes the safe and reliable provision of business private network services, effectively solves the problem of cross-department data sharing, and improves the collaboration efficiency.
[0053] Through the above technical effects, the present application can effectively solve the security risks, trust problems and adaptability problems existing in the process of cross-department electronic file sharing, improve the efficiency of government collaboration, and promote the sharing and utilization of data resources. BRIEF DESCRIPTION OF DRAWINGS
[0054] The specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0055] Figure 1 is an access flowchart of a method for cross-departmental electronic file sharing, evidence storage and credibility authentication based on a blockchain according to the present application;
[0056] Figure 2 is a flowchart of cross-departmental electronic file sharing, evidence storage and credibility authentication based on a blockchain;
[0057] Figure 3 is a credibility authentication flowchart;
[0058] Figure 4 is a cross-departmental electronic file secure sharing flowchart. DETAILED DESCRIPTION
[0059] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the application. However, it will be apparent to one skilled in the art that the application can be practiced without the specific details set forth in this description. In other instances, well-known methods, procedures, components, and circuits have not been described in detail so as not to unnecessarily obscure aspects of the application.
[0060] The terminology used in this description of one or more embodiments should not be interpreted as limiting the scope of the description of one or more embodiments. The singular forms "a," "an," and "the" used in this description of one or more embodiments and the claims should not be interpreted as limiting the scope of the description of one or more embodiments to a single referent unless otherwise indicated by context. It will be understood that the terms "and / or," "comprises," "comprising," "includes," and / or "including," as used herein, refer to having one or more items, with the possibility of one or more of the items being present, or lacking, as appropriate. It will be further understood that the terms "comprises" and / or "comprising," when used in this description of one or more embodiments, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0061] It should be understood that although the terms first, second, etc. can be used herein to describe various information, these terms are not intended to denote a particular order or chronology. These terms are used only to distinguish one from another. For example, without departing from the scope of the description of one or more embodiments, a first can be termed a second, and, similarly, a second can be termed a first. The word "if' as used herein means "when" or "upon" or "in response to the determination" depending on the context.
[0062] The application will be further described with reference to the drawings, in which:
[0063] Taking the scenario of "cross-departmental electronic file sharing, evidence storage and credibility authentication by the application system of the department and the application system of the external department" as an example.
[0064] As Figures 1-2As shown, in order to ensure access security, all access application systems need to apply for access to the file storage service. After the application is passed, the file storage service will issue a unique identity information and a public-private key pair to the access system. Among them, the identity information is used to represent the identity of the access party, and the public-private key pair is used for identity verification. The access system must carry the identity information and use the private key to sign the request data each time it requests the file storage authentication service. The file storage service will verify the identity information of the access system and the signature of the data each time it receives a request. Only after verification, the request will be considered a valid request and processed. In the subsequent description, this security mechanism will not be repeated.
[0065] (1) The file storage and authentication process of the external application system of the present application is mainly as follows:
[0066] ① The external application system submits a file storage request to the file storage agent service of the external network of the department. The request includes the file stream to be stored, the file Hash value, the metadata information of the file, and the file permission information, including the authorized writing party and the reading party (the identity information issued by the file storage service).
[0067] ② The file storage agent service checks the compliance of the received data, and the data that does not meet the regulations will be rejected. Then, the file storage agent service will encrypt the received file stream and metadata, and cache the encrypted file in the external network area. At the same time, the service will push the file transfer task information and the file information on-chain request to the message queue.
[0068] ③ The file storage service actively pulls the file storage request from the message queue and processes the file preparation, including file transfer, on-chain operation, etc.
[0069] ④ The file storage service actively transfers the cached file in the external network area to the internal network storage, saves the file storage address, and synchronously deletes the cached file in the external network area to release the storage space and reduce the security risk.
[0070] ⑤ The file storage service generates a unique storage identifier and connects to the blockchain system, calls the pre-deployed smart contract on the blockchain, and completes the on-chain operation of the original file Hash value, storage identifier, encrypted file metadata, and timestamp information. At the same time, the blockchain returns the transaction information and the file storage information of this time are bound to establish a trusted association.
[0071] ⑥ The file storage service returns the file storage result and storage information (including storage unique identifier, file storage address, bound blockchain transaction information, etc.) of this time to the external application system through the file storage agent service via the message queue.
[0072] The external department application system needs to properly save the file evidence information returned by the file evidence agent service, for subsequent file modification, query tracing, and trusted authentication service.
