Interactive management and control system and interactive management and control method for entities and digital archives with different security classifications

By constructing a system that includes servers and smart filing cabinets, and utilizing digital signature technology and multi-level authentication strategies to generate unique tokens and QR codes, the system addresses the shortcomings of security level configuration management in the digital and physical archive interaction control system, thereby improving both security and convenience.

CN121333767APending Publication Date: 2026-01-13NINGXIA TIANDI HUAYU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511693946.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In existing technologies, the interactive management and control systems for digital and physical archives are lacking in terms of configuration management and security verification at different security levels, making it difficult to achieve multi-level identity authentication and secure retrieval.

Method used

By constructing a system that includes servers, an interaction center, a unified database, a secure database, object storage, intelligent filing cabinets, and computers, and utilizing digital signature technology and multi-level authentication strategies, a unique token is generated and a QR code is created, enabling secure retrieval of files with different security levels.

Benefits of technology

It enables security verification and comprehensive interactive collaborative management of archives with different security levels, improving the security and convenience of archive management and meeting the authentication needs of managers at different levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333767A_ABST
    Figure CN121333767A_ABST
Patent Text Reader

Abstract

The invention provides an interactive management and control system and an interactive management and control method for entities and digital archives with different security classifications, which relate to the field of archive management and comprise a server, an interactive center, interactive terminal equipment, an intelligent archive cabinet, an entity archive management system, a computer, a digital archive management system, configuration entities and digital two-dimensional codes. An interaction center interacts with multiple devices and a system, a management user scans a code through an interaction terminal device and sends an initial request, and the interaction terminal device executes a first authentication program and / or executes authentication of a second authentication program through an intelligent file cabinet / computer and sends a first request and / or a second request. After the interaction center verifies the multiple requests and meets the corresponding security level authentication strategies, a target archive calling instruction is sent to the entity / digital archive management system to implement corresponding calling, and through multi-security level authentication strategy configuration and execution and matching of an authentication program, and in combination with an interaction management and control method, the multi-security level authentication strategy configuration is realized; and interactive access and security verification calling of multi-security-level numbers and entity archives are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of archival management technology, specifically to an interactive management system and method for physical and digital archives of different security classifications. Background Technology

[0002] As enterprises of all types and sizes gradually develop, the confidentiality of data and related access security become increasingly important. The interactive access and management of digital and physical archives also become increasingly crucial, mainly reflected in the following aspects:

[0003] 1. Highly confidential files, corresponding to the interactive management and retrieval of digital and physical files, require very high management requirements. They usually require the exclusive authority of the company's management, especially the chairman, to access, view, and manage them. This can be achieved through dedicated terminals and biometric authentication such as facial recognition and fingerprints, supplemented by password verification on the operating end such as filing cabinets and computers. This is an important aspect of security enhancement.

[0004] 2. The interactive management and retrieval of digital and physical archives with progressively decreasing confidentiality requires the appropriate allocation of management personnel with relatively reduced job levels. This involves using identity and password verification with varying degrees of reduced security requirements to retrieve digital and physical archives with correspondingly lower confidentiality levels. This should be supplemented by verification and judgment using professional terminals or operating devices such as filing cabinets or computers, which also presents a need to enhance security.

[0005] 3. With the gradual development of electronic devices in today's society, traditional PDAs / dedicated barcode scanning management devices are becoming less secure and comprehensive than smart devices such as smartphones in terms of the security and comprehensiveness of identity and password authentication procedures for management personnel in terms of barcode scanning for interactive management and retrieval of digital and physical files. To improve the security of file management, it is necessary to verify the dedicated / authorized smart devices of managers at different levels and to implement more stringent identity authentication procedures for file access and management.

[0006] 4. Furthermore, considering specific usage scenarios, modern enterprises / companies have increasingly higher demands for the corresponding storage and retrieval of digital and physical archives. This requires a set of interactive management systems and methods that configure different security level authentication strategies and corresponding multi-level identity authentication to enable the mutual retrieval of different types of archives and achieve the implementation of such systems. By configuring different security levels of identity and password verification procedures for the retrieval of archives with different security levels, retrieval can be performed after verification at different security levels for different confidentiality levels. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention provides an interactive management system and method for physical and digital archives with different security levels, solving the problems of lacking different security level configuration management and security verification, secure retrieval, and comprehensive interactive collaborative management in existing technologies for interactive management of digital and physical archives.

[0008] To achieve the above objectives, the present invention provides the following technical solution: an interactive management system and method for entities and digital archives of different security levels, comprising four aspects.

[0009] Firstly, this invention proposes an interactive management and control system for entities and digital archives of different security levels;

[0010] It includes servers and built-in interaction center, unified database, secure database, object storage, intelligent filing cabinets and physical file management system, computer and digital file management system, interactive terminal equipment, and the interaction center connects with each device and system network to realize signal interaction and file management and deploy API services;

[0011] The interaction center executes the configuration process: it records the correspondence between digital and physical archives through a unified database, configures different security levels and multi-level preset authentication strategies and procedures for the target archives; it generates a unique token for digital and physical archives, associates the target archive's type, ID, security level, and storage location, and stores it in the unified database; it generates digital and physical QR codes based on the corresponding archive type tokens and configures them in computers and smart filing cabinet compartments.

[0012] The interaction center executes the request verification procedure, and the API service verifies the initial request, the first request, and / or the second request.

[0013] The initial, first, and second requests are authentication requests sent based on digital signature technology after the authentication process has been completed by the corresponding device.

[0014] The interactive terminal device scans the code and sends an initial request to the API service. After verification, the API service obtains the security level of the target file from the unified database based on the Token and matches it with the preset authentication policy. According to the authentication procedure, it sends an authentication instruction to the interactive terminal device and / or smart file cabinet / computer. The user executes the corresponding first and / or second authentication procedure and sends the first and / or second request to the API service and verifies the request. When it is determined that the preset authentication policy is satisfied, the retrieval procedure for the target file is implemented.

[0015] The retrieval process includes API service commands for the digital / physical file management system to retrieve and display digital files according to the target file storage location, and to control the opening of the smart file cabinet compartments where physical files are located.

[0016] The interaction center is configured with audit logs to record scanning, access, and result feedback information.

[0017] Preferably, each secure and legitimate interactive terminal device has a pre-installed unique device digital certificate, and the identifier corresponding to each device and the corresponding digital certificate public key are stored in the security database;

[0018] The request verification process executed by the interaction center includes the initial request verification process:

[0019] The interactive terminal device scans the QR code and sends an initial request based on digital signature technology to the API service. This includes dynamically generating a high-strength random number and the current timestamp through the interactive terminal device, and using its pre-installed digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and the token contained in the QR code. This signature is then combined with the device identifier to form an initial request which is sent to the API service.

[0020] The API service receives an initial request, verifies that the timestamp is within the allowed time window, retrieves the corresponding digital certificate public key from the network connection's security database based on the device identifier in the initial request, and recalculates the signature of the random number, timestamp, and token in the initial request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the initial request. If the comparison result is consistent, it determines that the interactive terminal device conforms to the security device standard for interactive retrieval and generates a valid declaration of the interactive terminal device; and sends a first authentication instruction to the interactive terminal device and / or sends a second authentication instruction to the computer / intelligent filing cabinet according to the preset authentication policy.

[0021] The request verification process executed by the interaction center includes a first request verification process:

[0022] After receiving the first authentication instruction sent by the API service, the interactive terminal device verifies the preset password for the interactive terminal device of the management user and generates a first authentication program success declaration after the password verification is successful. Then, the interactive terminal device dynamically generates a high-strength random number and the current timestamp, and uses its internally preset digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and first authentication program success declaration. This signature is then combined with the device identifier to form a first request and sent to the API service.

[0023] When the API service receives the first request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the security database of the network connection based on the device identifier in the first request. Then, it recalculates the signature of the random number, timestamp, and first authentication program success declaration in the first request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the first request. If the comparison result is consistent, the first authentication program success declaration generated by the interactive terminal device is determined to be valid.

[0024] Each secure and legitimate computer and intelligent filing cabinet is pre-installed with a unique device digital certificate, and the identifier and corresponding digital certificate public key of each device are stored in the security database.

[0025] The request verification process executed by the interaction center includes a second request verification process:

[0026] After receiving the second authentication instruction sent by the API service, the computer / smart filing cabinet verifies the password set by the computer / smart filing cabinet and generates a second authentication program success declaration after the password verification is successful. Then, the computer / smart filing cabinet dynamically generates a high-strength random number and the current timestamp, and uses a preset digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and second authentication program success declaration. This signature is then combined with the device identifier to form a second request and sent to the API service.

