Method and system for detecting electronic file transfer in secret-related network environment

By implementing multi-dimensional detection in a classified network environment, the compliance issues of the entire process of electronic file transfer were resolved, achieving closed-loop management throughout the process and ensuring the security and compliance of the transfer.

CN121309142APending Publication Date: 2026-01-09AVICIT CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511588255.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-03
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

Existing technologies cannot meet the full-process compliance testing requirements for the transfer of electronic records in a classified network environment, posing risks of leakage and violations.

Method used

Multi-dimensional automated testing is implemented before and after the handover, including testing of the main body's classified qualifications, compliance of archives, and compliance of the environment. Data integrity and channel compliance are monitored in real time during transmission, and secondary testing is performed at the receiving end to generate detailed handover logs to ensure compliance.

Benefits of technology

It achieves closed-loop management of operators, equipment, files and environment throughout the entire process, effectively eliminating the risk of unauthorized transfer and leakage, and ensuring the security and compliance of the transfer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309142A_ABST
    Figure CN121309142A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for detecting electronic file transfer in a secret-related network environment, and belongs to the field of information security. The method is executed in a secret-related network environment of physical isolation, and comprises the following steps of: pre-detecting before handover initiation, and verifying the qualification of an operation main body, the compliance of files and the compliance of the environment; after the pre-detection is passed, carrying out real-time dynamic detection in an encryption transmission process, and monitoring the integrity of a data packet and the compliance of a transmission channel; the receiving end executes secondary detection before archiving, and verifies the compatibility of the storage qualification and the metadata; and finally, archiving and generating an encrypted secret-related handover detection log. According to the method, through full-process and multi-dimensional automatic detection and monitoring, closed-loop safety management of the secret-related electronic file transfer process is realized, the safety and compliance of transfer operation are remarkably improved, and the risk of secret leakage is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security, and specifically relates to a detection method and system for the transfer of electronic archives in a classified network environment. Background Technology

[0002] In classified organizations, the transfer of electronic records is a critical business process. These records involve state or commercial secrets, and the transfer must comply with relevant regulations and be carried out within a segregated network.

[0003] Existing technologies cannot meet the specific needs of electronic record transfer in classified network environments and have limitations. General technologies only focus on the integrity and format of the records, without addressing the qualification verification of personnel and equipment, which may lead to the risk of leakage. Classified network data security technologies emphasize encryption and isolation, but do not cover compliance verification throughout the entire transfer process, which may lead to violations. Electronic record classification detection technologies can only perform static classification level identification and lack real-time interception capabilities, requiring additional processing after unauthorized transfers and increasing risks.

[0004] Therefore, a new detection method and system are needed to achieve full-process, multi-dimensional detection before and after the handover, ensuring safety and compliance. Summary of the Invention

[0005] This invention aims to address the lack of full-process compliance testing in existing technologies when transferring electronic records in a classified network environment.

[0006] Therefore, the present invention provides a method for detecting the transfer of electronic files in a classified network environment. The method is executed in a physically isolated classified network environment and includes the following steps:

[0007] Pre-transfer detection steps: Before initiating the electronic file transfer process at the transfer initiator, multiple pre-detections are automatically executed, including entity confidentiality qualification detection, file confidentiality compliance detection, and environment compliance detection. Specifically, the entity confidentiality qualification detection checks the matching between the operator's identity, operator confidentiality qualifications, and the registration status of the operating equipment and the confidentiality level of the electronic files to be transferred; the file confidentiality compliance detection checks the integrity of the confidentiality identification of the electronic files to be transferred, the consistency of the confidentiality level with the approval form, and the validity of the confidentiality period; the environment compliance detection checks whether the network environment, peripheral connection status, and audit software operation status of the transfer initiator comply with confidentiality regulations. If any pre-detection fails, a warning is generated and the transfer process is blocked.