[0073] The external department application system can initiate a trusted authentication request to the file evidence service through the file evidence agent service by virtue of the saved file evidence information and the original file. The file evidence service first finds the corresponding file evidence data based on the file evidence information through the block chain smart contract, and verifies whether the requester has read permission. Only the access system authorized to read the file evidence data can obtain the authentication service. Next, the file evidence service calculates the Hash value of the original file and compares it with the Hash value stored in the block chain, and checks the identification information of the file evidence. Only when the Hash value of the original file is completely consistent with the Hash value stored in the block chain, and the identification information of the file evidence is completely consistent with the identification information stored in the block chain, can it be confirmed that the data is trusted, and the authentication is successful; otherwise, the authentication fails. Figure 3
[0074] The external department application system can modify the file that has been stored, but must first have the write permission of the file evidence. The modification operation includes forwarding the updated file and the original file evidence information to the file evidence service through the file evidence agent service. The file evidence service transfers the modified file in the external network area to the internal network storage, and performs on-chain processing on the related modification information, while ensuring the effective distinction between the new and old data.
[0075] The external department application system can query the file that has been stored through the file evidence agent service and the file evidence service. Similarly, the query operation also needs to meet the corresponding read permission. The file evidence service will return the storage file and related information that meet the requirements to the external department application system through the file evidence agent service according to the permission verification result.
[0076] The external department application system can subscribe to the file evidence information that it has the right to access through the subscription interface. When new file evidence information is stored on the chain, the file evidence service will actively push the file evidence information that the external department application system has read permission to the external department application system through the file evidence agent service.
[0077] (2) The present application also provides electronic file sharing, evidence storage, authentication, modification, query and subscription functions for the department application system. Unlike the external department system, the department application system directly interfaces with the file evidence service without going through the file evidence agent service. The main process is as follows:
[0078] ①The department application system can directly submit an electronic file storage request (including a file stream to be stored, a file hash value, file metadata information, and file permission information) to the file storage service, the file storage service stores the file in the intranet storage after encryption, and calls a blockchain smart contract to complete the on-chain operation of the Hash value of the original file, the storage identifier, the encrypted file metadata, and the timestamp information, establishes a trusted association, and ensures the tamper-proofing and traceability of the storage information.
[0079] ②The department application system can also initiate a trusted authentication request to the file storage service based on the saved storage information and the original electronic file. Similar to the external department process, the file storage service first verifies whether the requestor has authentication permission, and then compares the Hash value of the original electronic file, the storage information, and the information stored on the blockchain to determine the authentication result, thereby providing a trusted proof of the authenticity and integrity of the file.
[0080] ③The department application system can modify the stored electronic file if it has the corresponding storage file writing permission. The file storage service will directly store the updated file in the intranet after encryption, and perform on-chain processing of the related modification information, while ensuring the effective differentiation between the new and old data, and guaranteeing the traceability of the modification process.
[0081] ④The department application system can query the stored electronic file through the file storage service under the premise of meeting the reading permission. The file storage service will return the storage file and related information that meet the security compliance requirements to the department application system based on the permission verification result, facilitating users to quickly search and obtain the required files.
[0082] ⑤The department application system can subscribe to the electronic file storage information it has access to through a subscription interface. When new file storage information is on-chain, the file storage service will actively push the storage information with reading permission to the application system, realizing timely acquisition of the storage information.
[0083] (3) The present application is mainly applied to the field of cross-department electronic file safe sharing and trusted authentication based on blockchain. Through the provided storage, authentication, query, modification, and subscription interfaces, the safe sharing of cross-department electronic files can be realized. The following will take the external department as an example to illustrate the basic process of electronic file sharing interaction, which can be adjusted appropriately according to actual needs. Figure 4
[0084] ①The department application system subscribes to the electronic file types shared by the external department application system through a subscription service.
[0085] ②External application system submits electronic file information to file storage service through file storage agent service for storage. The authorized write party of the stored electronic file is the external application system, and the authorized read party is the external application system and the internal application system. The file storage service performs encrypted file storage and chain operation.
[0086] ③The file storage service pushes the storage information of this time to the internal application system according to the subscription rules and read permission.
[0087] ④Since having read permission, the internal application system can query electronic file information according to storage information, and the file storage service returns stored electronic file original file, blockchain information and historical data and other information.
