An archive global sense control intelligent protection method and system

By binding the identity anchor of archives with the protection strategy and the dynamic derivation chain tracing algorithm, the problem of seamless migration of protection strategies and traceability in the process of multi-path conversion during the transformation of archives from physical to electronic form is solved, and the intelligent protection of archives throughout their life cycle is realized.

CN121093387BActive Publication Date: 2026-02-06JINAN GUOYUN ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511631845.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2026-02-06
Estimated Expiration
2045-11-10

AI Technical Summary

Technical Problem

During the transition from physical to electronic records, existing record management systems cannot seamlessly migrate their protection strategies, leading to increased security risks. Furthermore, the conversion of electronic records across multiple media and paths makes them untraceable, resulting in multiple untraceable copies and rendering the protection strategies ineffective.

Method used

Based on the binding mechanism of the mapping between archive identity anchors and protection strategies, a dynamic identity mapping control algorithm and a dynamic derivation chain tracing algorithm are used to construct the archive identity anchor, protection strategy metastructure and directed derivation chain graph, so as to realize the continuity and traceability of protection strategies for archives under different forms and paths.

Benefits of technology

It achieves intelligent protection of archives throughout their lifecycle, and the protection strategy is automatically migrated during the transformation process to ensure security continuity and consistency, avoid copy chaos and path loss of control, and achieve traceability of full-domain protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121093387B_ABST
    Figure CN121093387B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of file security management, in particular to a file global sense control intelligent protection method and system; the method comprises the following steps: establishing an atomic identity description structure, jointly writing the atomic identity description structure and electronic file content into an identity mapping table, and constructing a file identity anchor point; calling a dynamic identity mapping control algorithm, and constructing a protection strategy mapping table between entity files and electronic files; constructing a directed derivative chain graph based on a derivative node information structure through a dynamic derivative chain tracing algorithm, and generating a dynamic traceable multi-path derivative chain; identifying a conversion derivative node, searching a protection strategy mapping table and a protection strategy element structure according to a file identity anchor point corresponding to the conversion derivative node, and constructing a protection strategy inheritance relationship between the conversion derivative node and an upstream derivative node. The application realizes global intelligent protection of the whole link in the process of file transformation from an entity to an electronic file and multi-path conversion of an electronic file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of archive security management technology, specifically to an intelligent protection method and system for comprehensive archive sensing and control. Background Technology

[0002] With the continuous acceleration of digitization, the storage and management of archives is transforming from a single physical form to an electronic form. Traditional archive protection systems mainly rely on physical protection measures and centralized, enclosed management locations, achieving comprehensive protection through physical security environments, access control, and scene isolation. However, this comprehensive protection is limited to the physical boundaries of physical archives and lacks effective coverage of the continuity of protection across media, system environments, and timelines. Electronic archive management systems, on the other hand, generally rely on storage media access control and access verification mechanisms for protection. The protection boundary is fixed in the static space of electronic document storage and access, making it impossible to achieve unified control and full traceability of archives across different media, paths, and dynamic transformation processes. This traditional comprehensive protection is more focused on the comprehensive protection of fixed media or fixed environments, without covering the dynamic changes in the state of archives across forms and paths throughout their entire lifecycle.

[0003] In actual archival management, the existing protection mechanisms generally suffer from two key technical problems during the transformation of physical archives to electronic archives and the conversion of electronic archives across multiple media and paths: First, because traditional protection mechanisms rely on binding protection strategies to the "document itself" rather than the "archival identity," the protection context of archives is severed during the transition from physical to electronic form, making it impossible to achieve a natural mapping of the archive identity and a seamless migration of protection strategies. Once the transformation is complete, the archive becomes an isolated object, requiring the protection strategy to be redefined, increasing security risks and weakening the interactivity between physical and electronic archives. Second, during the subsequent extraction, export, and copying of electronic archives, implicit conversion behaviors usually do not trigger existing security rules. The same archive may be exported multiple times from different paths, forming multiple untraceable copies, leading to problems such as non-unique protection objects or strategy failures. Summary of the Invention

[0004] The purpose of this invention is to provide a method and system for intelligent protection of archives with full-domain sensing and control, so as to solve the two key technical problems that exist in the existing protection mechanisms mentioned in the background art.

[0005] To achieve the above objectives, the technical solution of the present invention is: a method for intelligent protection of archives with comprehensive sensing and control, comprising:

[0006] S1. Establish an atomic identity description structure based on physical archive data, and write the atomic identity description structure and electronic archive content into the identity mapping table to construct archive identity anchor points;

[0007] S2. Call the dynamic identity mapping control algorithm to convert the protection policy information of the physical archive into a protection policy metastructure, and bind the protection policy metastructure with the archive identity anchor point to build a protection policy mapping table between the physical archive and the electronic archive.

[0008] S3. Extract the electronic archive status transition data to construct the derived node information structure. Based on the derived node information structure, construct a directed derived chain graph through a dynamic derived chain tracing algorithm. Associate the directed derived chain graph with the archive identity anchor point to generate a dynamic traceable multi-path derived chain.

