Bid evaluation base front-end processor system and data security communication and service collaboration method
By employing device authentication, interface authentication, and data encryption/decryption technologies, the front-end system of the bidding evaluation base solves the security and collaboration issues between the unified platform and the distributed bidding evaluation base, achieving secure data transmission and efficient business collaboration, and supporting the standardized operation of bidding and procurement for large enterprises.
Patent Information
- Application Number
- CN202511731647.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-24
- Publication Date
- 2026-02-13
AI Technical Summary
The lack of a secure, standardized, and efficient business collaboration architecture between the unified platform and the distributed bidding evaluation base leads to heterogeneous interface protocols, high operation and maintenance costs, insecure data transmission, and low business collaboration efficiency, which affects the large-scale and standardized development of bidding and procurement business of large enterprises.
It provides a front-end system for the bid evaluation base, including a data communication service module and a local business processing module. It adopts device authentication, interface authentication and data encryption and decryption units, and ensures data security through SM2 and SM4 algorithms. It supports local data caching and synchronization, and provides a graphical client tool to realize real-time offline data collection and recording.
A secure data interaction channel was built, reducing the complexity of system integration, ensuring data transmission security, achieving seamless collaboration between online and offline businesses, improving business continuity and regulatory efficiency, and meeting the real-time and standardized needs of large enterprises for bidding and procurement.
Smart Images

Figure CN121530679A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic bidding and procurement technology, and in particular to a front-end system for bid evaluation base and a method for secure data communication and business collaboration. Background Technology
[0002] With the deepening of enterprise digital transformation, large central enterprises and state-owned enterprises generally adopt centralized electronic bidding and procurement platforms (hereinafter referred to as unified platforms) to standardize procurement processes and improve management efficiency. Unified platforms are typically deployed in the group's data center and are responsible for processing the entire online procurement process, including project posting, bidding, bid opening, bid evaluation, and bid awarding. However, due to the large organizational structure and wide distribution of procurement units, unified platforms need to interact with multiple geographically dispersed bid evaluation base systems to support offline bid evaluation activities or hybrid online and offline business models. Currently, unified platforms and various bid evaluation base systems mostly adopt direct interface methods, that is, point-to-point connections through application programming interfaces (APIs) or network services to achieve data exchange. While this model achieves data interoperability to a certain extent, it also exposes a series of core technical problems: First, the systems of each bidding evaluation base are often built by different vendors, resulting in heterogeneous interface protocols and inconsistent data formats, leading to high integration difficulty, high operation and maintenance costs, and poor system scalability. Second, the lack of a unified security intermediary layer in direct connection results in inadequate encryption mechanisms during data transmission, making it vulnerable to unauthorized access, data leakage, or tampering, failing to meet the stringent requirements of data confidentiality and integrity in bidding and procurement operations. Furthermore, in terms of business collaboration, the lack of efficient data synchronization and process coordination mechanisms means that data generated from offline bidding evaluations must be manually entered afterward, easily causing data delays, errors, or loss, disrupting business continuity, and affecting full-process supervision and audit traceability. The essence of these problems lies in the lack of a secure, standardized, and efficient business collaboration architecture between the unified platform and the distributed bidding evaluation bases, which restricts the large-scale and standardized development of bidding and procurement operations for large enterprises. Summary of the Invention
[0003] Therefore, it is necessary to address the technical problem of the lack of a secure, standardized, and efficient business collaboration architecture between the current unified platform and the distributed bidding evaluation base, and to provide a front-end system for the bidding evaluation base and a method for secure data communication and business collaboration.
[0004] This invention provides a front-end system for a bid evaluation base, deployed between a unified electronic bidding and procurement platform and a distributed bid evaluation base system, for secure data communication and business collaboration. The system includes:
[0005] The data communication service module includes a device authentication unit, an interface authentication unit, and a data encryption / decryption unit. The device authentication unit is used to verify the physical deployment environment and network characteristics of the access device based on a pre-assigned tenant identifier. The interface authentication unit is used to verify the legality of the data exchange request through a digital signature mechanism. The data encryption / decryption unit is used to achieve confidentiality and integrity protection of the transmitted data by using a combination of asymmetric encryption algorithm and symmetric encryption algorithm.