[0088] ⑤Since having read permission, the internal application system can also perform file authentication according to storage information and original file, and the file storage service returns authentication information to provide trusted proof for the authenticity and integrity of the file.
[0089] ⑥Since having write permission, the external application system can submit electronic file or metadata modification request to the file storage service through the file storage agent service, and the file storage service stores and chains the modification information and pushes it to the internal application system.
[0090] The application realizes high decoupling in module design, and can flexibly select different services and components according to actual needs, such as message queue, file storage component, password algorithm and blockchain system. For example, to meet the demand of domestic information creation, RocketMQ can be selected as the message queue, Tencent cloud object storage COS can be selected as the file storage, SM2, SM3, SM4 and other national encryption algorithms can be selected as the password algorithm, and Chang'an chain can be selected as the blockchain system. Similarly, for the network environment with relatively loose security policy restriction, the file storage agent service module of the internal department extranet can also be removed to realize direct connection with the file storage service, thereby simplifying the deployment architecture.
[0091] The application has the following advantages:
[0092] 1. Electronic file storage and trusted authentication based on blockchain;
[0093] The application uses blockchain technology to realize the tamper-proof and traceable characteristics of general unstructured electronic files, builds a cross-department secure and trusted data sharing environment, and provides full-process data management functions and trusted authentication services. Support for fine-grained permission control of each chained data, allowing data owners to flexibly specify access permissions.
[0094] 2. Modular design and flexible adaptation;
[0095] Adopt modular design, each module decoupling, support flexible configuration password algorithm, storage system and blockchain underlying platform, thereby adapt to heterogeneous application environment and meet the requirement of Xiongchuang, and provide uniform application layer's blockchain interface, reduce the access difficulty, facilitate the access and transformation of traditional system.
[0096] 3. Secure sharing in unidirectional access network environment;
[0097] For special network environment such as government affairs, specific security mechanism is adopted to provide special network service safely while meeting unidirectional access strategy, promote cross-department cooperation, and provide a complete set of electronic file evidence and authentication blockchain general solution.
[0098] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the described apparatus embodiment is only schematic, for example, the division of the modules, modules or units is only a logical function division, and there can be another division manner in actual implementation, for example, multiple units or modules can be combined or integrated into another apparatus, or some features can be ignored or not executed.
[0099] The units can or can not be physically separate, and the components displayed as units can be a physical unit or multiple physical units, that is, can be located in one place, or can be distributed to multiple different places. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.
[0100] In addition, each functional unit in each embodiment of the present application can be integrated in a processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0101] In particular, the processes described above with reference to the flow charts can be implemented as computer software programs in accordance with embodiments of the present disclosure. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program comprising program code for performing the methods illustrated by the flow charts. In such embodiments, the computer program can be downloaded and installed from a network via a communication section, and / or installed from a detachable medium. When the computer program is executed by a central processing unit (CPU), the above-described functions defined in the methods of the present disclosure are performed. It should be noted that the above-described computer readable medium of the present disclosure can be a computer readable signal medium or a computer readable storage medium or any combination of the two. The computer readable storage medium may, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus or device, or any combination of the above.
[0102] The flow charts and block diagrams in the drawings are illustrations of possible architectural, functional, and operational architectures of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow charts or block diagrams can represent a module, a segment, or a portion of code which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or in the reverse order, depending on the functionality involved. It will also be noted that each block of the block diagrams and / or flow charts, and combinations of blocks in the block diagrams and / or flow charts, can be implemented by special purpose hardware-based systems which perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.
[0103] The above description is only a specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or replacements within the technical scope disclosed by the present disclosure should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain, characterized in that, Includes the following steps: External department application systems submit document storage requests to the document storage agency service of this department; The original file for the file evidence request includes the file stream to be evidenced, hash value, metadata, and file permission information; The document evidence storage proxy service encrypts the file stream and metadata according to the document evidence storage request, and caches the encrypted file in the external network area as a cache file; at the same time, the document evidence storage proxy service pushes the file transfer document evidence storage request to the message queue. The document evidence preservation service pulls document evidence preservation requests from the message queue; The document storage service transfers the corresponding cached files in the external network area to the internal network storage based on the document storage request, saves the file storage address, and simultaneously deletes the corresponding cached files in the external network area. The document preservation service generates a unique identifier for preservation and connects to the blockchain system. It calls a smart contract pre-deployed on the blockchain to complete the on-chain operation of the original file's hash value, the unique identifier for preservation, the metadata of the encrypted file, and the timestamp information. The document evidence preservation service returns evidence preservation information to external department application systems via a message queue and a document evidence preservation agent service; the evidence preservation information includes a unique evidence preservation identifier and the file storage address. External department application systems store evidence information; External application systems, based on the evidence storage information and the original documents, initiate a trusted authentication request to the document evidence storage service through the document evidence storage agent service; The document preservation service uses the preserved information and original documents from a trusted authentication request to search for the corresponding preserved data through a blockchain smart contract to provide authentication services.
2. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 1, characterized in that, It also includes the following steps: External departments modify existing documents using application systems; External department application systems can query documents that have been stored through document storage agency services and document storage services; External application systems can subscribe to the evidence storage information they are authorized to access through a subscription interface.
3. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 2, characterized in that, External department application systems modify existing documents, specifically including the following steps: The updated file and the original evidence information are forwarded to the file evidence service through the file evidence agency service; the file evidence service transfers the modified file temporarily stored in the external network area to the internal network storage and processes the relevant modification information on the blockchain.
4. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 3, characterized in that, External application systems can query archived documents through document evidence storage agency services and document evidence storage services, specifically including the following steps: The document evidence storage service will return compliant stored files and related information to external department application systems through the document evidence storage agent service, based on the permission verification results.
5. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 4, characterized in that, External application systems subscribe to the evidence storage information they are authorized to access via a subscription interface, specifically including the following steps: When new document evidence information is uploaded to the blockchain, the document evidence service will proactively push the evidence information that the external department application system has read access to to the external department application system through the document evidence proxy service.
6. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 5, characterized in that, The document evidence storage service uses evidence storage information based on trusted authentication requests to retrieve corresponding evidence storage data through blockchain smart contracts for authentication services. Specifically, it includes the following steps: The document preservation service uses the preserved information to find the corresponding preserved data through a blockchain smart contract and verifies whether the requester has the right to read it. If the access system with authorized reading rights to the stored evidence data obtains authentication services; Based on the authentication service, the document storage service calculates the hash value of the original file and compares it with the hash value stored in the blockchain, while also verifying the unique identifier of the stored document. If the hash value of the original file matches the hash value stored in the blockchain, and the unique identifier for the requested notarization matches the unique identifier for the notarization stored in the blockchain, the data is deemed trustworthy and the authentication is successful; otherwise, the authentication fails.
7. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 6, characterized in that, It also includes the following steps: After the on-chain operation is completed, the transaction information returned by the blockchain system is bound with the corresponding document storage information to establish a trusted association.
8. The method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain according to claim 7, characterized in that, Before the document evidence storage agent service encrypts the received file stream and metadata, the following steps are also included: Document preservation agency services conduct compliance checks on document preservation requests; If the document storage request is not compliant, storage will be refused.
9. A system for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain, used to implement the method for cross-departmental electronic document sharing, storage, and trustworthiness authentication based on blockchain as described in any one of claims 1-8, characterized in that, include: The request submission module is used by external application systems to submit document storage requests to the document storage agency service of this department. The original file for the file evidence request includes the file stream to be evidenced, hash value, metadata, and file permission information; The encryption caching module is used by the file evidence storage agent service to encrypt the file stream and metadata according to the file evidence storage request, and cache the encrypted file in the external network area as a cache file; at the same time, the file evidence storage agent service pushes the file transfer file evidence storage request to the message queue. The pull module is used by the file evidence service to pull file evidence requests from the message queue; The intranet storage module is used by the file evidence service to transfer the corresponding cached files in the extranet area to the intranet storage according to the file evidence request, save the file storage address, and synchronously delete the corresponding cached files in the extranet area. The on-chain module is used to generate a unique identifier for document storage and connect to the blockchain system. It calls the smart contract pre-deployed on the blockchain to complete the on-chain operation of the original file's hash value, unique identifier for document storage, metadata of the encrypted file, and timestamp information. The evidence storage module is used by the document evidence storage service to return evidence storage information to external application systems via a message queue and a document evidence storage agent service; the evidence storage information includes a unique evidence storage identifier and a file storage address; The evidence storage module is used by external department application systems to store evidence information. The authentication request module is used by external application systems to initiate a trusted authentication request to the document storage service through the document storage agent service based on the evidence storage information and the original document. The authentication module is used for document storage services. Based on the stored information and original documents of the trusted authentication request, the module uses a blockchain smart contract to find the corresponding stored data for authentication services.