[0008] Real-time dynamic detection steps during transmission: After all pre-detections pass, the encrypted transmission of the electronic file is initiated, and data packet integrity detection and transmission channel compliance monitoring are performed in real time during the transmission process; the data packet integrity detection includes fragmenting the encrypted data packet and periodically calculating the hash value of the fragment to compare with the initial value; the transmission channel compliance monitoring includes real-time monitoring of network parameters to detect unauthorized network switching, port opening, or bandwidth anomalies;

[0009] The receiving end performs a secondary inspection before archiving: After receiving and decrypting the data packet, the receiving end automatically performs a secondary inspection, including receiving end storage qualification inspection and metadata field compatibility inspection; the receiving end storage qualification inspection is used to confirm that the registration status, storage security level limit and remaining capacity of the receiving device meet the requirements; the metadata field compatibility inspection is used to compare the metadata of the electronic archives to be archived with the field library of the receiving end's archive management system;

[0010] Archiving and log traceability steps: After the secondary test is passed, the electronic file is archived to the designated directory of the receiving end, and an encrypted classified transfer test log is generated; the log contains information on the operator, equipment, file, test results and timestamps, and is synchronized to the classified audit system for centralized storage; if the secondary test fails, the file is returned and a return reason report is generated.

[0011] This invention also provides an electronic archive transfer detection system in a classified network environment, the system being deployed in a classified network environment, comprising:

[0012] The detection core module includes a multi-dimensional detection engine, an algorithm library that complies with national cryptographic management standards, and a result judgment unit. The detection core module is used to perform the pre-detection before the handover is initiated, the real-time dynamic detection during transmission, and the secondary detection before archiving at the receiving end.

[0013] The system integration and service interface layer serves as a secure data channel and functional collaboration component between the core detection module and external classified information systems. Through predefined secure communication protocols and interfaces, the system integration and service interface layer achieves the following:

[0014] The system can obtain the operator's identity information, biometric data, security level, and qualification validity period in real time from the classified personnel access control system.

[0015] Obtain the metadata field definitions and archive directory structure of the receiving end from the classified documents management system;

[0016] Send transmission channel status query requests and violation warning information to the classified network monitoring system, and receive terminal control command execution feedback from the system;

[0017] The classified key management system dynamically applies for data encryption and decryption keys for each transfer transaction and transmits the binding information between the key and the operation qualification.

[0018] Technical effects:

[0019] By constructing a multi-dimensional automated detection mechanism covering pre-transfer, transmission, and reception, a closed-loop management system is implemented for operators, equipment, archives, and the environment throughout the entire process. This effectively eliminates the risk of unauthorized transfers and leaks, ensuring the security and compliance of the transfer of classified electronic archives. Attached Figure Description

[0020] Figure 1 A flowchart illustrating the detection method for the transfer of electronic records in a classified network environment;

[0021] Figure 2 This is a system architecture diagram for detecting the transfer of electronic archives in a classified network environment. Detailed Implementation

[0022] Figure 1 This is a flowchart illustrating the detection method for the transfer of electronic records in a classified network environment. The following describes the detection method for the transfer of electronic records in a classified network environment.

[0023] This method is applicable to physically isolated classified intranet environments (such as enterprise classified intranets). The specific steps are as follows:

[0024] Step S1: Pre-detection before handover initiation.

[0025] After the transfer initiator (such as a classified computer operated by a classified personnel) logs into the "Classified Electronic Archives Transfer System" through a classified terminal, the system automatically triggers pre-detection, including the following three sub-detections:

[0026] Main body classified qualification test:

[0027] The system detects the "human-machine-permission" matching in the following ways:

[0028] Operator identity verification: The operator's biometric features are obtained through the fingerprint recognition module or face capture device integrated into the terminal and compared with the feature database in the confidential personnel access management system to confirm the authenticity of the identity;

[0029] Operator qualification verification: Retrieve the personnel's classification level (e.g., confidential, secret) and qualification validity period from the classified personnel access management system to determine whether they have the authority to operate the files to be transferred;

[0030] Verification of operating equipment registration: Read the MAC address and hard drive serial number of the operating equipment, compare them with the classified equipment management ledger, and confirm that the equipment is a registered classified terminal and that its storage level is not lower than the classification level of the archives to be transferred.

[0031] If any of the above verifications fails (such as expired personnel qualifications or unregistered equipment), the system will generate a "Violation of Main Qualification" warning and block the transfer process.

[0032] Document Confidentiality Compliance Testing:

[0033] The system automatically reads the classified metadata of the electronic files to be transferred (stored in the file header file or associated XML file) and performs the following checks:

[0034] Integrity of Classification Markings: Check whether the archives contain classification labels and classified watermarks (invisible digital watermarks).