[0006] The local business processing module, which works in conjunction with the data communication service module, includes a project information acquisition unit, a business data recording unit, and a data collection unit. The project information acquisition unit is used to acquire basic information of the procurement project from the unified platform as needed and cache it locally. The business data recording unit is used to provide client tools to support the real-time collection and recording of offline bidding data. The data collection unit is used to synchronize local business data to the unified platform according to a preset strategy.
[0007] In one embodiment, the device authentication unit is specifically used to: verify the physical deployment environment, network ecosystem and pre-configured security token of the access device based on a pre-allocated unique tenant identifier, and to achieve multi-dimensional authentication through identity authentication, certificate lifecycle management, access control, session management, log auditing and attack protection mechanisms, wherein the tenant identifier is allocated and synchronized to the local service through a centralized management system.
[0008] In one embodiment, the interface authentication unit is specifically used to: verify the data exchange request by means of a digital signature generated based on the SM2 algorithm, wherein the digital signature is generated by an encrypted random number and access is only allowed when the request originates from an authorized device in the device whitelist.
[0009] In one embodiment, the data encryption / decryption unit is specifically used to: encrypt the transmitted data using the SM4 symmetric encryption algorithm, and encrypt and sign the SM4 key and data digest using the SM2 asymmetric encryption algorithm; the encryption / decryption process includes generating a data digest, symmetric encryption, asymmetric encryption key and digest, and decryption, signature verification and integrity verification at the receiving end; and key management dynamically generates SM4 algorithm keys based on business characteristics, access client type and access time, and protects them with SM2 algorithm encryption, and the digital certificate adopts a periodic automatic update mechanism.
[0010] In one embodiment, the project information acquisition unit is specifically used to: retrieve basic information of the procurement project on demand from the unified platform, including project name, number, budget price, subcontracting details and time nodes, and cache it in a local database to support offline business processing.
[0011] In one embodiment, the business data recording unit is specifically used to: provide a graphical client tool that simulates the interface of the unified platform for bid opening and evaluation data elements, support project managers to enter bid opening and evaluation information in real time through the local network, and include an identity authentication function to ensure the legality of the operation.
[0012] In one embodiment, the data collection unit is specifically used to: encrypt locally cached business data through an encryption / decryption unit and synchronize it to a unified platform according to a preset time point or event triggering strategy, and support configuring data temporary storage time and local archiving strategy through the front-end management terminal, including a data snapshot generation subunit, used to create snapshots before data encryption to achieve local backup and audit traceability.
[0013] In one embodiment, the data communication service module further includes an interface security management unit for implementing permission verification and access control mechanisms to ensure that only authorized users can access specific ranges of data on a specific data interface. The permission verification is based on dynamic management of user roles and device whitelists, and access behavior is monitored through log auditing.
[0014] This invention also provides a data security communication and business collaboration method, which is executed by the front-end system of the bidding evaluation base, and the method includes:
[0015] Perform device authentication to verify the legitimacy and security of access devices, and perform interface access authentication to ensure the legitimacy of data exchange requests. Also, use encryption algorithms to encrypt and decrypt transmitted data to establish a secure channel between the unified platform and the bidding base system.
[0016] Procurement project information is obtained from a unified platform and cached locally. Offline bidding business data is collected through client tools, and the collected business data is processed securely.
[0017] Data synchronization is triggered according to a preset strategy, and the synchronized data is verified and processed for security. The business data is updated on the unified platform to achieve collaboration between local business data and the unified platform.
[0018] In one embodiment, the encryption and decryption processing of the transmitted data using an encryption algorithm includes:
[0019] The SM4 algorithm is used to symmetrically encrypt the plaintext data, while the SM2 algorithm is used to asymmetrically encrypt and sign the SM4 key and data digest. At the receiving end, the key and digest are first decrypted using SM2, and then the data is decrypted using SM4. Signature verification and integrity verification are then performed. Furthermore, the key is dynamically generated based on business characteristics, accessing client, and access time, and the digital certificate is automatically updated periodically.