[0009] S4. Identify the transformation derivation nodes in the transformation time window based on the directed derivation chain graph. Retrieve the protection strategy mapping table and protection strategy metastructure according to the archive identity anchor point corresponding to the transformation derivation node. Construct the protection strategy inheritance relationship between the transformation derivation node and its upstream derivation node through a dynamic and traceable multi-path derivation chain. Write the protection strategy inheritance relationship back to the directed derivation chain graph.

[0010] Preferably, in S1, the atomic identity description structure is a set of structured descriptions that transform the identity feature information of physical archives into electronic information structures. By establishing an identifier field, the identity information of the archives is kept consistent during the process of transforming physical archives into electronic archives.

[0011] The identity mapping table is a data mapping set used to store and index the correspondence between atomic identity description structures and electronic file content. By establishing index fields, the atomic identity description structures and electronic file content are bound to each other in a one-to-one correspondence.

[0012] Preferably, in S1, the archive identity anchor is an identifier structure that identifies the consistency of identity between physical archives and electronic archives. It is generated by binding the identifier field of the atomic identity description structure and the index field of the identity mapping table, and is used to establish a correspondence between identity features between physical archives and electronic archives.

[0013] The method for constructing the archive identity anchor is as follows: extract the identifier field of the atomic identity description structure corresponding to the entity archive, match the identifier field with the index field of the identity mapping table; bind the identifier field and the index field to form the archive identity anchor; and register the identifier value of the archive identity anchor in the identity mapping table.

[0014] Preferably, in S2, the dynamic identity mapping control algorithm is constructed based on the binding relationship between the file identity anchor and the identifier field of the atomic identity description structure, and the correspondence between the index field and the path identifier field in the identity mapping table. It is used to establish a one-to-one mapping logic between the file identity layer and the policy control layer, and to convert the protection policy data of the physical file into structured policy data.

[0015] The protection strategy metastructure is a structured strategy data set composed of access control data, security level information, and traceability information, used to record protection strategy information corresponding to the file identity anchor point;

[0016] The specific method for converting the protection strategy information of physical archives into a protection strategy metastructure includes: reading the physical archive protection strategy information corresponding to the archive identity anchor; parsing the access control data, security level information, and traceability information in the physical archive protection strategy information, and based on the field structure of the protection strategy metastructure, performing field mapping and format standardization processing on the access control data, security level information, and traceability information to obtain a standardized structured strategy data set; and converting the structured strategy data set into a protection strategy metastructure.

[0017] Preferably, in step S2, the protection strategy mapping table is a data mapping set that records the corresponding binding relationship between the protection strategy metastructure and the file identity anchor point, and is used to establish a mapping relationship of protection strategy information between physical files and electronic files;

[0018] The specific method for constructing the protection strategy mapping table between physical archives and electronic archives is as follows: read the protection strategy metastructure identifier value and the archive identity anchor identifier value; use the archive identity anchor identifier value as the index primary key, register the protection strategy metastructure identifier value in its corresponding record, and establish the corresponding binding relationship to obtain the protection strategy mapping table.

[0019] Preferably, in S3, the derived node information structure is a set of data structures used to record the derived behavior status information formed by the electronic archive during the conversion process, and is used to describe the derivation process of the electronic archive under different carriers and access paths in the form of time sequence and media conversion relationship.

[0020] The specific structure of the derived node information structure is as follows: The derived node information structure includes a timestamp field, a device identifier field, an operation type field, an output medium identifier field, and a source identity anchor point identifier field.

[0021] Preferably, in S3, the dynamic derived chain tracing algorithm is a dynamic path generation and backtracking algorithm constructed based on the temporal relationship and media conversion relationship between the timestamp field, device identifier field, operation type field and output medium identifier field in the derived node information structure, and is used to identify the derived chain relationship between electronic archives in different media and access paths;

[0022] The directed derivation chain graph is a directed graph structure constructed with the information structure of derived nodes as the set of nodes and the time and operation relationships between derived nodes as directed edges. It is used to record the multi-path derivation relationships of electronic archives under different media and operation behaviors in a structured manner.

[0023] Preferably, in S3, the dynamic traceable multi-path derivation chain is a multi-path chain structure based on a directed derivation chain graph, with the archive identity anchor value as the root reference and the set of derived nodes and the set of directed edges as paths, used to trace the conversion behavior of physical archives and electronic archives throughout the entire process.

[0024] Preferably, in S4, the protection strategy inheritance relationship is based on the path order between the transformation derivation node and its upstream derivation node in the dynamic traceable multi-path derivation chain, and the protection strategy metastructure recorded in the protection strategy mapping table is the inheritance source information. It is a one-to-one or one-to-many strategy mapping relationship established according to the derivation direction of the node and the path topology relationship, which is used to realize the chain inheritance and superposition of protection strategies when the transformation derivation node is formed.

[0025] The following method is used to construct the protection strategy inheritance relationship and write it back to the directed derivation chain graph: Using the transformation derivation node in the dynamic traceable multi-path derivation chain as the target node, retrieve its upstream derivation node set to determine its direct upstream node; based on the file identity anchor value corresponding to the upstream derivation node, retrieve the corresponding protection strategy metastructure in the protection strategy mapping table; establish an inheritance mapping relationship between the protection strategy metastructure corresponding to the upstream derivation node and the transformation derivation node to form the protection strategy inheritance relationship; and write this protection strategy inheritance relationship back to the corresponding directed edge in the directed derivation chain graph.