[0035] Matching Classification with Approval Form: Retrieve the classified file transfer approval form submitted by the operator (which has been approved through the OA system) and compare whether the classification level of the file in the approval form is consistent with the classification level in the file metadata (e.g., if the approval form is "Secret", the file metadata must not be "Confidential").

[0036] Confidentiality period compliance: Check whether the confidentiality period of the file is within the validity period and matches the transfer period in the approval form (if the file has expired, it must first pass the confidential file declassification approval, otherwise it cannot be transferred).

[0037] If any of the above checks fails (such as missing classified watermark or mismatched classification level), the system will generate a "Document Compliance Violation" warning, prompting the operator to correct and resubmit.

[0038] Environmental compliance testing:

[0039] The system collects current classified network environment parameters through a terminal agent program and performs the following checks:

[0040] Transmission channel detection: Confirm whether the terminal is connected to a classified network and whether the IP address belongs to a classified network segment (e.g., 10.XXX.XXX.XXX).

[0041] Peripheral device access test: Check the terminal's USB, HDMI and other interfaces to ensure that no unregistered peripheral devices (such as USB flash drives, external hard drives, non-classified printers) are connected;

[0042] Audit software detection: Confirm that the terminal has enabled dedicated classified audit software and that the audit logs are being uploaded in real time.

[0043] If any test fails (such as connecting a non-classified USB drive or the auditing software not starting), the system will issue an "Environmental Compliance Violation" warning and lock the terminal operation until rectification is completed.

[0044] Step S2: Real-time dynamic detection during transmission.

[0045] If all three sub-detections in step S1 pass, the system will automatically initiate the electronic document transmission process and perform real-time dynamic detection:

[0046] Data packet integrity check:

[0047] The system uses the SM3 cryptographic hash algorithm to fragment the electronic archive data packets encrypted with the SM4 algorithm (the key is dynamically allocated by the classified key management system) (each fragment is 1MB). A fragment hash value is generated every 5 seconds and compared with the initial hash value pre-generated by the transfer initiator.

[0048] If the hash values ​​match, it is determined that the data packet has not been tampered with, and transmission continues.

[0049] If the hash values ​​are inconsistent, the transmission will be stopped immediately, a "data packet tampering" warning will be generated, and a warning message (including terminal IP, transmission time, and tampered fragment number) will be sent to the classified network monitoring system.

[0050] Transmission channel compliance monitoring:

[0051] The system monitors the network parameters of the transmission channel in real time (such as gateway address and routing table). If the following behaviors are detected, the transmission will be immediately interrupted:

[0052] The transmission channel did not use the designated classified network segment;

[0053] Unauthorized ports are open (such as ports 8080 and 22).

[0054] Abnormal bandwidth fluctuations (such as a sudden drop below 100kbps, which may indicate a data breach).

[0055] Step S3: Secondary detection before archiving at the receiving end.

[0056] After the receiving end (such as a classified archive management server or a classified terminal of the receiving unit) receives and decrypts all data packets, the system automatically triggers a secondary check to prevent archiving risks due to unqualified receiving end:

[0057] Receiver storage qualification test:

[0058] The system reads the storage medium information of the receiving device and compares it with the classified storage device registration database:

[0059] The receiving end has been confirmed to be a classified storage device;

[0060] Confirm that the upper limit of its storage classification level (e.g., classified equipment can store confidential and secret files) is not lower than the classification level of the files to be transferred;

[0061] Check if the remaining capacity meets the file storage and backup requirements (e.g., if the file size is 5GB, the remaining capacity should be no less than 10GB).

[0062] Metadata field compatibility check:

[0063] The system compares the classified metadata of the archives to be transferred (such as classification level, confidentiality period, and generating unit) with the field database of the classified archives management system at the receiving end:

[0064] Confirm that the metadata fields (such as "classification level") exist in the receiving system;

[0065] Confirm the metadata format (e.g., date format is "YYYY-MM-DD", security classification format is "Chinese characters + "). The "+duration period" is consistent with the receiving system.

[0066] If there are incompatible fields (such as the receiving end not having a "Confidential Watermark Identifier" field), the system will automatically generate a "Field Mapping Table" and prompt the administrator to configure it and then re-check.

[0067] Step S4: Archiving and Log Tracing.

[0068] If step S3 passes the test, the system will automatically archive the electronic file to the corresponding directory in the receiving end's classified file management system (e.g., "Secret-2024-Research and Development") and generate an archiving success notification.