[0020] The aforementioned front-end system for the bidding evaluation base and its data security communication and business collaboration methods include: a data communication service module that verifies the physical deployment environment and network characteristics of access devices based on pre-assigned tenant identifiers through a device authentication unit, achieving multi-dimensional authentication to ensure device legitimacy and security; an interface authentication unit that verifies the legitimacy of data exchange requests through a digital signature mechanism based on the SM2 algorithm, preventing unauthorized access; and a data encryption / decryption unit that uses a combination of SM4 symmetric encryption and SM2 asymmetric encryption algorithms to encrypt, sign, and decrypt transmitted data, ensuring data confidentiality and integrity and building a secure channel. Simultaneously, the local business processing module obtains basic procurement project information from the unified platform on demand through the project information acquisition unit and caches it in a local database, supporting offline business processing; a business data recording unit provides a graphical client tool to simulate the unified platform interface, allowing project managers to collect and record bidding evaluation data in real time via the local network, avoiding manual data entry omissions; and a data collection unit that encrypts local business data and synchronizes it to the unified platform according to preset time points or event-triggered strategies, supporting data snapshot generation for backup and audit traceability, thereby improving business continuity and regulatory efficiency. Overall, the front-end system, acting as an intermediary and buffer, standardizes data interaction protocols, reduces system integration complexity and operational pressure, enhances data transmission security, and enables seamless collaboration between online and offline businesses through localized applications. This meets the large-scale, standardized, and real-time requirements of large enterprises' bidding and procurement operations. Furthermore, the data security communication and business collaboration methods executed by this system, through steps such as device authentication, interface authentication, data encryption / decryption, project information caching, offline data collection, and secure synchronization, further solidify the practicality and reliability of the overall solution. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0022] Figure 1 This is a schematic diagram of the front-end system of the bid evaluation base, as shown in one embodiment.
[0023] Figure 2 This is a flowchart of a data security communication and business collaboration method according to one embodiment;
[0024] Figure 3 This is an internal structural diagram of an electronic device according to one embodiment. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] The following is combined Figures 1-3 This invention describes the bid evaluation base front-end system and the data security communication and business collaboration method.
[0027] like Figure 1 As shown, in one embodiment, a bid evaluation base front-end system is deployed between a unified electronic bidding and procurement platform and a distributed bid evaluation base system for secure data communication and business collaboration, including a data communication service module 110 and a local business processing module 120.
[0028] The data communication service module 110 includes a device authentication unit 112, an interface authentication unit 114, and a data encryption / decryption unit 116.
[0029] Device authentication unit 112 verifies the physical deployment environment and network characteristics of access devices based on pre-allocated tenant identifiers. Specifically, based on pre-allocated unique tenant identifiers, it is allocated and synchronized to local services through a centralized management system to verify the physical deployment environment, network ecosystem, and pre-configured security tokens of access devices. Multi-dimensional authentication is achieved through identity authentication, certificate lifecycle management, access control, session management, log auditing, and attack protection mechanisms to ensure device legitimacy and security. Interface authentication unit 114 verifies the legitimacy of data exchange requests through a digital signature mechanism. Specifically, it verifies data exchange requests using a digital signature generated based on the SM2 algorithm. The signature is generated by an encrypted random number, and access is only allowed when the request originates from an authorized device within the device whitelist, thus verifying the legitimacy of the data exchange request. The data encryption / decryption unit 116 is used to achieve confidentiality and integrity protection of transmitted data by combining asymmetric and symmetric encryption algorithms. Specifically, it uses the SM4 symmetric encryption algorithm to encrypt the transmitted data, and combines it with the SM2 asymmetric encryption algorithm to encrypt and sign the SM4 key and data digest. The encryption / decryption process includes generating a data digest, symmetric encryption, asymmetric encryption key and digest, as well as decryption, signature verification and integrity verification at the receiving end. The key management dynamically generates the SM4 algorithm key based on business characteristics, access client type and access time, and protects it with SM2 algorithm encryption. The digital certificate adopts a periodic automatic update mechanism to achieve confidentiality and integrity protection of transmitted data.
[0030] The local business processing module 120 works in conjunction with the data communication service module 110, and includes a project information acquisition unit 122, a business data recording unit 124, and a data aggregation unit 126. The project information acquisition unit retrieves basic procurement project information from the unified platform on demand and caches it locally. Specifically, it pulls basic procurement project information from the unified platform on demand, including project name, number, budget price, subcontracting details, and time nodes, and caches it in the local database to support offline business processing. The business data recording unit 124 provides client tools to support the real-time collection and recording of offline bidding data. Specifically, it provides a graphical client tool that simulates the unified platform's bidding data element interface, allowing project managers to enter bidding and evaluation information in real time via the local network, and includes an identity authentication function to ensure the legitimacy of the operation. The data collection unit 126 is used to synchronize local business data to the unified platform according to a preset strategy. Specifically, according to a preset time point or event trigger strategy, the locally cached business data is encrypted by the encryption and decryption unit and then synchronized to the unified platform. It also supports configuring the data storage time and local archiving strategy through the front-end management terminal, including a data snapshot generation subunit, which is used to create a snapshot before data encryption to achieve local backup and audit traceability.
