Digital file security traceability method

By introducing uniqueness and encryption mechanisms into the digital file generation and download process, combined with blockchain technology and multi-dimensional behavioral profiling, the problem of lack of traceability in the download and use of digital files is solved, enabling rapid and accurate location of the source of data leakage and improving the efficiency and accuracy of data security management.

CN121543069APending Publication Date: 2026-02-17CHINA COMMERCE NETWORKS (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511708339.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-20
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

The lack of effective tracking and tracing mechanisms for existing digital files during download and use makes it difficult to quickly locate the source of data leaks. Furthermore, traditional download methods consume a lot of manpower and time and have a low success rate.

Method used

By introducing uniqueness and encryption mechanisms into the digital file generation and download process, download information is recorded and dynamic verification codes are generated. Combined with blockchain technology, a multi-dimensional behavioral baseline profile and intelligent early warning system are constructed to achieve secure traceability of digital files and rapid location of the source of leakage.

Benefits of technology

Ensuring the security and traceability of digital files during transmission and use enables the rapid and accurate identification of the source of leaks, reduces the risk of data breaches, and improves the efficiency and accuracy of data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121543069A_ABST
    Figure CN121543069A_ABST
Patent Text Reader

Abstract

The invention discloses a digital file security traceability method, and belongs to the technical field of information security. According to the method and the system, the problem that a leakage source is difficult to locate quickly after data leakage due to the fact that an effective tracking and tracing mechanism is lacked in the downloading and using processes of the existing digital file is solved, and a unique identifier, an encryption technology and a detailed recording mechanism are introduced into the whole process of generating, downloading, using and querying the digital file; the full-life-cycle management of the digital file is realized, when a batch leakage or continuous number leakage scene occurs, correct digital information and encrypted downloading information can be quickly analyzed, and the information is utilized to trace in the database, so that a leakage source can be quickly and accurately positioned, and the leakage efficiency is improved. And meanwhile, the security control capability and the data security management consciousness of enterprises such as printing factories and the like on digital files are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically a method for secure tracing of digital files. Background Technology

[0002] With the rapid development of information technology, the use and dissemination of digital documents have become more convenient, especially in scenarios such as printing plants that require the processing of large volumes of digital documents. Downloading and using digital documents is an important part of daily work. In places like printing plants, the secure management of digital documents is particularly important. Digital documents often contain sensitive content such as important design information and customer data; once leaked, the consequences are unimaginable. However, traditional download methods have significant shortcomings in data tracking. Once a digital document is leaked, it is difficult to trace the source of the leak, not only leading to the leakage of trade secrets but also requiring a significant amount of manpower and time for investigation, with a low success rate. Therefore, these methods do not meet current needs. To address this, we propose a method for secure digital document traceability. Summary of the Invention

[0003] The purpose of this invention is to provide a method for secure traceability of digital files. By recording the download organization, download time, and number of downloads each time the file is downloaded externally, and then re-encrypting and compiling the data with a unique code to generate new and unique data and form a digital file for download, the downloaded digital file will contain download organization information. When the digital file is leaked, the source of the leak can be traced back based on the digital file, thereby ensuring the security of the digital file in the transmission link and tracing the source of the problem, thus solving the problems mentioned in the background art.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for secure traceability of digital documents, the method comprising:

[0005] Brands initiate digital product application orders in the system, providing the order quantity and digital rule information. After the platform verifies the information, it automatically generates unique digital files.

[0006] The downloading organization finds the digital application form information that needs to be downloaded on the platform as needed, clicks the download button, and generates a download record;

[0007] Based on the download history, obtain the digital file, encrypt the digital file again, and then provide it for download.

[0008] The printing plant downloads the encrypted digital files to its local machine and prints them into labels and packaging materials for use on the products.

[0009] After a consumer scans the code, the original digital information is parsed from the URL scanned by the consumer and used for anti-counterfeiting information query.

[0010] When there is a mass or consecutive number leak of digital numbers, the leaked digital information is obtained, and the digital information is analyzed using tools to extract the correct digital information and encrypted download information. The extracted information is then used to trace the source in the database and locate the risk organization that caused the leak.