[0069] The system will automatically generate a "Classified Transfer Detection Log", which includes the following:

[0070] Operator information (name, security classification);

[0071] Operating device information (MAC address, device number);

[0072] File information (file name, security classification, size);

[0073] Test results (pass / fail status of each step);

[0074] Timestamp (accurate to milliseconds).

[0075] Logs are encrypted using the SM4 algorithm and synchronized to the classified audit system. The content is immutable (using blockchain technology, each log entry generates a unique block identifier). Only personnel with "classified audit privileges" (such as the unit's confidentiality office administrator) can access the logs after authorization, and the retention period is no less than 5 years.

[0076] If step S3 fails the check, the system will return the file to the transfer initiator and generate a "Return Reason Report" (such as "Insufficient storage capacity at the receiving end" or "Incompatible metadata fields"), prompting the operator to coordinate with the receiving end to rectify the issues and then re-transfer the file.

[0077] Implementation example: Transfer of "confidential product design documents" by a company.

[0078] Implementation environment:

[0079] Classified network: A physically isolated classified internal network within an enterprise (IP network segment: XXXX.XXX.XXX.XXX);

[0080] The transfer initiator: a classified computer operated by a classified R&D personnel (registered, MAC address: XX-XX-XX-XX-XX-XX), which integrates a fingerprint recognition module;

[0081] Receiving end: The confidential storage server of the enterprise's archives department (registered, with the upper limit of the storage security level being confidential).

[0082] Linked systems: Classified personnel access control system, classified file management system, and classified network monitoring system.

[0083] Implementation steps:

[0084] (1) Pre-transfer detection (step S1):

[0085] Users log in to the classified electronic file transfer system via fingerprint and upload "secret-level product design documents" and the corresponding transfer approval form (which has been approved by two secret-level personnel via OA).

[0086] Entity's Classified Qualification Detection: The system compares the fingerprint with the access control system to confirm that the person has a classified operation qualification (valid until December 2026) and that the operating device is a registered classified terminal, thus matching the person, machine, and permissions.

[0087] Document Confidentiality Compliance Check: The system reads the file metadata and confirms that it contains "secret". The document is labeled with a "10-year" security classification and has an invisible watermark indicating confidentiality. The security classification of the approval form is consistent with that of the document, and the confidentiality period is valid.

[0088] Environmental compliance test: The system scanned the terminal to confirm that it was connected to a classified network, had no external USB flash drives, and that the audit software was running, thus the environment was compliant;

[0089] If the pre-detection passes, the system allows the handover to be initiated.

[0090] (2) Real-time dynamic detection during transmission (step S2):

[0091] The system obtains the SM4 encryption key from the classified key management system, encrypts the file data packet, and then begins transmission;

[0092] Every 5 seconds, a shard hash value is generated and compared with the initial value. No anomalies were found throughout the process.

[0093] Monitor the transmission channel in real time to confirm that the IP address is always in the 10.XXX.XXX.XXX network segment and that no unauthorized ports are open.

[0094] Transmission complete, no violation warnings.

[0095] (3) Secondary detection before archiving at the receiving end (step S3):

[0096] After receiving the data packet, the receiving server requests a decryption key from the key management system (by providing a filing certificate), and triggers a secondary detection after decryption.

[0097] Storage qualification test: The server was confirmed to be a classified device with 500GB of remaining capacity (file size 20GB), which meets the storage requirements;

[0098] Metadata compatibility test: Compare the file metadata with the field library of the document management system to confirm compatibility of fields such as "Secret Classification", "Design Unit", and "Confidentiality Period";

[0099] The second test passed, and the system indicated that the file could be archived.

[0100] (4) Archiving and log traceability (step S4):

[0101] The system archives the files to the "Confidential Documents Management System - Secret Level - 2024 - Product Design" directory;

[0102] Automatically generate encrypted logs, including: Operator: Zhang XX (Confidential), Device MAC: 00-XX-XX-XX-XX-XX, File Name: XXX Product Design Document, Test Result: All steps passed, Timestamp: 2025-06-15 09:12:35;

[0103] Logs are encrypted and synchronized to the classified audit system to ensure they cannot be tampered with.

[0104] Figure 2 This is a system architecture diagram for detecting the transfer of electronic archives in a classified network environment.