[0027] When the API service receives the second request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the security database of the network connection based on the device identifier in the second request. Then, it recalculates the signature of the random number, timestamp, and successful second authentication program declaration in the second request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the second request. If the comparison result is consistent, the successful second authentication program declaration generated by the computer / intelligent filing cabinet is determined to be valid.

[0028] The interaction center executes a request verification procedure, whereby the API service verifies the initial request, the first request, and / or the second request. Based on the valid declaration of the interactive terminal device, the successful declaration of the first authentication procedure, and the successful declaration of the second authentication procedure, the center determines that the corresponding authentication procedures have been successfully completed and meet the preset authentication strategy, and then retrieves the target digital file / physical file accordingly.

[0029] Preferably, the first setting procedure for the unified database to distinguish and set multiple security levels for the retrieved target entity files and digital files is as follows: based on multiple sets of comparison relationships, different security levels are set for the target files retrieved in the multiple sets of comparison relationships, and the same security level is set for the entity files and digital files in any comparison relationship, so as to adapt to the security level requirements of the target digital and entity files retrieved based on the comparison relationship, to set different security level authentication strategies, corresponding security level authentication procedures, and implement retrieval procedures.

[0030] The second setting procedure for the unified database to distinguish and set multiple security levels for physical and digital archives is as follows: based on different types of archives in the same set of comparison relationships, different security levels are set for the target physical and digital archives to be retrieved in the several comparison relationships, so as to adapt to the security level requirements of different archive types based on digital and physical archives in the several comparison relationships, and to set different security level authentication strategies, corresponding security level authentication procedures, and subsequent retrieval procedures.

[0031] The security classification setting procedure is uniformly implemented by the interaction center, including: editing the security classification of multiple correspondence relationships, the security classification of physical files and digital files in several correspondence relationships in the management backend of the interaction center, and storing the edited security classification information as core fields in a structured format in the file table of the unified database to complete the security classification setting, including the first security classification, the second security classification, and the third security classification, and configuring the first security classification authentication strategy, the second security classification authentication strategy, and the third security classification authentication strategy corresponding to different security classifications, as well as the corresponding authentication procedures for different security classification authentication strategies.

[0032] Furthermore, the multi-level authentication strategy for files with different security classifications, and the authentication procedures that corresponding management users need to perform, include a first authentication procedure and / or a second authentication procedure, which include:

[0033] The first-level authentication strategy requires verification of two authentication procedures: a first authentication procedure verifying the password set on the interactive terminal device, and a second authentication procedure verifying the password set on the computer / smart filing cabinet. The administrator completes the first authentication procedure by verifying the password set on the interactive terminal device and sends a first request to the API service. The API service processes the first request and generates a successful declaration for the first authentication procedure. After the administrator completes the second authentication procedure by verifying the password set on the corresponding computer / smart filing cabinet, a second request is sent to the API service. The API service processes the second request and generates a successful declaration for the second authentication procedure. Based on the successful declarations for the first and second authentication procedures, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart filing cabinet compartment containing the target physical file according to its storage location to complete the retrieval.

[0034] The second level of authentication strategy requires a first authentication procedure that verifies the password set on the interactive terminal device. After the user completes the first authentication procedure by verifying the password set on the interactive terminal device, a first request is sent to the API service. The API service processes the first request and generates a first authentication procedure success declaration. Based on the first authentication procedure success declaration, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart file cabinet compartment where the target physical file is located to complete the retrieval.

[0035] The third level of security authentication strategy requires a second authentication procedure to verify the password set by the computer / smart filing cabinet. The management user completes the second authentication procedure by verifying the password set by the computer / smart filing cabinet and sends a second request to the API service. The API service processes the second request and generates a successful declaration of the second authentication procedure. Based on the successful declaration of the second authentication procedure, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart filing cabinet compartment where the target physical file is located to complete the retrieval.

[0036] Preferably, the intelligent filing cabinet is equipped with a password module, and the password includes face / fingerprint / numeric password. After receiving the second authentication instruction sent by the API service, the management user verifies at least one password through the password module and matches it with the corresponding decryption password inside the intelligent filing cabinet. After the match is correct, the second request is generated and sent to the API service. After the API service processes the second request and generates a valid result of the successful declaration of the second authentication procedure, it instructs the physical file management system connected to the network to electrically open the electric lock of the corresponding compartment of the filing cabinet according to the storage location of the target file to retrieve the target physical file and complete the retrieval procedure.

[0037] The computer is equipped with a password module, which includes a face / numeric password. After receiving the second authentication instruction sent by the API service, the administrator verifies at least one password through the password module and matches it with the corresponding decryption password stored in the computer. If the match is correct, the administrator executes the second request and sends it to the API service. After the API service processes the second request and generates a valid result declaring the second authentication process successful, it instructs the network-connected digital file management system to display the file content of the target digital file according to the storage location of the target file and complete the retrieval process.

[0038] Preferably, each compartment of the intelligent filing cabinet is independently equipped with an electric lock and a door magnetic sensor. The electric lock and door magnetic sensor of any compartment are independently connected to different I / O control ports of the control module. The control module controls and manages the electric lock and door magnetic sensor of any compartment through any I / O control port.

[0039] When the physical file management system executes the target physical file retrieval procedure, the control module sends an unlocking command to the electric lock of the target compartment through the I / O control port, driving it to unlock electrically. After unlocking, a spring installed inside the compartment opens the compartment door. Then, the door magnetic sensor detects that the compartment door is open and sends a mechanical opening signal to the control module through its corresponding I / O control port. Based on the mechanical opening signal, the control module determines that the compartment is open and implements a locking control monitoring procedure for the I / O control port, including:

[0040] After the user opens the compartment door, they can perform operations on the physical file. After the operation is completed, the user manually closes the compartment door against the spring force. When the door magnetic sensor detects that the compartment door is closed, i.e., mechanically closed, it sends a mechanical closing signal to the control module through its corresponding I / O control port. After the control module receives the mechanical opening signal through the I / O control port and then receives the mechanical closing signal through the I / O control port again, it determines that the single target physical file retrieval is completed. It then sends a locking command to the electronic lock of the compartment through the I / O control port and drives it to electrically lock to completely lock the compartment door containing the target physical file.

[0041] The intelligent filing cabinet's physical filing management system and its control module, electric lock, and door magnetic sensor are connected to at least one stable power source and one backup power source for long-term continuous power supply. The physical filing management system is also connected to a rechargeable power source, which powers the control module, power monitoring module, and alarm module built into the physical filing management system. When the power monitoring module detects that the stable power source / backup power source is de-energized or the rechargeable power source's power level is below a preset threshold, it sends a signal to the control module, which then controls the alarm module to issue an alarm notification.

[0042] Preferably, the digital archives management system is configured with a retrieval system for managing digital archives;

[0043] When the interactive terminal device scans the entity QR code and the interactive center executes the request verification procedure, after the API service processes the first request and generates a valid result of the first authentication procedure success declaration, the interactive center sends a first confirmation information signal to the digital archive management system. The digital archive management system sends a retrieval signal to the retrieval system based on the first confirmation information signal, and the retrieval system displays the retrieval location of the target digital archive in the digital archive file management system, performs preliminary confirmation and provides the retrieval location of the digital archive, thereby realizing the display of the storage location of the target digital archive.

[0044] The retrieval system is also used to provide retrieval functions when managing users to retrieve specified digital files, and to provide corresponding digital QR codes after the retrieval to facilitate management users to scan the codes and ultimately obtain the target files.

[0045] Optionally, for file types that only have physical / digital files but no corresponding digital / physical files, when configuring a physical / digital QR code containing a unique token, the target file associated with the token is itself, and an ID, a first or second security level, and a storage location are set for it. The request verification procedure is executed through the interaction center, and the API service processes the initial request, the first request, and / or the second request to generate a valid declaration of the interactive terminal device, a valid result of the first authentication procedure success declaration, and / or a valid result of the second authentication procedure success declaration. Based on the declaration and the valid result, the retrieval procedure is executed to retrieve the target file with its own attributes from the digital file management system / intelligent file cabinet compartment.

[0046] Preferably, the digital file is stored in object storage connected to the interaction center network. After storage, the object storage returns a file access address. The interaction center saves the file access address and the corresponding Token information associated with the target digital file in a unified database. When a user retrieves the target digital file, the interaction center verifies and processes the first request and / or the second request via API service and generates a first authentication procedure success declaration and / or a second authentication procedure success declaration. Based on the Token information, the interaction center obtains the corresponding file access address and further retrieves the target digital file from the object storage based on the file access address. The file is then returned to the computer's digital file management system via API service for display.