[0026] On the other hand, the present invention provides an intelligent protection system for full-domain sensing and control of archives, including a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the aforementioned intelligent protection method for full-domain sensing and control of archives.

[0027] Compared with the prior art, the above-mentioned technical solution of the present invention has the following beneficial technical effects:

[0028] 1. In this invention, the binding mechanism based on the mapping between the archive identity anchor and the protection strategy can always use the archive identity as the sole protection reference during the process of the archive transforming from physical form to electronic form, so as to realize the automatic migration and continuous loading of the protection strategy, avoid the problem of loss of protection context and reconfiguration of strategy caused by the transformation process, and ensure the security continuity and consistency of the archive in the early stage of its life cycle.

[0029] 2. In this invention, by introducing a dynamic derivation chain tracing algorithm and a strategy inheritance write-back mechanism, the full-chain traceability and dynamic policy transmission of electronic archives in multi-path derivation scenarios such as export, copying, and conversion are realized. This ensures that every conversion behavior is clearly recorded, traceable, and verifiable, further avoiding hidden security risks such as copy chaos, path loss of control, and failure of protection strategies, thereby achieving full-domain intelligent protection for the entire life cycle of archives. Attached Figure Description

[0030] Figure 1 This is a flowchart of one embodiment of the present invention. Detailed Implementation

[0031] Example 1, as Figure 1 As shown, the specific implementation steps of the intelligent protection method for full-domain sensing and control of archives proposed in this invention are as follows:

[0032] S1. Establish an atomic identity description structure based on physical archive data, and write the atomic identity description structure and electronic archive content into the identity mapping table to construct archive identity anchor points;

[0033] S2. Call the dynamic identity mapping control algorithm to convert the protection policy information of the physical archive into a protection policy metastructure, and bind the protection policy metastructure with the archive identity anchor point to build a protection policy mapping table between the physical archive and the electronic archive.

[0034] S3. Extract the electronic archive status transition data to construct the derived node information structure. Based on the derived node information structure, construct a directed derived chain graph through a dynamic derived chain tracing algorithm. Associate the directed derived chain graph with the archive identity anchor point to generate a dynamic traceable multi-path derived chain.

[0035] S4. Identify the transformation derivation nodes in the transformation time window based on the directed derivation chain graph. Retrieve the protection strategy mapping table and protection strategy metastructure according to the archive identity anchor point corresponding to the transformation derivation node. Construct the protection strategy inheritance relationship between the transformation derivation node and its upstream derivation node through a dynamic and traceable multi-path derivation chain. Write the protection strategy inheritance relationship back to the directed derivation chain graph.

[0036] In this embodiment S1, the atomic identity description structure is a set of structured descriptions that transform the identity feature information of physical archives into electronic information structures. By establishing an identifier field, the identity information of the archives is kept consistent during the process of transforming physical archives into electronic archives.

[0037] The identity mapping table is a data mapping set used to store and index the correspondence between atomic identity description structures and electronic file content. By establishing index fields, the atomic identity description structures and electronic file content are bound to each other in a one-to-one correspondence.

[0038] In this embodiment S1, the physical archive data refers to the structured collection information of the archive content and its external attributes in the form of a physical medium. Specifically, it includes archive number identifier, archive formation time identifier, archive holder identifier, archive medium attribute identifier, and archive content summary identifier, which are used to provide basic data for identity feature extraction during the archive digitization process. The archive number identifier is a field information that identifies the unique number of the archive; the archive formation time identifier is a timestamp information that records the time when the archive was formed; the archive holder identifier is a field information that records the subject of ownership or management rights of the archive; the archive medium attribute identifier is used to record the type information of the archive storage medium; and the archive content summary identifier is used to record the summary feature information of the archive content.

[0039] In this embodiment S1, the atomic identity description structure is a set of structured identity features generated according to preset field rules based on the collected physical archive data. This structured set includes an identity identifier field, a timestamp field, a subject identifier field, and a content summary field. The above information is solidified through standardized field mapping rules to uniquely identify the consistency of the archive's identity in physical and electronic media. The atomic identity description structure has uniqueness, non-repeatability, and traceability, and can maintain the continuity of identity information when the archive medium is converted. The identity mapping table supports path identifiers and identity structure indexes in multiple data formats, realizing bidirectional indexing and retrieval capabilities across media.

[0040] In this embodiment, during the process of writing the atomic identity description structure and the electronic file content into the identity mapping table, the physical file data is first extracted and the corresponding atomic identity description structure is generated. Then, in the digitization process, the mapping write instruction is called, using the file number identifier as the index primary key, to synchronously write the atomic identity description structure and the electronic file path identifier into the identity mapping table. Finally, the mapping record is verified to ensure the one-to-one correspondence between the atomic identity description structure and the electronic file path identifier, and a unique binding relationship is generated after successful writing.