[0011] Also includes:

[0012] During each download, the precise timestamp of the download is hashed to generate a 6-bit segment, which is then combined with a 5-bit ciphertext generated by unique digital encryption and a 1-bit download count identifier to form an indivisible dynamic checksum.

[0013] The dynamic verification code is tightly embedded in the final URL provided to the consumer. After the consumer scans the code, the timestamp information in the dynamic verification code is automatically extracted and parsed, and compared with the current time of the server.

[0014] Different effective lifecycle thresholds are preset for different types of products based on their lifecycle characteristics; if the difference between the query time and the embedded timestamp exceeds the corresponding threshold, the code is directly determined to be an invalid risk code, the subsequent anti-counterfeiting information query process is terminated, and the consumer is notified that the query has timed out.

[0015] Meanwhile, a multi-dimensional behavioral baseline profile is independently established and dynamically updated for each downloading organization. The baseline includes download frequency, time period, quantity, type of downloaded files, and geographic access characteristics.

[0016] When the behavior of any downloading organization deviates from its historical baseline in real time, an early warning is automatically triggered based on a preset deviation threshold, which is dynamically adjusted according to the organization's historical behavior.

[0017] Once the warning is triggered, all download tasks for that organization and all subsequent download tasks will be forcibly suspended and will enter a manual review process. At the same time, all recent download records of the organization will be automatically linked for cross-comparison and analysis.

[0018] After the review is approved, the review conclusion and the timestamp of the resumed download are recorded, and the entire process of this warning and handling is included in the traceability database.

[0019] Furthermore, based on the download history, the digital file is obtained, encrypted again, and then made available for download, including:

[0020] Based on the order for the downloaded digital item, retrieve the file generated and stored on the server. The file contains the digital item and its corresponding URL link.

[0021] Based on the downloaded document information, obtain the download order information and record the order ID. The download order information includes the download time, number of downloads, download organization, and download user.

[0022] Each digital element in the digital file is re-encrypted based on the downloaded information, and two encryption schemes are provided based on different customer needs;

[0023] According to the encryption requirements, each digital code is re-encrypted, and the encrypted digital code is rewritten into a new file to form a new digital file, which is then provided for download.

[0024] Two encryption schemes are offered to meet different customer needs:

[0025] Both the digital data itself and its corresponding URL are encrypted.

[0026] The digital data itself is encrypted, but the URL link remains viewable.

[0027] Furthermore, to address higher security requirements, both the digital data itself and its corresponding URL are encrypted, specifically as follows:

[0028] Extract the original digital URL from the digital file;

[0029] The data portion of the original digital URL is encrypted using symmetric encryption.

[0030] After encryption, the encrypted data is combined with the order ID to form a new string;

[0031] After two encryptions, the final encrypted URL is obtained. The URL contains the data that has undergone two symmetric encryption processes. The original digital file URL can be obtained by decryption.

[0032] Furthermore, the digital data itself is encrypted, while the URL remains viewable, specifically as follows:

[0033] Get the original digital URL from the digital file, and get the digital verification code;

[0034] The verification code needs to be regenerated, and the generation rules are as follows:

[0035] Obtain the unique code in the file, perform a symmetric encryption algorithm to generate encrypted ciphertext, and compress the ciphertext into 5 letters;

[0036] Additionally, the last digit of the verification code is set to the number of downloads, recorded from 1 to Z, a total of 33 letters, including 1 to 9 and A to Z, where the letters I and O are removed from A to Z;

[0037] The first download records 1, and each subsequent download increments by 1, supporting a maximum of 33 download records. Each download changes the verification code to new content, which is then encrypted to form a new digital file.

[0038] The digital verification code is the last 6 digits of the URL link. During subsequent downloads, if the recorded value exceeds 9, it is recorded as A, and the value is incremented sequentially until Z.

[0039] Furthermore, the parsed information is used to trace back in the database, including tracing download history by order ID and locking down individual download events by download count.