[0047] The physical files are stored one by one in the corresponding compartment of the smart file cabinet. The compartment information of the specified physical files is edited by the physical file management system. The compartment editing information is sent to the interaction center in a structured format as a core field via the network and compared with the file table in the unified database. When the management user retrieves the corresponding target physical file, the first request and / or the second request are verified and processed by the API service and a first authentication procedure success declaration result and / or a second authentication procedure success declaration result is generated. The interaction center retrieves the corresponding compartment editing information according to the file table. The physical file management system is then instructed by the API service to open the compartment of the smart file cabinet according to the corresponding compartment editing information. The compartment editing information also points to the storage location of the target physical file.

[0048] The physical file management system sets up a grid configuration mapping table to uniquely bind the grid editing information of any grid to the I / O control ports of multiple sets of electric locks and door magnetic sensors connected to the control module. When the physical file management system executes the retrieval of a target physical file, it uses the grid configuration mapping table to instruct the control module to control the electric lock to unlock, the door magnetic sensor to provide feedback signals, and the electric lock to lock after the retrieval program is completed.

[0049] Secondly, this invention proposes an interactive management and control method for entities of different security levels and digital archives;

[0050] The interactive control method based on the interactive control system for entities and digital archives of different security levels as described in the first aspect includes the following steps:

[0051] S1: Digital archives are stored in the server's object storage, while physical archives are stored in the smart filing cabinet compartments. The interaction center executes a configuration program: It records the mapping relationship between digital and physical archives through a unified database, configures the archive security level and corresponding multi-level authentication strategies and first and / or second authentication procedures for the retrieved target archive; it generates a unique token for each archive and associates it with the type, ID, security level, and storage location of the retrieved target archive; based on the token, it generates corresponding digital and physical QR codes, which are then configured on the computer and in the smart filing cabinet compartments.

[0052] S11: The security classification of the target file is set through the first and second setting procedures;

[0053] S12: The storage location of target numbers and physical archives is managed through the retrieval system and grid editing information;

[0054] S2: The interaction center executes the request verification procedure, which is completed by the API service to verify the initial request, the first request, and / or the second request sent based on digital signature technology, including:

[0055] S21: The interactive terminal device scans the QR code and sends an initial request to the API service;

[0056] S22: After verifying the initial request, the API service obtains the security level of the target file and matches it with the preset authentication policy, then sends authentication instructions to multiple devices;

[0057] S23: Manage users to verify the first authentication procedure through interactive terminal devices and / or verify the second authentication procedure through computers / smart filing cabinets, and send the first request and / or the second request to the API service;

[0058] S24: The API service processes multiple requests and executes the target file retrieval procedure after determining that multiple authentication procedures have successfully declared their validity.

[0059] S3: Execute the retrieval procedure: API service command digital file management system / physical file management system retrieves and displays the target digital file / controls the opening of the smart file cabinet compartment where the target physical file is located based on the corresponding storage location;

[0060] S4: The interaction center is configured to record audit logs for scanning, access, and result feedback information.

[0061] Thirdly, the present invention proposes an intelligent device, comprising:

[0062] The system includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes these computer instructions to perform the interactive management method for different security levels of entities and digital archives as described in the second aspect.

[0063] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions, the computer instructions being used to cause a computer to execute the interactive management method for different security levels of entities and digital archives described in the second aspect.

[0064] This invention provides an interactive management system and method for entities and digital archives with different security levels. It has the following beneficial effects:

[0065] 1. This invention records the correspondence between digital and physical archives through a unified database, and configures the archive security level based on the correspondence or the archive type, and provides a multi-level authentication strategy and different combinations of the first authentication procedure and / or the second authentication procedure to verify the different retrieval identities and password authentications of the multi-level security archives. This facilitates the retrieval of first-level, second-level, and third-level security archives by the company / enterprise chairman, authorized / appointed managers at various levels, and other personnel, respectively, through authentication procedures. Different authentication procedures are set for different security levels of archives before retrieval is possible.

[0066] 2. This invention retrieves target physical / digital files by scanning QR codes. To meet the increasing demand for retrieving and using different types of files, the innovative interactive management system and methods automatically match the corresponding security level authentication strategy of the target file type and manage users to execute the corresponding first and / or second authentication procedures. The implementation effect, convenience, and security are all improved and guaranteed.

[0067] 3. By using a dedicated interactive terminal device for managing users, such as a smartphone, the security of retrieving target files is improved through verification via an initial request, a first request, and a second request from the operating terminal. The combination of multiple authentication procedures enhances the reasonable configuration of authentication strategies for files of different security levels and facilitates the implementation of appropriate retrieval verification methods for retrieving target files. Attached Figure Description

[0068] Figure 1 This is a schematic diagram of the overall structure of an interactive control system according to an embodiment of the present invention;

[0069] Figure 2 This is a schematic diagram illustrating the interaction effect between multiple devices in an interactive control system according to an embodiment of the present invention;

[0070] Figure 3 This is a schematic diagram illustrating the electrical connection effect between the control module and the electric lock according to an embodiment of the present invention;

[0071] Figure 4 This is a schematic diagram of the overall structure of an intelligent filing cabinet according to an embodiment of the present invention;

[0072] Figure 5 This is a schematic diagram of the structure of the electronically controlled lock in the compartment door of an intelligent filing cabinet according to an embodiment of the present invention;

[0073] Figure 6 This is a schematic diagram of the interactive control method according to an embodiment of the present invention;

[0074] Figure 7 This is a schematic diagram of the hardware structure of a smart device according to an embodiment of the present invention.

[0075] Among them, 100, Server; 110, Interaction Center; 111, API Service; 112, Unified Database; 113, Secure Database; 114, Object Storage; 115, Audit Log; 200, Interactive Terminal Device; 210, Unique Device Certificate for Interactive Terminal Device; 220, QR Code Scanning Module; 230, Password Setting Module; 300, Smart Filing Cabinet; 310, Unique Device Certificate for Smart Filing Cabinet; 320, Physical File Management System; 321, Control Module; 322, Power Monitoring Module; 323, Alarm Module; 33 0. Compartment door body; 331. Electric lock; 3311. Lock tongue; 3312. Locking latch; 332. Door magnetic sensor; 333. Physical QR code; 334. Spring; 341. Stable power supply; 342. Backup power supply; 343. Rechargeable power supply; 344. Automatic transfer switch; 350. Intelligent filing cabinet password module; 400. Computer; 410. Unique device certificate for computer; 420. Digital filing management system; 421. Retrieval system; 422. Digital QR code; 430. Computer password module; 440. Computer peripherals. Detailed Implementation

[0076] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0077] Example 1

[0078] like Figure 1-5 As shown, this embodiment of the invention provides an interactive management and control system for entities and digital archives with different security levels.

[0079] The interactive management and control system for physical and digital archives of different security levels includes a server 100 and a built-in interactive center 110, as well as a unified database 112, a secure database 113, and an object storage 114 connected to the interactive center 110 via a network. It also includes an intelligent filing cabinet 300 for storing and managing physical archives, a physical archive management system 320, a computer 400 and a digital archive management system 420, and an interactive terminal device 200. The interactive center (system) 110 is connected to each device and system via a network to achieve data signal interaction and archive management, and deploys API services 111. The interactive terminal device 200, such as a smartphone, is equipped with a QR code scanning function and is configured with identification passwords including fingerprint and facial biometric passwords. That is, the interactive terminal device 200 (smartphone) is equipped with a password setting module 230 and a QR code scanning function module 220 to implement related execution functions, and interacts with, verifies, and manages with the API services 111 of the interactive center 110 (system).

[0080] Interaction Center 110 executes the configuration procedure: It records the correspondence between digital and physical archives through the unified database 112, and configures the target archives for different security levels and multi-level preset authentication strategies, along with the corresponding required authentication procedures; it generates a unique token for both digital and physical archives, associates the target archive's type, ID, security level, and storage location, and stores it in the unified database 112; based on the corresponding archive tokens of different types, it generates corresponding digital and physical QR codes, which are configured in the computer 400 (e.g., the digital archive management system 420) and the smart file cabinet 300 compartments; the physical QR code 333 is printed and pasted into the corresponding smart file cabinet 300 compartment.