[0041] In this embodiment S1, the archive identity anchor is an identifier structure that identifies the consistency of identity between physical archives and electronic archives. It is generated by binding the identifier field of the atomic identity description structure and the index field of the identity mapping table, and is used to establish a correspondence between identity features between physical archives and electronic archives.

[0042] The method for constructing the archive identity anchor is as follows: extract the identifier field of the atomic identity description structure corresponding to the entity archive, match the identifier field with the index field of the identity mapping table; bind the identifier field and the index field to form the archive identity anchor; and register the identifier value of the archive identity anchor in the identity mapping table.

[0043] In this embodiment S1, the identifier field of the atomic identity description structure is a set of data fields used to uniquely identify the identity characteristics of the entity archive, specifically including the archive number identifier field, the archive formation time identifier field, the archive holder identifier field, and the archive content summary identifier field; the index field of the identity mapping table is a set of primary key fields used to establish a one-to-one correspondence with the above identifier fields, specifically including the index primary key field and the path identifier field, wherein the index primary key field is used as a unique reference identifier for retrieval and binding, and the path identifier field is used to indicate the location of the electronic archive in the digital storage medium.

[0044] When generating a file identity anchor, the set of identifier fields is first read from the atomic identity description structure, and the corresponding index field is retrieved from the identity mapping table. After one-to-one matching is completed, the identifier field is bound to the index primary key field according to a preset combination rule to generate a file identity anchor identifier value. When registering the file identity anchor identifier value in the identity mapping table, the file identity anchor identifier value is used as the index key and stored in the primary key column of the mapping table, and a mapping record is established with the corresponding path identifier field. At the same time, the generation timestamp and binding status flag of the identifier value are recorded in the mapping table to provide a unique reference for subsequent retrieval, verification and protection strategy loading of file identity anchors.

[0045] In this embodiment S2, the dynamic identity mapping control algorithm is constructed based on the binding relationship between the file identity anchor and the identifier field of the atomic identity description structure, as well as the correspondence between the index field and the path identifier field in the identity mapping table. It is used to establish a one-to-one mapping logic between the file identity layer and the policy control layer, and to convert the protection policy data of the physical file into structured policy data.

[0046] The protection strategy metastructure is a structured strategy data set composed of access control data, security level information, and traceability information, used to record protection strategy information corresponding to the file identity anchor point;

[0047] The specific method for converting the protection strategy information of physical archives into a protection strategy metastructure includes: reading the physical archive protection strategy information corresponding to the archive identity anchor; parsing the access control data, security level information, and traceability information in the physical archive protection strategy information, and based on the field structure of the protection strategy metastructure, performing field mapping and format standardization processing on the access control data, security level information, and traceability information to obtain a standardized structured strategy data set; and converting the structured strategy data set into a protection strategy metastructure.

[0048] In this embodiment S2, a one-to-one binding relationship is formed between the archive identity anchor point and the identifier field of the atomic identity description structure. The identifier field is a set of fields used to uniquely represent the identity characteristics of the entity archive, including the archive number identifier field, the archive formation time identifier field, the archive holder identifier field, and the archive content summary identifier field. Through this binding relationship, the unique correspondence of the identity characteristics of the entity archive can be realized in the process of digital transformation. A unique index correspondence relationship is formed between the index field and the path identifier field in the identity mapping table. The index field is the primary key field for registering the archive identity anchor point identifier value, and the path identifier field is the field for recording the location identifier of the electronic archive in the digital storage medium. The correspondence between the two ensures that single-point anchoring and traceable positioning are achieved between the identity feature layer and the electronic archive content layer.

[0049] In this embodiment, the dynamic identity mapping control algorithm is constructed based on the one-to-one binding relationship between the aforementioned archive identity anchor points and identifier fields, as well as the unique index correspondence between the index fields and path identifier fields in the identity mapping table. This dynamic identity mapping control algorithm establishes anchor point binding rules, mapping table correspondence rules, and a set of field mapping rules to complete a structured mapping path from the entity archive identity layer to the policy control layer, ensuring that protection policy information can be continuously loaded and consistently traced across different media. Its construction process includes establishing binding and mapping rules, defining parsing processes, defining field mapping processes, setting registration processes, and setting change response processes, enabling the protection policy information to have dynamic mapping capabilities at the structural layer. The protection policy data of the entity archive is a set of policy information generated during the formation or management of the archive in its physical form, including at least access control data, security classification information, and traceability information. Access control data is used to record the access subject, allowed operation set, restrictions, and inheritance constraints. Security classification information is used to record the security classification level, confidentiality period, decryption conditions, and visibility range. Traceability information is used to record the source identifier, formation stage identifier, transfer record, responsible entity identifier, and recording time identifier.

[0050] In this embodiment, the field mapping and format standardization process is based on parsing the entity file protection strategy information, and standardizes the access control data, security level information, and traceability information according to the field rules of the protection strategy metastructure. The mapping process includes steps such as determining field correspondence, encoding normalization, time format unification, permission set compliance, subject identifier compliance, and null value handling to ensure the consistency of the value domain between the source field and the target field. After the mapping is completed, the above standardization results are summarized to generate a standardized structured strategy data set.