[0105] This invention provides a classified network electronic archive transfer detection system, the system being deployed in a classified network environment, comprising:

[0106] The core detection module includes a multi-dimensional detection engine, an algorithm library that complies with national cryptographic management standards, and a result judgment unit, which are used to perform the pre-detection before the handover is initiated, the real-time dynamic detection during transmission, and the secondary detection before archiving at the receiving end.

[0107] The system integration and service interface layer serves as a secure data channel and functional collaboration component between the core detection module and external classified information systems. This system integration and service interface layer achieves the following through predefined secure communication protocols and interfaces:

[0108] The system can obtain the operator's identity information, biometric data, security level, and qualification validity period in real time from the classified personnel access control system.

[0109] Obtain the metadata field definitions and archive directory structure of the receiving end from the classified documents management system;

[0110] Send transmission channel status query requests and violation warning information to the classified network monitoring system, and receive terminal control command execution feedback from the system;

[0111] The classified key management system dynamically applies for data encryption and decryption keys for each transfer transaction and transmits the binding information between the key and the operation qualification.

[0112] In one embodiment, the algorithm library stores hash algorithms, symmetric encryption algorithms, and classified watermark recognition algorithms, and the parameters of the algorithm library can be dynamically adjusted according to updates to relevant national standards.

[0113] In one embodiment, when the system integration and service interface layer detects a violation during the real-time dynamic detection step in the transmission, it pushes a warning message to the classified network monitoring system and triggers an emergency response operation performed by the classified network monitoring system. The emergency response operation includes interrupting the transmission, locking the violating terminal, or disconnecting its unauthorized peripheral connections.

[0114] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for detecting the transfer of electronic archives in a classified network environment, characterized in that, The method is performed in a physically isolated classified network environment and includes the following steps: Pre-transfer detection steps: Before initiating the electronic file transfer process at the transfer initiator, multiple pre-detections are automatically executed, including entity confidentiality qualification detection, file confidentiality compliance detection, and environment compliance detection. Specifically, the entity confidentiality qualification detection checks the matching between the operator's identity, operator confidentiality qualifications, and the registration status of the operating equipment and the confidentiality level of the electronic files to be transferred; the file confidentiality compliance detection checks the integrity of the confidentiality identification of the electronic files to be transferred, the consistency of the confidentiality level with the approval form, and the validity of the confidentiality period; the environment compliance detection checks whether the network environment, peripheral connection status, and audit software operation status of the transfer initiator comply with confidentiality regulations. If any pre-detection fails, a warning is generated and the transfer process is blocked. Real-time dynamic detection steps during transmission: After all pre-detections pass, the encrypted transmission of the electronic file is initiated, and data packet integrity detection and transmission channel compliance monitoring are performed in real time during the transmission process; the data packet integrity detection includes fragmenting the encrypted data packet and periodically calculating the hash value of the fragment to compare with the initial value; the transmission channel compliance monitoring includes real-time monitoring of network parameters to detect unauthorized network switching, port opening, or bandwidth anomalies; The receiving end performs a secondary inspection before archiving: After receiving and decrypting the data packet, the receiving end automatically performs a secondary inspection, including receiving end storage qualification inspection and metadata field compatibility inspection; the receiving end storage qualification inspection is used to confirm that the registration status, storage security level limit and remaining capacity of the receiving device meet the requirements; the metadata field compatibility inspection is used to compare the metadata of the electronic archives to be archived with the field library of the receiving end's archive management system; Archiving and log traceability steps: After the secondary test is passed, the electronic file is archived to the designated directory of the receiving end, and an encrypted classified transfer test log is generated; the log contains information on the operator, equipment, file, test results and timestamps, and is synchronized to the classified audit system for centralized storage; if the secondary test fails, the file is returned and a return reason report is generated.

2. The detection method for the transfer of electronic archives in a classified network environment according to claim 1, characterized in that, The aforementioned entity's classified qualification testing includes: The biometric features of operators are acquired by a biometric collection device integrated into a classified terminal and compared with the feature database in the classified personnel access control system to verify the authenticity of their identity. The confidentiality level and qualification validity period of the operator are retrieved from the confidential personnel access management system to determine whether the operator has the authority to operate the electronic files to be transferred. The hardware address information of the operating device is read and compared with the classified device management ledger to confirm that the device is a registered classified terminal and its storage level is not lower than the classification level of the electronic file to be transferred.