[0081] Interaction center 110 executes a request verification procedure, and API service 111 verifies the initial request, first request, and / or second request. The initial, first, and second requests are authentication requests sent based on digital signature technology after completing the authentication procedure through the corresponding device. This includes interactive terminal device 200 scanning a QR code and sending an initial request to API service 111. After verification, API service 111 obtains the target file's security level from unified database 112 based on the Token and matches it with a preset authentication policy. Based on the preset corresponding authentication procedure, it sends an authentication instruction to interactive terminal device 200 and / or smart file cabinet 300 / computer 400. It manages users to execute the first and / or second authentication procedures for the corresponding security level and sends the first and / or second requests to API service 111. This includes managing users to execute the first authentication procedure and send the first request through interactive terminal device 200, and / or managing users to execute the second authentication procedure and send the second request through computer 400 / smart file cabinet 300. API service 111 processes and verifies the requests. When it is determined that the preset authentication policy is met after all the corresponding authentication procedures are successfully completed, the target file retrieval procedure is implemented.

[0082] The retrieval procedure includes API service 111 instructing digital file management system 420 to retrieve and display the target digital file according to the target digital file storage location, or API service 111 instructing entity file management system 320 to control the intelligent file cabinet 300 where the target entity file is located to open and complete the retrieval.

[0083] The interaction center 110 is configured with audit log 115 to record scanning, access and result feedback information, which facilitates subsequent inspection and management of file retrieval records and improves the effectiveness of security supervision.

[0084] Each secure and legitimate interactive terminal device 200 is pre-installed with a unique device digital certificate 210, and the identifier corresponding to each device and the corresponding digital certificate public key are stored in the security database 113.

[0085] The request verification process executed by Interaction Center 110 includes the initial request verification process:

[0086] The interactive terminal device 200 scans the QR code and sends an initial request based on digital signature technology to the API service 111. This includes dynamically generating a high-strength random number and the current timestamp through the interactive terminal device 200, and using its pre-installed digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and the token contained in the QR code. The signature is then combined with the device identifier to form an initial request which is sent to the API service 111.

[0087] The API service 111 receives an initial request. If the timestamp is within the allowed time window, it retrieves the corresponding digital certificate public key from the network connection's security database 113 based on the device identifier in the initial request. Using the digital certificate public key, it recalculates the signature of the random number, timestamp, and token in the initial request according to the same algorithm and rules. The result is compared with the digital signature in the initial request. If the comparison is consistent, it determines that the interactive terminal device 200 meets the security device standard for interactive retrieval functions and generates a valid interactive terminal device declaration to verify the initial identity authentication of the management user. It then sends a first authentication command to the interactive terminal device 200 according to a preset authentication policy, and / or sends a second authentication command to the computer 400 / intelligent filing cabinet 300. The device identifier, such as the device ID or serial number of the interactive terminal device 200, is used by the API service 111 for corresponding indexing.

[0088] The request verification process executed by Interaction Center 110 includes a first request verification process:

[0089] After receiving the first authentication command sent by the API service 111, the interactive terminal device 200 verifies the password set for the management user and generates a first authentication program success declaration after the password verification is successful. Then, the interactive terminal device 200 dynamically generates a high-strength random number and the current timestamp, and uses its pre-set digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and first authentication program success declaration. This signature is then combined with the device identifier to form a first request and sent to the API service 111.

[0090] When the API service 111 receives the first request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the network connection security database 113 based on the device identifier in the first request. Then, it recalculates the signature of the random number, timestamp, and first authentication program success declaration in the first request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the first request. If the comparison result is consistent, the first authentication program success declaration generated by the interactive terminal device is determined to be valid.

[0091] Each secure and legitimate computer 400 and smart filing cabinet 300 is pre-installed with a unique device digital certificate, corresponding to a unique device digital certificate 410 for the computer 400 and a unique device digital certificate 310 for the smart filing cabinet 300. The identifier of each device and the corresponding digital certificate public key are stored in the security database 113. The smart filing cabinet 300 is an Internet of Things (IoT) device.

[0092] The request verification procedure executed by Interaction Center 110 includes a second request verification procedure:

[0093] After receiving the second authentication command sent by API service 111, the computer 400 / smart filing cabinet 300 verifies the password set by the computer 400 / smart filing cabinet 300 and completes the password verification. After the password verification is successful, a second authentication program success declaration is generated. Then, the computer 400 / smart filing cabinet 300 dynamically generates a high-strength random number and the current timestamp, and uses a preset digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and second authentication program success declaration. This signature is then combined with the device identifier to form a second request and sent to API service 111.

[0094] When the API service 111 receives the second request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the network connection's security database 113 based on the device identifier in the second request. Using the digital certificate public key, it recalculates the signature of the random number, timestamp, and successful second authentication declaration in the second request according to the same algorithm and rules. The result is compared with the digital signature in the second request. If the comparison result is consistent, the successful second authentication declaration generated by the computer 400 / intelligent filing cabinet 300 is deemed valid. The device identifier, such as the device ID or serial number of the computer 400 / intelligent filing cabinet 300, is used by the API service 111 for corresponding indexing.

[0095] The interaction center 110 executes a request verification procedure, and the API service 111 verifies the initial request, the first request, and / or the second request. Based on the valid declaration of the interactive terminal device, the successful declaration of the first authentication procedure, and the successful declaration of the second authentication procedure, it determines that the corresponding authentication procedures have been successfully completed and meet the preset authentication strategy, and then implements the corresponding retrieval of the target digital file / physical file.

[0096] When the interaction center 110 executes multiple request verification procedures, the API service 111 retrieves the public keys of digital certificates corresponding to multiple devices from the secure database 113 of the network connection, and recalculates the signatures of different data in multiple requests according to the same algorithm and rules. When the multiple devices perform local signature calculations on the relevant data using the preset private keys of digital certificates, the same algorithm and rules are used, such as hash algorithms. For more technical details, please refer to the relevant well-known technologies in the field. This invention will not elaborate further.

[0097] The first setting procedure for the unified database 112 to distinguish and set multiple security levels for the retrieved target entity files and digital files is as follows: based on multiple sets of comparison relationships, different security levels are set for the target files retrieved in the multiple sets of comparison relationships, and the same security level is set for entity files and digital files in any comparison relationship, so as to adapt to the security level requirements of the target digital and entity files retrieved based on the comparison relationship, to set different security level authentication strategies, corresponding security level authentication procedures, and implement retrieval procedures.

[0098] The second setting procedure for the unified database 112 to distinguish and set multiple security levels for the physical archives and digital archives is as follows: based on the different types of archives in the same set of comparison relationships, different security levels are set for the target physical archives and digital archives retrieved from the several comparison relationships, so as to adapt to the security level requirements of different archive types based on digital archives and physical archives in the several comparison relationships, to set different security level authentication strategies, corresponding security level authentication procedures, and subsequent retrieval procedures.

[0099] The security classification setting procedure is uniformly implemented by the interaction center 110, including: editing the security classification of multiple correspondence relationships, the security classification of physical files and digital files in several correspondence relationships in the management backend of the interaction center 110, and storing the edited security classification information as core fields in a structured format in the file table of the unified database 112 to complete the security classification setting, including the first security classification, the second security classification, and the third security classification, and configuring the first security classification authentication strategy, the second security classification authentication strategy, and the third security classification authentication strategy corresponding to different security classifications, as well as the corresponding authentication procedure standards for different security classification authentication strategies.

[0100] Furthermore, the multi-level authentication strategy for files of different security levels, and the authentication procedures that corresponding management users need to perform, include a first authentication procedure and / or a second authentication procedure, which include:

[0101] The first-level authentication strategy requires verification of two authentication procedures: a first authentication procedure verifying the password set on the interactive terminal device 200, and a second authentication procedure verifying the password set on the computer 400 / intelligent filing cabinet 300. The managing user completes the first authentication procedure by verifying the password set on the interactive terminal device 200 and sends a first request to the API service 111. The API service 111 processes the first request and generates a valid result declaring the first authentication procedure successful. After the managing user completes the second authentication procedure by verifying the password set on the corresponding computer 400 / intelligent filing cabinet 300, a second request is sent to the API service 111. The API service 111 processes the second request and generates a valid result declaring the second authentication procedure successful. Based on the valid results of the first and second authentication procedures, the API service 111 obtains the target digital file / target physical file information and instructs the digital file management system 420 / physical file management system 320 to display the target digital file / open the compartment of the intelligent filing cabinet 300 where the target physical file is located to complete the retrieval.

[0102] The second level of authentication strategy requires the verification of the password set by the interactive terminal device 200 in the first authentication process. After the management user completes the first authentication process by verifying the password set by the interactive terminal device 200, a first request is sent to the API service 111. The API service 111 processes the first request and generates a valid result declaring the first authentication process successful. Based on the valid result declaring the first authentication process successful, the API service obtains the target digital file / target physical file information and instructs the digital file management system 420 / physical file management system 320 to display the target digital file / open the compartment of the smart file cabinet 300 where the target physical file is located to complete the retrieval.