[0031] The bid evaluation base front-end system in this embodiment solves the security risks and protocol heterogeneity issues in the direct interface mode through the multi-dimensional authentication mechanism of the device authentication unit 112 and the SM2-based digital signature whitelist verification of the interface authentication unit 114, thus constructing a unified security intermediary layer. The data encryption and decryption unit 116 adopts a combination of national cryptographic algorithms and dynamic key management to ensure the confidentiality, integrity, and anti-attack capabilities of the data transmission process. The local business processing module 120 overcomes the delay and error risks of offline data post-entry through project information caching, real-time collection via a graphical client, and one-click submission, ensuring business continuity. The configurable synchronization strategy and snapshot generation mechanism of the data collection unit 126 enhance the reliability of data archiving and audit traceability capabilities, ultimately achieving the unification of secure standardized communication and efficient business collaboration.
[0032] In one embodiment, the data communication service module 110 further includes an interface security management unit for implementing permission verification and access control mechanisms to ensure that only authorized users can access a specific range of data on a specific data interface. Permission verification is dynamically managed based on user roles and device whitelists, and access behavior is monitored through log auditing. Optionally, during interface calls, dynamic permission verification is performed based on user roles and device whitelists to ensure that only authorized users can access a specific range of data on a specific data interface. Simultaneously, an access control mechanism restricts the data operation scope of authorized users, and all interface access behaviors are monitored and recorded in real time through log auditing. Through multi-layered security measures (including authentication, permission control, and behavior auditing), the security and reliability of interface calls are ensured, preventing unauthorized access and unauthorized data operations. This effectively solves the problem of insufficient interface security control in the direct interface mode, achieving refined access control through dynamic permission management and a whitelist mechanism, and constructing a complete security traceability chain combined with log auditing, significantly improving the security protection capabilities of data transmission and the traceability of unauthorized operations. The interface security management unit enhances the security management at the interface level of the front-end system, building upon device and interface authentication. This forms a comprehensive security protection system covering devices, interfaces, users, and operational behaviors, ensuring the integrity and reliability of the data exchange process.
[0033] Furthermore, this invention also provides a data security communication and business collaboration method, which is executed by the front-end system of the bidding evaluation base and includes the following steps:
[0034] Step S210: Perform device authentication to verify the legitimacy and security of the access device and perform interface access authentication to ensure the legitimacy of the data exchange request. Also, use encryption algorithms to encrypt and decrypt the transmitted data to establish a secure channel between the unified platform and the bidding base system.
[0035] First, device authentication is performed. Based on the pre-assigned unique tenant identifier, the physical deployment environment, network ecosystem, and pre-configured security token of the access device are verified. Multi-dimensional authentication mechanisms, including identity authentication, certificate lifecycle management, access control, and session management, ensure the legitimacy and security of the device. Next, interface access authentication is performed. Data exchange requests are verified using a digital signature generated based on the SM2 algorithm. Access is only allowed when the request originates from an authorized device in the device whitelist, ensuring the legitimacy of the data exchange request. At the same time, encryption algorithms are used to encrypt and decrypt the transmitted data. Specifically, the data is encrypted using the SM4 symmetric encryption algorithm, and the SM4 key and data digest are encrypted and signed using the SM2 asymmetric encryption algorithm, establishing a secure channel between the unified platform and the bidding base system.
[0036] Step S220: Obtain procurement project information from the unified platform and cache it locally, and collect offline bidding business data through client tools, and perform security processing on the collected business data.
[0037] In terms of business collaboration, basic information of procurement projects is obtained from the unified platform and cached in the local database to support offline business processing; offline bidding business data is collected through graphical client tools, simulating the unified platform interface for project managers to enter bidding information in real time, and the collected data is securely processed.
[0038] Step S230: Trigger data synchronization operation according to preset strategy, perform security verification and processing on synchronized data, and complete the update of business data on unified platform to achieve collaboration between local business data and unified platform.