[0051] In this embodiment, the protection strategy metastructure is a structured strategy data set composed of an access control data structure, a security level information structure, and a traceability information structure. It is used to record protection strategy information corresponding to the archive identity anchor point in a standardized field format, enabling independent storage and cross-media mapping of protection strategy information. After mapping, the standardized structured strategy data set is registered as a protection strategy metastructure in the protection strategy mapping table, and a one-to-one correspondence is established with the corresponding archive identity anchor point identifier value. Through the above processing, dynamic mapping and continuous loading of entity archive protection strategy data between the identity layer and the strategy control layer are realized, providing basic support for subsequent derivation chain management and strategy inheritance.

[0052] In this embodiment S2, the protection strategy mapping table is a data mapping set that records the binding relationship between the protection strategy metastructure and the archive identity anchor point. It has uniqueness, traceability and cross-media mapping characteristics. It is used to establish the mapping relationship of protection strategy information between physical archives and electronic archives, so as to realize the continuous loading and consistent traceability of protection strategies in the process of changes in the form of archive media.

[0053] The specific method for constructing the protection strategy mapping table between physical archives and electronic archives is as follows: read the protection strategy metastructure identifier value and the archive identity anchor identifier value; use the archive identity anchor identifier value as the index primary key, register the protection strategy metastructure identifier value in its corresponding record, and establish the corresponding binding relationship to obtain the protection strategy mapping table.

[0054] In this embodiment S2, the protection strategy mapping table is a data mapping set used to register the one-to-one correspondence between protection strategy metastructure identifier values ​​and file identity anchor point identifier values. Its data structure includes at least an index primary key field, a strategy identifier field, a version field, an effective time field, an expiration time field, a status flag field, a path identifier field, a verification code field, a creation time field, and an update time field. The index primary key field is used to register the file identity anchor point identifier value and is the basic field for unique retrieval and binding. The strategy identifier field is used to register the protection strategy metastructure identifier value. The version field, effective time field, and expiration time field are used to record the time validity and change process of different strategy versions. The status flag field is used to identify the valid or invalid status of the record. The path identifier field is used to record the electronic file path information corresponding to the file identity anchor point. The verification code field is used to record record-level verification information. The creation time field and update time field are used to record the registration and change time of the mapping relationship. Through the unique combination constraint of the index primary key field and the strategy identifier field, it is ensured that the same file identity anchor point corresponds to only one valid protection strategy metastructure at the same time.

[0055] In this embodiment, the protection strategy metastructure identifier value is an identifier value generated after the physical archive protection strategy data is mapped and formatted through a dynamic identity mapping control algorithm. This protection strategy metastructure identifier value is used to uniquely identify a standardized strategy structure data in the protection strategy mapping table. The archive identity anchor identifier value is an identifier value generated based on the one-to-one binding relationship between the atomic identity description structure identifier field and the primary key field of the identity mapping table index. This archive identity anchor identifier value serves as the primary key index field in the mapping table. Through the unique correspondence between these two identifier values, the traceable mapping between physical archives and electronic archives at the protection strategy control layer is realized.

[0056] In this embodiment, when constructing the protection strategy mapping table between physical and electronic archives, the archive identity anchor value is used as the index key, and the identification value of the protection strategy metastructure is registered in the corresponding record, and a corresponding binding relationship is established. Specific operations include: First, reading the archive identity anchor value and the corresponding protection strategy metastructure identification value, and verifying the path identification information corresponding to the archive identity anchor in the identity mapping table; then, retrieving the currently valid record for the archive identity anchor value in the protection strategy mapping table. If it exists, the existing record is set to invalid and the invalidation time is registered; if it does not exist, a new initial version record is created; next, a new record is created in the mapping table, using the archive identity anchor value as the index key, and registering the protection strategy metastructure identification value, version information, effective time, status flag, and path identification fields; subsequently, a record-level checksum is calculated and written into the checksum field. Through bidirectional verification of the anchor identifier and the strategy identifier, the uniqueness and validity of the binding relationship are confirmed; finally, the creation time and update time fields are registered, the mapping relationship is solidified, and the registration of the protection strategy mapping table is completed.

[0057] In this embodiment S3, the derived node information structure is a set of data structures used to record the derived behavior status information formed by the electronic archive during the conversion process. It is used to describe the derivation process of the electronic archive under different carriers and access paths in the form of time sequence and media conversion relationship.

[0058] The specific structure of the derived node information structure is as follows: The derived node information structure includes a timestamp field, a device identifier field, an operation type field, an output medium identifier field, and a source identity anchor point identifier field.

[0059] In this embodiment, the timestamp field of the derived node is used to record the precise time of the conversion of the electronic archive; the device identifier field of the derived node is used to record the identifier of the terminal device or system that performs the conversion operation; the operation type field of the derived node is used to record the specific operation type that occurred; the output medium identifier field of the derived node is used to record the identifier of the target medium output by the electronic archive conversion; and the source identity anchor identifier field is used to record the archive identity anchor identifier value corresponding to this derivation behavior, thereby realizing the association between the derived node and the archive identity anchor.