[0103] The third-level authentication strategy requires a second authentication procedure to verify the password set by the computer 400 / intelligent filing cabinet 300. The management user completes the first authentication procedure by verifying the password set by the computer 400 / intelligent filing cabinet 300 and sends a first request to the API service 111. The API service 111 processes the second request and generates a valid result declaring the second authentication procedure successful. Based on the valid result declaring the second authentication procedure successful, the API service 111 obtains the target digital file / target physical file information and instructs the digital file management system 420 / physical file management system 320 to display the target digital file / open the compartment of the intelligent filing cabinet 300 where the target physical file is located to complete the retrieval.

[0104] It is worth noting that the security levels and corresponding settings of the second and third security level authentication strategies limit the security level assignment of target digital files / target physical files according to different usage scenarios, and there is no certain proof that the security level of the second security level authentication strategy must be higher than that of the third security level authentication strategy; the pre-implementation procedure of the multiple security level authentication procedures is that the interaction center 110 verifies the initial request authentication; after the management user verifies the set password of the corresponding computer 400 to complete the second authentication procedure, the target is to retrieve the digital file; after verifying the set password of the corresponding smart file cabinet 300 to complete the second authentication procedure, the target is to retrieve the physical file.

[0105] The intelligent filing cabinet 300 is equipped with a password module 350, and the password includes face / fingerprint / numeric password. After receiving the second authentication instruction sent by API service 111, the management user verifies at least one password through the password module 350 and matches it with the corresponding decryption password built into the intelligent filing cabinet 300. After a correct match, a second request is generated and sent to API service 111. After API service 111 processes the second request and generates a valid result of the successful declaration of the second authentication procedure, it instructs the network-connected physical file management system 320 to electrically open the electric lock 331 of the corresponding compartment of the intelligent filing cabinet 300 according to the storage location of the target file to retrieve the target physical file and complete the retrieval procedure. The intelligent filing cabinet 300 is equipped with at least one password module 350 corresponding to face / fingerprint / numeric password, such as at least one of a face recognition module (camera), a fingerprint recognition module, and a numeric password input module, and is configured with corresponding verification and decryption information for matching verification.

[0106] The computer 400 is equipped with a password module 430, which includes a face / numeric password. After receiving the second authentication instruction sent by the API service 111, the administrator verifies at least one password through the password module 430 and matches it with the corresponding decryption password stored in the computer 400. If the match is correct, the administrator executes the second request and sends it to the API service 111. After the API service 111 processes the second request and generates a valid result of the successful declaration of the second authentication process, it instructs the network-connected digital file management system 420 to display the file content of the target digital file according to the storage location of the target file and complete the retrieval process. The password module 430 of the computer 400 verifies the password through the face recognition camera module / numeric password input module. At the same time, the computer 400 stores relevant preset face information / password and matches it with face recognition information / input information for verification. The numeric password is entered by the administrator through the computer external device 440 in a pop-up window as needed.

[0107] refer to Figure 3Each compartment of the intelligent filing cabinet 300 is independently equipped with an electronic lock 331 and a door magnetic sensor 332. The electronic lock 331 and door magnetic sensor 332 of any compartment are independently connected to different I / O control ports of the control module 321. The control module 321 controls and manages the electronic lock 331 and door magnetic sensor 332 of any compartment through any I / O control port.

[0108] When the physical file management system 320 executes the target physical file retrieval procedure, the control module 321 sends an unlocking command to the electric lock 331 of the target compartment through the I / O control port, driving it to unlock electrically. After unlocking, the spring 334 installed inside the compartment opens the compartment door 330. Then, the door magnetic sensor 332 of the compartment detects that the compartment door 330 is open and sends a mechanical opening signal to the control module 321 through its corresponding I / O control port. Based on the mechanical opening signal, the control module 321 determines that the compartment is open and implements a locking control monitoring procedure for the I / O control port, including:

[0109] After the user opens the door 330, they can perform operations on physical files. After the operation is completed, the user manually closes the door 330 against the spring force of the spring 334. When the door magnetic sensor 332 detects that the door 330 is closed (i.e., mechanically closed), it sends a mechanical closing signal to the control module 321 through its corresponding I / O control port. After receiving the mechanical opening signal and the mechanical closing signal through the I / O control port, the control module 321 determines the single target physical file retrieval. Upon completion of the operation, a locking command is sent to the electronic lock 331 of the compartment via the I / O control port, driving it to electrically lock and completely secure the door 330 of the compartment containing the target physical file. The control module 321 outputs high-level / low-level signals to a dedicated drive circuit through multiple I / O control ports, which controls the electronic lock 331 to perform unlocking / locking actions. The electronic lock 331 is selected as a power-off locking type, and the high-level output signal controls the unlocking of the electronic lock 331.

[0110] refer to Figure 5The control module 321 controls the electronic lock 331 to lock / unlock by extending the bolt 3311 into / out of the corresponding latch 3312. The electronic lock 331 and latch 3312 are preferentially installed on the cabinet compartment and the cabinet compartment door 330 respectively to lock the cabinet compartment door 330 to the cabinet compartment. The electronic lock 331 is an electronic lock, and the relevant mechanical structure will not be described in detail in this invention. The spring 334 can be replaced and installed inside the cabinet compartment. When the cabinet compartment door 330 is mechanically closed, the spring 334 uses appropriate compression force to resist the cabinet compartment door 330 so that the cabinet compartment door 330 can be opened after unlocking. At the same time, the appropriate selection and installation position of the spring 334 ensures that the spring force of the spring 334 is not significantly damaged when the cabinet compartment door 330 is manually closed or when the cabinet compartment door 330 is locked for a long time.

[0111] The intelligent filing cabinet 300's physical filing management system 320, its control module 321, electric lock 331, and door magnetic sensor 332 are connected to at least one stable power supply 341 (such as an online uninterruptible power supply, online UPS) with AC power input and one backup power supply 342 (such as a generator) for long-term continuous power supply. The stable power supply 341 and the backup power supply 342 are electrically connected by an automatic transfer switch (ATS) 344, which automatically starts the generator to supply power when the stable power supply 341 fails. The physical filing management system 320 is also connected to a rechargeable power supply 343 (such as a battery), which supplies power to the built-in control module 321, power monitoring module 322, and alarm module 323. When the power monitoring module 322 detects that either the stable power supply 341 or the backup power supply 342 has lost power or the rechargeable power supply 343's power level is below a preset threshold, it sends a signal to the control module 321, which then controls the alarm module 323 to issue an alarm prompt, facilitating timely maintenance and charging of the stable power supply 341, the backup power supply 342, and the rechargeable power supply 343 by the management user.

[0112] The control module 321, power monitoring module 322, and alarm module 323 are placed in the intelligent filing cabinet 300. For example, if they are placed inside the password module 350 of the intelligent filing cabinet, although not shown in the figure, their placement inside can still be understood as reasonable and effective.

[0113] The digital archive management system 420 is configured with a retrieval system 421 for managing digital archives;

[0114] When the interactive terminal device 200 scans the physical QR code 333 and the interactive center 110 executes the request verification procedure, after the API service 111 processes the first request and generates a valid result of the first authentication procedure success declaration, the interactive center 110 sends a first confirmation information signal to the digital archive management system 420. The digital archive management system 420 sends a retrieval signal to the retrieval system 421 based on the first confirmation information signal, and the retrieval system 421 displays the retrieval location of the target digital archive in the digital archive file management system, performs preliminary confirmation and provides the retrieval location of the digital archive, thereby realizing the display of the storage location of the target digital archive.

[0115] The retrieval system 421 is also used to provide retrieval functions when managing users to retrieve specified digital files, and is also used to provide corresponding digital QR codes 422 after retrieval to facilitate user scanning. The digital QR codes 422 are placed in the digital file management system 420 or further placed in the retrieval system 421, and are used to ultimately obtain the target file. The retrieval function of the retrieval system 421 only displays the relevant field information of the target file, especially for the target file with a high level of confidentiality, it provides a simplified information display.

[0116] As an optional embodiment, for type files that only have physical / digital files but no corresponding digital / physical files, when configuring a physical QR code 333 / digital QR code 422 containing a unique token, the target file associated with the token is itself, and it is assigned an ID, a first or second security level, and a storage location. The request verification procedure is executed through the interaction center 110, and the API service 111 processes the initial request, the first request, and / or the second request and generates a valid declaration of the interactive terminal device, a valid result of the first authentication procedure success declaration, and / or a valid result of the second authentication procedure success declaration. Based on the declaration and the valid result, the retrieval procedure is executed to retrieve the target file with its own attributes from the digital file management system 420 / the smart file cabinet 300 compartment. This implementation setting also explains the scenario where scanning the digital QR code 422 and the physical QR code 333 corresponds to the digital file and physical file, respectively, when used to retrieve the corresponding target file.