[0039] Data synchronization is performed according to preset time points or event-triggered strategies. Local business data is encrypted and synchronized to a unified platform to complete security verification and processing, thereby enabling business data updates.
[0040] The transmitted data is encrypted using encryption algorithms, including: using the SM4 algorithm to symmetrically encrypt the plaintext data, and using the SM2 algorithm to asymmetrically encrypt and sign the SM4 key and data digest; at the receiving end, the key and digest are first decrypted using SM2, and then the data is decrypted using SM4, and the signature and integrity are verified; the key is dynamically generated based on business characteristics, accessing client and access time, and the digital certificate is automatically updated periodically.
[0041] This embodiment addresses the interface heterogeneity issue in direct-connection mode through a standardized security authentication process, ensures data transmission confidentiality through a combination of national cryptographic algorithms, and avoids data entry delays through local caching and real-time acquisition. The technical benefits include building an end-to-end secure communication system, reducing system integration complexity, achieving seamless collaboration between online and offline businesses, and enhancing long-term system security through dynamic key management and certificate update mechanisms, effectively supporting the large-scale and standardized operation of bidding and procurement for large enterprises.
[0042] Figure 3 This example illustrates a schematic diagram of the physical structure of an electronic device, which can be a smart terminal. Its internal structure diagram can be as follows: Figure 3As shown. The electronic device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a method for secure data communication and business collaboration, which includes:
[0043] Perform device authentication to verify the legitimacy and security of access devices, and perform interface access authentication to ensure the legitimacy of data exchange requests. Also, use encryption algorithms to encrypt and decrypt transmitted data to establish a secure channel between the unified platform and the bidding base system.
[0044] Procurement project information is obtained from a unified platform and cached locally. Offline bidding business data is collected through client tools, and the collected business data is processed securely.
[0045] Data synchronization is triggered according to a preset strategy, and the synchronized data is verified and processed for security. The business data is updated on the unified platform to achieve collaboration between local business data and the unified platform.
[0046] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the electronic device to which the present invention is applied. A specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0047] On the other hand, the present invention also provides a computer storage medium storing a computer program, which, when executed by a processor, implements a method for secure data communication and business collaboration, the method comprising:
[0048] Perform device authentication to verify the legitimacy and security of access devices, and perform interface access authentication to ensure the legitimacy of data exchange requests. Also, use encryption algorithms to encrypt and decrypt transmitted data to establish a secure channel between the unified platform and the bidding base system.
[0049] Procurement project information is obtained from a unified platform and cached locally. Offline bidding business data is collected through client tools, and the collected business data is processed securely.
[0050] Data synchronization is triggered according to a preset strategy, and the synchronized data is verified and processed for security. The business data is updated on the unified platform to achieve collaboration between local business data and the unified platform.
[0051] In another aspect, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and when the processor executes the computer instructions, it implements a method for secure data communication and business collaboration, the method comprising:
[0052] Perform device authentication to verify the legitimacy and security of access devices, and perform interface access authentication to ensure the legitimacy of data exchange requests. Also, use encryption algorithms to encrypt and decrypt transmitted data to establish a secure channel between the unified platform and the bidding base system.
[0053] Procurement project information is obtained from a unified platform and cached locally. Offline bidding business data is collected through client tools, and the collected business data is processed securely.
[0054] Data synchronization is triggered according to a preset strategy, and the synchronized data is verified and processed for security. The business data is updated on the unified platform to achieve collaboration between local business data and the unified platform.
[0055] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory.
[0056] By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0057] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0058] The above-described embodiments are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the appended claims.
Claims
1. A pre-processing system for a bid evaluation base, characterized in that, Deployed between the unified electronic bidding and procurement platform and the distributed bid evaluation base system for secure data communication and business collaboration, the system includes: The data communication service module includes a device authentication unit, an interface authentication unit, and a data encryption / decryption unit. The device authentication unit is used to verify the physical deployment environment and network characteristics of the access device based on a pre-assigned tenant identifier. The interface authentication unit is used to verify the legality of the data exchange request through a digital signature mechanism. The data encryption / decryption unit is used to achieve confidentiality and integrity protection of the transmitted data by using a combination of asymmetric encryption algorithm and symmetric encryption algorithm. The local business processing module, which works in conjunction with the data communication service module, includes a project information acquisition unit, a business data recording unit, and a data collection unit. The project information acquisition unit is used to acquire basic information of the procurement project from the unified platform as needed and cache it locally. The business data recording unit is used to provide client tools to support the real-time collection and recording of offline bidding data. The data collection unit is used to synchronize local business data to the unified platform according to a preset strategy.