[0060] In this embodiment S3, the dynamic derived chain tracing algorithm is a dynamic path generation and backtracking algorithm built on the temporal relationship and media conversion relationship between the timestamp field, device identifier field, operation type field and output medium identifier field in the derived node information structure. It is used to identify the derived chain relationship between electronic archives in different media and access paths.

[0061] The directed derivation chain graph is a directed graph structure constructed with the information structure of derived nodes as the set of nodes and the time and operation relationships between derived nodes as directed edges. It is used to record the multi-path derivation relationships of electronic archives under different media and operation behaviors in a structured manner.

[0062] In this embodiment, the specific method for constructing a directed derivation chain graph based on the derived node information structure using a dynamic derivation chain tracing algorithm is as follows:

[0063] S3.1. Verify the existence of required fields for each derived node information structure; mark nodes with missing fields as not eligible for edge construction according to the preset default strategy, retain the record but do not generate directed edges; unify the timestamp field of derived nodes to the same time representation format and record the standardized timestamp; normalize the device identifier field and output medium identifier field of derived nodes to a standard code according to the preset encoding table to ensure consistency of subsequent matching; divide the nodes into several homogeneous sets according to the source identity anchor point identifier field; construct an independent graph for each homogeneous set, with the root node pointing to the same file identity anchor point identifier value;

[0064] S3.2 Sort nodes in ascending order using the timestamp field of derived nodes as the primary sorting key; determine the time interval between adjacent nodes according to the preset time window threshold; if the interval exceeds the threshold, divide the nodes into different time segments and build edges for each segment to avoid incorrect cross-segment associations.

[0065] S3.3 Within the same time segment, perform the following determinations for two nodes with adjacent times: If the derived nodes have the same device identifier field and the derived node's output medium identifier field changes from "inner domain" to "outer domain", then it is determined that there is a medium conversion relationship from the upstream node to the downstream node; if the derived nodes have the same device identifier field and the derived node's operation type field is a conversion operation such as "print", "export", or "upload", then a directed edge is established from the upstream node to the downstream node; if the derived nodes have different device identifier fields but the derived nodes have the same output medium identifier field, and the time difference is within the threshold, then it is determined that there is a cross-device same medium derivation relationship, and a directed edge is established.

[0066] S3.4 For scenarios where there are multiple downstream nodes for the same upstream node and the time difference is within a threshold, a directed edge is generated for each downstream node in the edge set to form a branch structure, which is used to express a dynamic and traceable multi-path derivation chain. When two nodes are identical except for the timestamp field and the time difference is less than the merging threshold, the later node is merged into the earlier node, and the merging flag is recorded to avoid duplicate edge construction. Before adding a new directed edge, a check is performed on the candidate downstream node to see if it can be traced back to the upstream node. If a traceback path exists, the edge is not built, and a conflict flag is recorded to avoid forming a loop.

[0067] S3.5. Generate an adjacency list structure using node identifiers as keys and a list of downstream node identifiers as values; simultaneously generate a reverse adjacency list; record the basis for edge construction in the edge set, including the derived node timestamp field, derived node device identifier field, derived node operation type field, and derived node output medium identifier field participating in the determination; register a root reference on the directed subgraph generated for each same-source set, wherein the root reference is the source identity anchor point identifier field value common to the set.

[0068] In this embodiment, the handling of anomalies and conflicts in the directed derived chain graph is as follows: When there are multiple candidate upstream nodes under the same timestamp field, the node with the same device identifier field as the current node's derived node is selected first; if there are still multiple candidates, the node with the closest time difference is selected; the abandoned candidate is recorded as an alternative relationship; when the output medium identifier field of the derived node is missing and the operation type field of the derived node is a conversion operation, it is marked as "to be completed", no edge is built, and it is only retained as an isolated node, and incremental edge building will be triggered after subsequent completion.

[0069] In this embodiment S3, the dynamic traceable multi-path derivation chain is a multi-path chain structure based on a directed derivation chain graph, with the archive identity anchor value as the root reference and the set of derived nodes and the set of directed edges as paths. It is used to trace the conversion behavior of physical archives and electronic archives throughout the entire process.

[0070] In this embodiment S3, the specific method for associating the directed derivation chain graph with the archive identity anchor point to generate a dynamic and traceable multi-path derivation chain is as follows: Register the corresponding archive identity anchor point identifier value at the root node position of the directed derivation chain graph, and use this identifier value as the unique entry identifier of the multi-path derivation chain; perform mapping verification between each derivation node in the graph and the source identity anchor point identifier field to confirm that all derivation nodes belong to the same anchor point association range; record path sequence information, derivation node timestamp field, derivation node operation type field, and derivation node output medium identifier field in the multi-path chain structure to achieve dynamic path backtracking; register the aggregated multi-path chain structure as a dynamic and traceable multi-path derivation chain in the link traceability record set, using the anchor point identifier value as the entry point to achieve path-level tracing and inheritance of subsequent protection strategies.