[0117] In some highly confidential digital and physical archives, it is not common to convert between archive types for storage and only save the original archive. In this case, after storing the archive of the appropriate type, such as highly confidential physical or digital archives, it is necessary to verify the first level of security authentication policy before retrieval to complete a more secure access and retrieval process.

[0118] In a preferred embodiment, the digital file is stored in object storage 114 connected to the interaction center 110 via a network. After storage, object storage 114 returns a file access address (URL). The interaction center 110 associates the file access address (URL) with the Token information of the corresponding target digital file in a unified database 112. When a user retrieves the corresponding target digital file, after the API service 111 verifies and processes the first request and / or the second request and generates a valid result of the first authentication procedure success declaration and / or the second authentication procedure success declaration, the interaction center 110 obtains the corresponding file access address based on the Token information and further retrieves the target digital file from object storage 114 based on the file access address. The file is then returned to the digital file management system 420 of computer 400 via API service 111. The object storage 114 may be, for example, Alibaba Cloud OSS, Tencent Cloud COS, or Huawei Cloud OBS.

[0119] The physical files are stored one by one in any corresponding compartment of the intelligent file cabinet 300. The compartment information of the built-in specified physical files is edited by the physical file management system 320, and the compartment editing information is sent to the interaction center 110 in a structured format via the network as the core field. It is then compared with the file table in the unified database 112. When the management user retrieves the corresponding target physical file, after the API service 111 verifies and processes the first request and / or the second request and generates a valid result of the first authentication procedure success declaration and / or the second authentication procedure success declaration, the interaction center 110 retrieves the corresponding compartment editing information according to the file table. The API service 111 instructs the physical file management system 320 to open the compartment of the intelligent file cabinet 300 according to the corresponding compartment editing information. The compartment editing information also points to the storage location of the target physical file.

[0120] The physical file management system 320 sets up a grid configuration mapping table to uniquely bind the grid editing information of any grid to the I / O control port of the control module 321, which is connected to multiple sets of electric locks 331 and door magnetic sensors 332. When the physical file management system 320 executes the retrieval of the target physical file, it uses the grid configuration mapping table to instruct the control module 321 to control the electric lock 331 to unlock and the door magnetic sensor 332 to provide a feedback signal (mechanical opening signal) through the corresponding I / O control port. After the retrieval program is completed, it uses the feedback signal (mechanical closing signal) of the door magnetic sensor 332 to control the electric lock 331 to lock again.

[0121] In the interaction center 110 (system) of the present invention, the API service 111 interacts with the interactive terminal device 200 to receive initial requests, first requests, etc. sent by the interactive terminal device 200 via the network, and to send authentication instructions to the interactive terminal device 200. The API service 111 interacts with the security database 113 to retrieve multiple digital certificate public keys and perform digital signature work. The API service 111 interacts with the unified database 112 and obtains information such as file security level and matching preset authentication policies, authentication procedures, and the storage location of the target file. The API service 111 interacts with the object storage 114 and, through the file access address (URL) obtained from the unified database 112, initiates a retrieval of the target digital file from the object storage 114 via the interaction center 110. The API service 111 interacts with the computer 400 to send authentication commands and receive second requests; the API service 111 establishes a connection with the digital file management system 420, and instructs the digital file management system 420 of the computer 400 to obtain and display the target digital file according to its storage location, and the digital file management system 420 implements the management and operation requirements of the target digital file; the API service 111 interacts with the intelligent file cabinet 300 to send authentication commands and receive second requests; the API service 111 establishes a connection with the physical file management system 320, and instructs the physical file management system 320 to control the opening of the compartment of the intelligent file cabinet 300 where the target physical file is located according to the storage location of the target file (including compartment editing information).

[0122] Example 2

[0123] Embodiment 2 of this invention proposes an interactive management method for entities with different security levels and digital archives; see reference Figure 6 This includes the following steps:

[0124] S1: Digital archives are stored in object storage 114 on server 100, and physical archives are stored in the smart filing cabinet 300 compartments; the interaction center 110 executes a configuration program: recording the correspondence between digital and physical archives through a unified database 112, configuring the archive security level and corresponding preset multi-level authentication strategies and corresponding first and / or second authentication procedures for the retrieved target archives; generating a unique token for each archive and associating it with the type, ID, security level, and storage location of the retrieved target archive; generating corresponding digital and physical QR codes based on the token and configuring them in the computer 400 and the smart filing cabinet 300 compartments:

[0125] S11: The security classification of the archive is set through the first setting procedure and the second setting procedure;

[0126] The first setting procedure and the second setting procedure, based on multiple sets of comparison relationships and the file type in any comparison relationship, respectively set different security levels for digital files and physical files in multiple sets of comparison relationships and several comparison relationships, and configure authentication strategies and authentication procedures corresponding to different security levels;

[0127] S12: The storage location of digital and physical archives is managed through the retrieval system 421 and grid editing information;

[0128] The retrieval system 421 is used to display the retrieval location of the target digital file in the digital file management system 420, and is also used to provide retrieval function when managing users to retrieve specified digital files and to provide a corresponding digital QR code 422 after the retrieval to facilitate management users to scan the code;

[0129] The grid editing information of the target entity file is edited by the entity file management system 320. The grid editing information is sent to the interaction center 110 in a structured format as a core field through the network. The grid editing information is compared with the file table stored in the same database. The entity file management system 320 is controlled to open the grid of the smart file cabinet 300 based on the grid editing information through the API service 111.

[0130] S2: Interaction center 110 executes the request verification procedure, which is completed by API service 111 for verifying the initial request, first request, and / or second request sent based on digital signature technology, including:

[0131] S21: Interactive terminal device 200 scans the QR code and sends an initial request to API service 111;

[0132] S22: After verifying the initial request, API service 111 obtains the security level of the target file and matches it with the preset authentication policy, and sends authentication instructions to multiple devices;

[0133] S23: The management user verifies the first authentication procedure through the interactive terminal device 200 and / or the computer 400 / intelligent filing cabinet 300 verifies the second authentication procedure, and sends the first request and / or the second request to the API service 111;

[0134] S24: The API service processes multiple requests and executes the target file retrieval procedure after determining that multiple authentication procedures have successfully declared their validity.

[0135] S3: Execute the retrieval procedure: API service 111 instructs the digital file management system 420 / physical file management system 320 to retrieve and display the target digital file / control the opening of the intelligent file cabinet 300 where the target physical file is located;

[0136] S4: The interaction center 110 configures the audit log 115 and records scanning, access and result feedback information; specifically, it also includes data operations such as managing user scanning and execution of multiple authentication procedures, previewing, retrieving and downloading target files.

[0137] It is worth noting that the above steps are predicated on the following: the server 100's built-in interactive center 110 (system) and the intelligent filing cabinet 300, the built-in physical filing management system 320, the computer 400, the built-in digital filing management system 420, and the interactive terminal device 200 are connected via a network to achieve data signal interaction and filing management. These details will not be elaborated further in the described steps. For specific implementation details of each step, please refer to the description and record in Implementation 1. Figures 1-5 This embodiment 2 will not be described in detail.

[0138] In addition, the notification of the scanning and first authentication process performed by the interactive terminal device 200 is sent through, for example, a dedicated APP set up for the corresponding smartphone, and the management user performs the verification through the scanning function module 220 and the password setting module 230.

[0139] Example 3

[0140] like Figure 7 As shown, Embodiment 3 of the present invention provides an intelligent device, including: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the interactive management and control method for entities of different security levels and digital archives in Embodiment 2.

[0141] Figure 7 This is a schematic diagram of the structure of a smart device provided in an optional embodiment of the present invention, such as... Figure 7 As shown, the intelligent device includes one or more processors 50, a memory 60, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the intelligent device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple intelligent devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 7 Take a processor 50 as an example.

[0142] Processor 50 may be a central processing unit, a network processor, or a combination thereof. Processor 50 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GPRS), or any combination thereof.

[0143] The memory 60 stores instructions executable by at least one processor 50 to cause the at least one processor 50 to perform the method shown in the above embodiments.

[0144] The memory 60 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the smart device. Furthermore, the memory 60 may include high-speed random access memory and non-transient memory, such as at least one disk storage device, flash memory device, or other non-transient solid-state storage device. In some alternative embodiments, the memory 60 may optionally include memory remotely located relative to the processor 50, which can be connected to the smart device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof. The memory 60 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk, or solid-state drive; the memory 60 may also include combinations of the above types of memory.