3. The detection method for the transfer of electronic archives in a classified network environment according to claim 1, characterized in that, The environmental compliance check is performed by a terminal agent program running on the handover initiator, including: Check whether the network segment of the current network connection is a designated classified network segment; Check the terminal's universal serial bus interface and audio / video interface to ensure that no unregistered external storage devices or output devices are connected. Confirm that the terminal has enabled the designated classified audit software and that the audit logs are being uploaded in real time.

4. The detection method for the transfer of electronic archives in a classified network environment according to claim 1, characterized in that, In the real-time dynamic detection step during transmission, the data packet integrity detection specifically includes: The electronic archive data packets encrypted with the symmetric encryption algorithm are processed in fragments using a hash algorithm. During transmission, the hash value of each fragment is periodically calculated and compared with the initial hash value of the corresponding fragment generated at the handover initiator. If any hash value does not match, transmission is immediately stopped and a data packet tampering warning is generated.

5. The detection method for the transfer of electronic archives in a classified network environment according to claim 2, characterized in that, In the real-time dynamic detection step during transmission, the key used for encrypted transmission is dynamically allocated by the classified key management system, and the key is bound to the qualification information of the operator in this handover operation; the receiving end needs to provide its equipment registration certificate to the classified key management system in order to apply for a decryption key.

6. The detection method for the transfer of electronic archives in a classified network environment according to claim 1, characterized in that, When the metadata field compatibility detection detects incompatibility, it automatically generates a field mapping suggestion table based on preset mapping rules or historical configurations. This suggestion table contains the correspondence between the source field and the target field. The system will only perform a re-detection after the administrator confirms and configures the table.

7. The detection method for the transfer of electronic archives in a classified network environment according to claim 1, characterized in that, After the classified transfer detection log is generated, it is encrypted using a symmetric encryption algorithm approved by the national cryptography management department, and at least one of the following methods is used to ensure the integrity and immutability of the log content: Digital signature-based technology; Write the logs to the blockchain evidence storage system to generate a unique block hash and timestamp; After completing the above integrity protection, the logs will be synchronized to the classified audit system for centralized storage and management.

8. A system for detecting the transfer of electronic archives in a classified network environment, used to implement the method according to any one of claims 1 to 7, characterized in that, The system is deployed in a classified network environment and includes: The detection core module includes a multi-dimensional detection engine, an algorithm library that complies with national cryptographic management standards, and a result judgment unit. The detection core module is used to perform the pre-detection before the handover is initiated, the real-time dynamic detection during transmission, and the secondary detection before archiving at the receiving end. The system integration and service interface layer serves as a secure data channel and functional collaboration component between the core detection module and external classified information systems. Through predefined secure communication protocols and interfaces, the system integration and service interface layer achieves the following: The system can obtain the operator's identity information, biometric data, security level, and qualification validity period in real time from the classified personnel access control system. Obtain the metadata field definitions and archive directory structure of the receiving end from the classified documents management system; Send transmission channel status query requests and violation warning information to the classified network monitoring system, and receive terminal control command execution feedback from the system; The classified key management system dynamically applies for data encryption and decryption keys for each transfer transaction and transmits the binding information between the key and the operation qualification.

9. The classified network electronic archives transfer detection system according to claim 8, characterized in that, The algorithm library stores hash algorithms, symmetric encryption algorithms, and classified watermark recognition algorithms, and the parameters of the algorithm library can be dynamically adjusted according to updates to relevant national standards.

10. The classified network electronic archives transfer detection system according to claim 8, characterized in that, When the system integration and service interface layer detects a violation during the real-time dynamic detection step in the transmission, it pushes a warning message to the classified network monitoring system and triggers an emergency response operation performed by the classified network monitoring system. The emergency response operation includes interrupting the transmission, locking the violating terminal, or disconnecting its unauthorized peripheral connections.

Citation Information

Patent Citations

  • Wisdom archive big data platform system

    CN106960405A

  • Four-property detection method and system applied to electronic archive system

    CN116304263A

  • Archive data security integration management system

    CN120257327A

  • Short message data encryption and secure transmission system

    CN120711382A

  • Data security transmission method based on digital archive multi-protection

    CN120880802A