[0071] In this embodiment, the dynamic traceable multi-path derivation chain uses the archive identity anchor value as the entry point to achieve centralized management and path-level referencing of all derivation paths under the same anchor point, realizing full traceability of the conversion behavior of electronic archives across different media, paths, and devices. In the subsequent process of protection strategy inheritance, the upstream nodes and policy sources can be quickly located based on the path sequence of the dynamic traceable multi-path derivation chain, realizing path mapping and chain inheritance of protection strategies, thereby ensuring the continuity and verifiability of protection strategies throughout the entire conversion and derivation lifecycle of the archive.

[0072] In this embodiment S4, the protection strategy inheritance relationship is based on the path order between the transformation derivation node and its upstream derivation node in the dynamic traceable multi-path derivation chain. The protection strategy metastructure recorded in the protection strategy mapping table is used as the inheritance source information. A one-to-one or one-to-many strategy mapping relationship is established according to the derivation direction of the node and the path topology relationship. This relationship is used to realize the chain inheritance and superposition of protection strategies when the transformation derivation node is formed.

[0073] The following method is used to construct the protection strategy inheritance relationship and write it back to the directed derivation chain graph: Taking the transformation derivation node in the dynamically traceable multi-path derivation chain as the target node, retrieve its upstream derivation node set to determine its direct upstream node; based on the file identity anchor value corresponding to the upstream derivation node, retrieve the corresponding protection strategy metastructure in the protection strategy mapping table; establish an inheritance mapping relationship between the protection strategy metastructure corresponding to the upstream derivation node and the transformation derivation node to form the protection strategy inheritance relationship; write this protection strategy inheritance relationship back to the corresponding directed edge in the directed derivation chain graph, recording the strategy inheritance source, protection strategy metastructure identifier value, and inheritance rule identifier as edge attributes, completing the path registration of the protection strategy inheritance relationship. This allows the strategy inheritance path to be recovered by traversing the directed derivation chain graph, realizing the dynamic transmission and verification of the strategy along the link.

[0074] In this embodiment S4, a transformation derived node refers to a derived node in a dynamic traceable multi-path derived chain whose operation type field belongs to "transformation operation". The transformation operation includes printing, exporting, copying, media transfer, uploading, burning, or other operations that will cause substantial changes in the state of the archive media or the access environment. The essential difference between a transformation derived node and other derived nodes is that its path position corresponds to the transition point of the archive media state, and it is a key node for the inheritance and triggering of protection strategies.

[0075] In this embodiment, the method for identifying transformation-derived nodes within a transformation time window based on a directed derivation chain graph is as follows: First, a preset transformation time window range is determined based on the timestamp field of each derived node in the graph; then, all derived nodes in the directed derivation chain graph are traversed, and their operation type fields are matched; when the node's operation type belongs to "transformation operation" and its timestamp field is within the current time window range, the node is identified as a transformation-derived node and marked as a policy trigger point on the path; next, the topological position of the node and its relationship with the upstream node are recorded in the graph. This system is used for subsequent protection policy inheritance and policy write-back. The method for retrieving the protection policy mapping table and protection policy metastructure based on the file identity anchor point corresponding to the transformation-derived node is as follows: First, read the corresponding file identity anchor point identifier value from the source identity anchor point identifier field of the transformation-derived node; then, search the protection policy mapping table using this file identity anchor point identifier value as the index primary key to locate the corresponding protection policy metastructure identifier value; finally, using the retrieved protection policy metastructure identifier value, load the corresponding protection policy metastructure content from the mapping table or metastructure storage area, providing an upstream policy source for constructing the policy inheritance relationship.

[0076] Example 2: The present invention proposes an intelligent archive full-domain sensing and control system, which is applied to the intelligent archive full-domain sensing and control method proposed in Example 1. It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the intelligent archive full-domain sensing and control method in Example 1.

[0077] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited thereto. Various changes can be made within the scope of knowledge possessed by those skilled in the art without departing from the spirit of the present invention.