[0145] The smart device also includes an input device 70 and an output device 80. The processor 50, memory 60, input device 70, and output device 80 can be connected via a bus or other means. Figure 7 Taking the example of a connection between China and Israel via a bus.

[0146] Input device 70 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the smart device, such as a touchscreen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 80 may include display devices, auxiliary lighting devices (e.g., LEDs), and haptic feedback devices (e.g., vibration motors). The aforementioned display devices include, but are not limited to, liquid crystal displays, light-emitting diodes, displays, and plasma displays. In some optional embodiments, the display device may be a touchscreen.

[0147] Example 4

[0148] Embodiment 4 of the present invention also provides a computer-readable storage medium storing computer instructions for causing a computer to execute the interactive management method for different security levels of entities and digital archives in Embodiment 2. The methods described above according to embodiments of the present invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and subsequently stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that a computer, processor, microprocessor controller, or programmable hardware includes storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0149] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0150] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. An interactive management and control system for physical and digital archives of different security levels, characterized in that: It includes servers and built-in interaction center, unified database, secure database, object storage, intelligent filing cabinets and physical file management system, computer and digital file management system, interactive terminal equipment, and the interaction center connects with each device and system network to realize signal interaction and file management and deploy API services; The interaction center executes the configuration process: it records the correspondence between digital and physical archives through a unified database, configures different security levels and multi-level preset authentication strategies and procedures for the target archives; it generates a unique token for digital and physical archives, associates the target archive's type, ID, security level, and storage location, and stores it in the unified database; it generates digital and physical QR codes based on the corresponding archive type tokens and configures them in computers and smart filing cabinet compartments. The interaction center executes the request verification procedure, and the API service verifies the initial request, the first request, and / or the second request. The initial, first, and second requests are authentication requests sent based on digital signature technology after the authentication process has been completed by the corresponding device. The interactive terminal device scans the code and sends an initial request to the API service. After verification, the API service obtains the security level of the target file from the unified database based on the Token and matches it with the preset authentication policy. According to the authentication procedure, it sends an authentication instruction to the interactive terminal device and / or smart file cabinet / computer. The user executes the corresponding first and / or second authentication procedure and sends the first and / or second request to the API service and verifies the request. When it is determined that the preset authentication policy is satisfied, the retrieval procedure for the target file is implemented. The retrieval process includes API service commands for the digital / physical file management system to retrieve and display digital files according to the target file storage location, and to control the opening of the smart file cabinet compartments where physical files are located. The interaction center is configured with audit logs to record scanning, access, and result feedback information.

2. The interactive management and control system for entities and digital archives of different security levels according to claim 1, characterized in that: Each secure and legitimate interactive terminal device is pre-installed with a unique device digital certificate, and the identifier corresponding to each device and the corresponding digital certificate public key are stored in the security database. The request verification process executed by the interaction center includes the initial request verification process: The interactive terminal device scans the QR code and sends an initial request based on digital signature technology to the API service. This includes dynamically generating a high-strength random number and the current timestamp through the interactive terminal device, and using its pre-installed digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and the token contained in the QR code. This signature is then combined with the device identifier to form an initial request which is sent to the API service. The API service receives an initial request, verifies that the timestamp is within the allowed time window, retrieves the corresponding digital certificate public key from the network connection's security database based on the device identifier in the initial request, and recalculates the signature of the random number, timestamp, and token in the initial request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the initial request. If the comparison result is consistent, it determines that the interactive terminal device conforms to the security device standard for interactive retrieval and generates a valid declaration of the interactive terminal device; and sends a first authentication instruction to the interactive terminal device and / or sends a second authentication instruction to the computer / intelligent filing cabinet according to the preset authentication policy. The request verification process executed by the interaction center includes a first request verification process: After receiving the first authentication instruction sent by the API service, the interactive terminal device verifies the preset password for the interactive terminal device of the management user and generates a first authentication program success declaration after the password verification is successful. Then, the interactive terminal device dynamically generates a high-strength random number and the current timestamp, and uses its internally preset digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and first authentication program success declaration. This signature is then combined with the device identifier to form a first request and sent to the API service. When the API service receives the first request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the security database of the network connection based on the device identifier in the first request. Then, it recalculates the signature of the random number, timestamp, and first authentication program success declaration in the first request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the first request. If the comparison result is consistent, the first authentication program success declaration generated by the interactive terminal device is determined to be valid. Each secure and legitimate computer and intelligent filing cabinet is pre-installed with a unique device digital certificate, and the identifier and corresponding digital certificate public key of each device are stored in the security database. The request verification process executed by the interaction center includes a second request verification process: After receiving the second authentication instruction sent by the API service, the computer / smart filing cabinet verifies the password set by the computer / smart filing cabinet and generates a second authentication program success declaration after the password verification is successful. Then, the computer / smart filing cabinet dynamically generates a high-strength random number and the current timestamp, and uses a preset digital certificate private key to generate a digital signature for key request data including the random number, timestamp, and second authentication program success declaration. This signature is then combined with the device identifier to form a second request and sent to the API service. When the API service receives the second request and verifies that the timestamp is within the allowed time window, it retrieves the digital certificate public key corresponding to the device from the security database of the network connection based on the device identifier in the second request. Then, it recalculates the signature of the random number, timestamp, and successful second authentication program declaration in the second request using the digital certificate public key according to the same algorithm and rules. The result is compared with the digital signature in the second request. If the comparison result is consistent, the successful second authentication program declaration generated by the computer / intelligent filing cabinet is determined to be valid. The interaction center executes a request verification procedure, whereby the API service verifies the initial request, the first request, and / or the second request. Based on the valid declaration of the interactive terminal device, the successful declaration of the first authentication procedure, and the successful declaration of the second authentication procedure, the center determines that the corresponding authentication procedures have been successfully completed and meet the preset authentication strategy, and then retrieves the target digital file / physical file accordingly.

3. The interactive management and control system for entities and digital archives of different security levels according to claim 2, characterized in that: The first setting procedure for the unified database to distinguish and set multiple security levels for the retrieved target entity files and digital files is as follows: based on multiple sets of comparison relationships, different security levels are set for the target files retrieved in the multiple sets of comparison relationships, and the same security level is set for the entity files and digital files in any comparison relationship, so as to adapt to the security level requirements of the target digital and entity files retrieved based on the comparison relationship, to set different security level authentication strategies, corresponding security level authentication procedures, and implement retrieval procedures. The second setting procedure for the unified database to distinguish and set multiple security levels for physical and digital archives is as follows: based on different types of archives in the same set of comparison relationships, different security levels are set for the target physical and digital archives to be retrieved in the several comparison relationships, so as to adapt to the security level requirements of different archive types based on digital and physical archives in the several comparison relationships, and to set different security level authentication strategies, corresponding security level authentication procedures, and subsequent retrieval procedures. The security classification setting procedure is uniformly implemented by the interaction center, including: editing the security classification of multiple correspondence relationships, the security classification of physical files and digital files in several correspondence relationships in the management backend of the interaction center, and storing the edited security classification information as core fields in a structured format in the file table of the unified database to complete the security classification setting, including the first security classification, the second security classification, and the third security classification, and configuring the first security classification authentication strategy, the second security classification authentication strategy, and the third security classification authentication strategy corresponding to different security classifications, as well as the corresponding authentication procedures for different security classification authentication strategies.

4. The interactive management and control system for entities and digital archives of different security levels according to claim 3, characterized in that: The multi-level authentication strategy for files with different security classifications, and the authentication procedures that corresponding management users need to perform, include the first authentication procedure and / or the second authentication procedure, which include: The first-level authentication strategy requires verification of two authentication procedures: a first authentication procedure verifying the password set on the interactive terminal device, and a second authentication procedure verifying the password set on the computer / smart filing cabinet. The administrator completes the first authentication procedure by verifying the password set on the interactive terminal device and sends a first request to the API service. The API service processes the first request and generates a successful declaration for the first authentication procedure. After the administrator completes the second authentication procedure by verifying the password set on the corresponding computer / smart filing cabinet, a second request is sent to the API service. The API service processes the second request and generates a successful declaration for the second authentication procedure. Based on the successful declarations for the first and second authentication procedures, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart filing cabinet compartment containing the target physical file according to its storage location to complete the retrieval. The second level of authentication strategy requires a first authentication procedure that verifies the password set on the interactive terminal device. After the user completes the first authentication procedure by verifying the password set on the interactive terminal device, a first request is sent to the API service. The API service processes the first request and generates a first authentication procedure success declaration. Based on the first authentication procedure success declaration, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart file cabinet compartment where the target physical file is located to complete the retrieval. The third level of security authentication strategy requires a second authentication procedure to verify the password set by the computer / smart filing cabinet. The management user completes the second authentication procedure by verifying the password set by the computer / smart filing cabinet and sends a second request to the API service. The API service processes the second request and generates a successful declaration of the second authentication procedure. Based on the successful declaration of the second authentication procedure, the API service obtains the target digital file / target physical file information and instructs the digital file management system / physical file management system to display the target digital file / open the smart filing cabinet compartment where the target physical file is located to complete the retrieval.