2. The bid evaluation base pre-processing system according to claim 1, characterized in that, The device authentication unit is specifically used to: verify the physical deployment environment, network ecosystem and pre-configured security token of the access device based on the pre-allocated unique tenant identifier, and to achieve multi-dimensional authentication through identity authentication, certificate lifecycle management, access control, session management, log auditing and attack protection mechanisms. The tenant identifier is allocated and synchronized to the local service through a centralized management system.
3. The pre-processing system for the bid evaluation base according to claim 1, characterized in that, The interface authentication unit is specifically used to: verify the data exchange request by using a digital signature generated based on the SM2 algorithm, wherein the digital signature is generated by an encrypted random number and access is only allowed when the request originates from an authorized device in the device whitelist.
4. The pre-processing system for the bid evaluation base according to claim 1, characterized in that, The data encryption / decryption unit is specifically used to: encrypt transmitted data using the SM4 symmetric encryption algorithm, and encrypt and sign the SM4 key and data digest using the SM2 asymmetric encryption algorithm; the encryption / decryption process includes generating a data digest, symmetric encryption, asymmetric encryption key and digest, as well as decryption, signature verification and integrity verification at the receiving end; and key management dynamically generates SM4 algorithm keys based on business characteristics, access client type and access time, and protects them with SM2 algorithm encryption, and the digital certificate adopts a periodic automatic update mechanism.
5. The pre-processing system for the bid evaluation base according to claim 1, characterized in that, The project information acquisition unit is specifically used to: retrieve basic information of procurement projects from the unified platform on demand, including project name, number, budget price, subcontracting details and time nodes, and cache it in the local database to support offline business processing.
6. The pre-processing system for the bid evaluation base according to claim 1, characterized in that, The business data recording unit is specifically used to: provide a graphical client tool that simulates the interface of the unified platform for bid opening and evaluation data elements, support project managers to enter bid opening and evaluation information in real time through the local network, and include an identity authentication function to ensure the legality of the operation.
7. The pre-processing system for the bid evaluation base according to claim 1, characterized in that, The data collection unit is specifically used to: encrypt locally cached business data through the encryption / decryption unit and synchronize it to the unified platform according to a preset time point or event triggering strategy, and support the configuration of data temporary storage time and local archiving strategy through the front-end management terminal, including a data snapshot generation subunit, which is used to create snapshots before data encryption to achieve local backup and audit traceability.
8. The bid evaluation base pre-processing system according to any one of claims 1 to 7, characterized in that, The data communication service module also includes an interface security management unit, which is used to implement permission verification and access control mechanisms to ensure that only authorized users can access specific data of a specific data interface. The permission verification is based on dynamic management of user roles and device whitelists, and access behavior is monitored through log auditing.
9. A method for secure data communication and business collaboration, characterized in that, The method is executed by the front-end system of the bid evaluation base, and the method includes: Perform device authentication to verify the legitimacy and security of access devices, and perform interface access authentication to ensure the legitimacy of data exchange requests. Also, use encryption algorithms to encrypt and decrypt transmitted data to establish a secure channel between the unified platform and the bidding base system. Procurement project information is obtained from a unified platform and cached locally. Offline bidding business data is collected through client tools, and the collected business data is processed securely. Data synchronization is triggered according to a preset strategy, and the synchronized data is verified and processed for security. The business data is updated on the unified platform to achieve collaboration between local business data and the unified platform.
10. The data security communication and business collaboration method according to claim 9, characterized in that, The encryption and decryption processing of transmitted data using an encryption algorithm includes: The SM4 algorithm is used to symmetrically encrypt the plaintext data, while the SM2 algorithm is used to asymmetrically encrypt and sign the SM4 key and data digest. At the receiving end, the key and digest are first decrypted using SM2, and then the data is decrypted using SM4. Signature verification and integrity verification are then performed. Furthermore, the key is dynamically generated based on business characteristics, accessing client, and access time, and the digital certificate is automatically updated periodically.