Claims

1. An archival global sense control intelligent protection method, characterized in that, The method comprises the following steps: S1, establishing an atomic identity description structure based on entity archive data, writing the atomic identity description structure and electronic archive content into an identity mapping table together to construct an archive identity anchor point; In S1, the archive identity anchor point is an identification structure for identifying the consistency of the entity archive and the electronic archive identity, which is generated by binding the identification field of the atomic identity description structure and the index field of the identity mapping table, and is used to establish a corresponding relationship of identity features between the entity archive and the electronic archive; the archive identity anchor point construction method is as follows: extracting the identification field of the atomic identity description structure corresponding to the entity archive, matching the identification field with the index field of the identity mapping table; binding the identification field and the index field to form the archive identity anchor point; and registering the archive identity anchor point identification value in the identity mapping table; S2, calling a dynamic identity mapping control algorithm to convert the protection policy information of the entity archive into a protection policy meta structure, and binding the protection policy meta structure with the archive identity anchor point to construct a protection policy mapping table between the entity archive and the electronic archive; In S2, the dynamic identity mapping control algorithm is constructed based on the binding relationship of the archive identity anchor point and the identification field of the atomic identity description structure, and the corresponding relationship of the index field and the path identification field in the identity mapping table, and is used to establish a one-to-one mapping logic between the archive identity layer and the policy control layer, and convert the protection policy data of the entity archive into structured policy data; the protection policy meta structure is a structured policy data set composed of permission control data, secret level information and traceability information, and is used to record the protection policy information corresponding to the archive identity anchor point; The specific method of converting the protection policy information of the entity archive into the protection policy meta structure comprises the following steps: reading the entity archive protection policy information corresponding to the archive identity anchor point; parsing the permission control data, secret level information and traceability information in the entity archive protection policy information, and performing field mapping and format standardization processing on the permission control data, secret level information and traceability information based on the field structure of the protection policy meta structure to obtain a standardized structured policy data set; and converting the structured policy data set into the protection policy meta structure; S3, extracting electronic archive state conversion data to construct a derived node information structure, constructing a directed derived chain graph based on the derived node information structure through a dynamic derived chain tracing algorithm, associating the directed derived chain graph with the archive identity anchor point, and generating a dynamic traceable multi-path derived chain. The S3 is a dynamic path generation backtracking algorithm based on the time sequence relationship and medium conversion relationship among the time stamp field, the device identification field, the operation type field and the output medium identification field in the derivative node information structure, and is used for identifying the derivative link relationship between electronic archives in different media and access paths; the directed derivative chain graph is a directed graph structure constructed by taking the derivative node information structure as a node set and taking the time and operation relationship between the derivative nodes as a directed edge, and is used for recording the multi-path derivative relationship of electronic archives in different media and operation behaviors in a structured manner; the dynamic traceable multi-path derivative chain is a multi-path chain structure constructed by taking the directed derivative chain graph as a structure basis, taking the archive identity anchor point identification value as a root reference, and taking the derivative node set and the directed edge set as a path, and is used for tracing the conversion behaviors of entity archives and electronic archives throughout the process; S4, based on the directed derivative chain graph, a conversion derivative node in a conversion time sequence window is identified, a protection policy mapping table and a protection policy meta structure are retrieved according to the archive identity anchor point corresponding to the conversion derivative node, and a protection policy inheritance relationship between the conversion derivative node and its upstream derivative nodes is constructed through the dynamic traceable multi-path derivative chain, and the protection policy inheritance relationship is written back to the directed derivative chain graph; In the S4, the protection policy inheritance relationship is a one-to-one or one-to-many strategy mapping association relationship established according to the path order between the conversion derivative node and its upstream derivative nodes in the dynamic traceable multi-path derivative chain, and the protection policy meta structure recorded in the protection policy mapping table is used as the inheritance source information, and is used for realizing the chain inheritance and superposition of the protection policy when the conversion derivative node is formed; the conversion derivative node refers to a derivative node whose derivative node operation type field belongs to a conversion type operation in the dynamic traceable multi-path derivative chain; the protection policy inheritance relationship is constructed and written back to the directed derivative chain graph, and the specific method is as follows: taking the conversion derivative node in the dynamic traceable multi-path derivative chain as a target node, retrieving a set of its upstream derivative nodes, determining its direct upstream node; according to the archive identity anchor point identification value corresponding to the upstream derivative node, the corresponding protection policy meta structure is retrieved in the protection policy mapping table; the inheritance mapping relationship between the protection policy meta structure corresponding to the upstream derivative node and the conversion derivative node is established, and the protection policy inheritance relationship is formed; the protection policy inheritance relationship is written back to the corresponding directed edge in the directed derivative chain graph.

2. The file global sense control intelligent protection method according to claim 1, characterized in that: In the S1, the atomic identity description structure is a structured description set of converting the identity feature information of an entity archive into electronic information structure, and is used for keeping the archive identity information consistent in the process of converting the entity archive into an electronic archive by establishing an identification field; The identity mapping table is a data mapping set for storing and indexing the correspondence between the atomic identity description structure and the electronic archive content, and the atomic identity description structure and the electronic archive content are one-to-one bound by establishing an index field.

3. The method of claim 2, wherein: The S2 is the protection policy mapping table, which is a data mapping set recording the corresponding binding relationship between the protection policy meta-structure and the archive identity anchor point, and is used to establish the mapping relationship of the protection policy information between the entity archive and the electronic archive; The specific method for constructing the protection policy mapping table between the entity archive and the electronic archive is as follows: reading the protection policy meta-structure identification value and the archive identity anchor point identification value; taking the archive identity anchor point identification value as the index primary key, registering the protection policy meta-structure identification value in the corresponding record, and establishing the corresponding binding relationship to obtain the protection policy mapping table.

4. The file global sense control intelligent protection method according to claim 3, characterized in that: The S3 is the derived node information structure, which is a data structure set recording the derived behavior state information of the electronic archive formed in the conversion process, and is used to describe the derived process of the electronic archive under different carriers and access paths in the form of time sequence and medium conversion relationship. The specific structure of the derived node information structure is as follows: the derived node information structure includes a timestamp field, a device identification field, an operation type field, an output medium identification field and a source identity anchor point identification field.

5. An archive global awareness control intelligent protection system, comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: The processor executes the computer program to realize the archive global sense control intelligent protection method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Financial archive management method and system and electronic equipment

    CN112214657A

  • Conference file digital management system and method and electronic equipment

    CN117251526A