5. The interactive management and control system for entities and digital archives of different security levels according to claim 4, characterized in that: The intelligent filing cabinet is equipped with a password module, and the password includes face / fingerprint / numeric password. After receiving the second authentication instruction sent by the API service, the management user verifies at least one password through the password module and matches it with the corresponding decryption password inside the intelligent filing cabinet. After the match is correct, the second request is generated and sent to the API service. After the API service processes the second request and generates a valid result of the successful declaration of the second authentication procedure, it instructs the physical file management system connected to the network to electrically open the electric lock of the corresponding compartment of the filing cabinet according to the storage location of the target file to retrieve the target physical file and complete the retrieval procedure. The computer is equipped with a password module, which includes a face / numeric password. After receiving the second authentication instruction sent by the API service, the administrator verifies at least one password through the password module and matches it with the corresponding decryption password stored in the computer. If the match is correct, the administrator executes the second request and sends it to the API service. After the API service processes the second request and generates a valid result declaring the second authentication process successful, it instructs the network-connected digital file management system to display the file content of the target digital file according to the storage location of the target file and complete the retrieval process.

6. The interactive management and control system for entities and digital archives of different security levels according to claim 5, characterized in that: Each compartment of the intelligent filing cabinet is independently equipped with an electric lock and a magnetic door sensor. The electric lock and magnetic door sensor of any compartment are independently connected to different I / O control ports of the control module. The control module controls and manages the electric lock and magnetic door sensor of any compartment through any I / O control port. When the physical file management system executes the target physical file retrieval procedure, the control module sends an unlocking command to the electric lock of the target compartment through the I / O control port, driving it to unlock electrically. After unlocking, a spring installed inside the compartment opens the compartment door. Then, the door magnetic sensor detects that the compartment door is open and sends a mechanical opening signal to the control module through its corresponding I / O control port. Based on the mechanical opening signal, the control module determines that the compartment is open and implements a locking control monitoring procedure for the I / O control port, including: After the user opens the compartment door, they can perform operations on the physical file. After the operation is completed, the user manually closes the compartment door against the spring force. When the door magnetic sensor detects that the compartment door is closed, i.e., mechanically closed, it sends a mechanical closing signal to the control module through its corresponding I / O control port. After the control module receives the mechanical opening signal through the I / O control port and then receives the mechanical closing signal through the I / O control port again, it determines that the single target physical file retrieval is completed. It then sends a locking command to the electronic lock of the compartment through the I / O control port and drives it to electrically lock to completely lock the compartment door containing the target physical file. The intelligent filing cabinet's physical filing management system and its control module, electric lock, and door magnetic sensor are connected to at least one stable power source and one backup power source for long-term continuous power supply. The physical filing management system is also connected to a rechargeable power source, which powers the control module, power monitoring module, and alarm module built into the physical filing management system. When the power monitoring module detects that the stable power source / backup power source is de-energized or the rechargeable power source's power level is below a preset threshold, it sends a signal to the control module, which then controls the alarm module to issue an alarm notification.

7. The interactive management and control system for entities and digital archives of different security levels according to claim 6, characterized in that: The digital archives management system is configured with a retrieval system for managing digital archives; When the interactive terminal device scans the entity QR code and the interactive center executes the request verification procedure, after the API service processes the first request and generates a valid result of the first authentication procedure success declaration, the interactive center sends a first confirmation information signal to the digital archive management system. The digital archive management system sends a retrieval signal to the retrieval system based on the first confirmation information signal, and the retrieval system displays the retrieval location of the target digital archive in the digital archive file management system, performs preliminary confirmation and provides the retrieval location of the digital archive, thereby realizing the display of the storage location of the target digital archive. The retrieval system is also used to provide retrieval functions when managing users to retrieve specified digital files, and to provide corresponding digital QR codes after the retrieval to facilitate management users to scan the codes and ultimately obtain the target files.

8. The interactive management and control system for entities and digital archives of different security levels according to claim 7, characterized in that: For file types that only have physical / digital files but no corresponding digital / physical files, when configuring a physical / digital QR code containing a unique token, the target file associated with the token is itself. An ID, a first or second security level, and a storage location are set for it. A request verification procedure is executed through the interaction center, and the API service processes the initial request, the first request, and / or the second request, generating a valid declaration of the interactive terminal device, a valid result of the first authentication procedure success declaration, and / or a valid result of the second authentication procedure success declaration. Based on the declaration and the valid result, a retrieval procedure is executed to retrieve the target file with its own attributes from the digital file management system / intelligent file cabinet compartment.

9. The interactive management and control system for entities and digital archives of different security levels according to any one of claims 1-8, characterized in that: The digital archive is stored in object storage connected to the interaction center network. After storage, the object storage returns a file access address. The interaction center associates the file access address with the Token information of the corresponding target digital archive in a unified database. When a user retrieves the corresponding target digital archive, the interaction center verifies and processes the first request and / or the second request via API service and generates a first authentication procedure success declaration and / or a second authentication procedure success declaration. Based on the Token information, the interaction center obtains the corresponding file access address and further retrieves the target digital archive from the object storage based on the file access address. The archive is then returned to the computer's digital archive management system via API service for display. The physical files are stored one by one in the corresponding compartment of the smart file cabinet. The compartment information of the specified physical files is edited by the physical file management system. The compartment editing information is sent to the interaction center in a structured format as a core field via the network and compared with the file table in the unified database. When the management user retrieves the corresponding target physical file, the first request and / or the second request are verified and processed by the API service and a first authentication procedure success declaration result and / or a second authentication procedure success declaration result is generated. The interaction center retrieves the corresponding compartment editing information according to the file table. The physical file management system is then instructed by the API service to open the compartment of the smart file cabinet according to the corresponding compartment editing information. The compartment editing information also points to the storage location of the target physical file. The physical file management system sets up a grid configuration mapping table to uniquely bind the grid editing information of any grid to the I / O control ports of multiple sets of electric locks and door magnetic sensors connected to the control module. When the physical file management system executes the retrieval of a target physical file, it uses the grid configuration mapping table to instruct the control module to control the electric lock to unlock, the door magnetic sensor to provide feedback signals, and the electric lock to lock after the retrieval program is completed.

10. An interactive control method for an interactive control system of entities with different security levels and digital archives as described in any one of claims 1-9, characterized in that: Includes the following steps: S1: Digital archives are stored in the server's object storage, while physical archives are stored in the smart filing cabinet compartments. The interaction center executes a configuration program: It records the mapping relationship between digital and physical archives through a unified database, configures the archive security level and corresponding multi-level authentication strategies and first and / or second authentication procedures for the retrieved target archive; it generates a unique token for each archive and associates it with the type, ID, security level, and storage location of the retrieved target archive; based on the token, it generates corresponding digital and physical QR codes, which are then configured on the computer and in the smart filing cabinet compartments. S11: The security classification of the target file is set through the first and second setting procedures; S12: The storage location of target numbers and physical archives is managed through the retrieval system and grid editing information; S2: The interaction center executes the request verification procedure, which is completed by the API service to verify the initial request, the first request, and / or the second request sent based on digital signature technology, including: S21: The interactive terminal device scans the QR code and sends an initial request to the API service; S22: After verifying the initial request, the API service obtains the security level of the target file and matches it with the preset authentication policy, then sends authentication instructions to multiple devices; S23: Manage users to verify the first authentication procedure through interactive terminal devices and / or verify the second authentication procedure through computers / smart filing cabinets, and send the first request and / or the second request to the API service; S24: The API service processes multiple requests and executes the target file retrieval procedure after determining that multiple authentication procedures have successfully declared their validity. S3: Execute the retrieval procedure: API service command digital file management system / physical file management system retrieves and displays the target digital file / controls the opening of the smart file cabinet compartment where the target physical file is located based on the corresponding storage location; S4: The interaction center is configured to record audit logs for scanning, access, and result feedback information.

11. A smart device, characterized in that, include: The system includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes these computer instructions to perform the interactive management method for entities of different security levels and digital archives as described in claim 10.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the interactive management method for entities of different security levels and digital archives as described in claim 10.