[0040] Furthermore, the download history can be traced through the order ID, specifically as follows:

[0041] Scan to obtain URL link information containing the target tag;

[0042] Extract the data after the target tag according to the preset URL rules, and remove the characters of a specified length at the end to obtain the encrypted code;

[0043] The encrypted digital code is decrypted using a symmetric encryption key to obtain the original digital code and the associated order ID;

[0044] The original digital code obtained through decryption is used to query the database to confirm its existence and validity, thereby eliminating interference from counterfeit or invalid digital codes.

[0045] If the original digital file exists, use the decrypted order ID to query the information about the original digital file when it was downloaded, including the download time, number of downloads, download organization, and download user;

[0046] Risk organization positioning is based on the downloaded information obtained.

[0047] Furthermore, a single download event is identified by the number of downloads, specifically as follows:

[0048] Scan to obtain URL link information containing the target tag;

[0049] Extract the data after the target tag according to the preset URL rules, and remove the characters of a specified length at the end to obtain the encrypted code;

[0050] Use the encrypted code as the original code, and query the database to see if the original code exists to confirm that the code is correct and valid.

[0051] Assuming the numbers are correct, extract the last 6 digits from the URL, where the last digit represents the number of downloads.

[0052] Based on the original data, query the original application order corresponding to the original data, and obtain the historical download count of the original application order by the order ID;

[0053] By identifying the number of times a digital file is downloaded, information about the specific digital file being downloaded can be used to pinpoint the risky organization that leaked the digital file. The historical download data includes the download time, number of downloads, downloading organization, and downloading user.

[0054] Furthermore, the digital file contains a unique code and a digital URL link information. The unique code consists of the first 16 digits. The digital file is used to convert the code into a QR code and print it onto the product surface.

[0055] Furthermore, a multi-dimensional behavioral baseline profile is independently established and dynamically updated for each downloading organization, specifically as follows:

[0056] Collect historical behavioral data of download organizations over a continuous time period to construct a multi-dimensional behavioral feature set, including download frequency time series distribution, cluster analysis of typical download periods, statistical distribution of single download quantity, download file type preference matrix, and geographic density heat map of access IP.

[0057] Each dimension feature is normalized and weighted, and a weighted moving average algorithm based on time decay factor is used to dynamically update the baseline values ​​of each dimension to ensure that the behavioral profile evolves adaptively with the operation cycle.

[0058] Set a dynamic deviation threshold matrix, which is automatically adjusted according to the confidence interval based on the historical statistical values ​​of the volatility of each dimension of behavior.

[0059] When the deviation of any dimension's real-time behavioral data from the baseline exceeds the corresponding threshold, or when multiple dimensions deviate simultaneously, a warning signal of the corresponding level is triggered, and the process enters the manual review stage after the warning is triggered.

[0060] Furthermore, the manual review process after an alert is triggered includes:

[0061] Automatically generate early warning reports, including deviation dimension radar charts, real-time behavior and baseline comparison curves, a list of associated download tasks, and recommendations of potentially risky organizations based on behavioral graph similarity;

[0062] Auditors use the auditing terminal to retrieve all operation logs, file download metadata, access IP geographic location change maps, and comparative analysis data of other organizations' behavior within the set period before the warning time of the organization under warning;

[0063] The reviewers will make a comprehensive judgment based on the multi-dimensional chain of evidence and categorize the review conclusions into three types: false alarm recovery, partial restriction of permissions or permanent ban and initiation of judicial remedies. The reviewers will also need to fill in the review comments and supporting evidence.

[0064] After the review is approved, the digital identity of the reviewer, the review timestamp, the processing conclusion and the fingerprint of the related evidence chain are recorded, and all data of this warning event is archived to the traceability database for subsequent model optimization and judicial evidence collection.

[0065] For cases confirmed as false alarms, the organization's behavioral baseline will be smoothed and corrected based on the audit findings, and such behavioral patterns will be given higher tolerance in subsequent monitoring.

[0066] Compared with the prior art, the beneficial effects of the present invention are:

[0067] This invention ensures the security and traceability of digital files during transmission and use by introducing uniqueness and encryption mechanisms into the generation and download process. The automatically generated unique digital files, combined with encryption technology, effectively prevent tampering and illegal copying of digital files during download and use, thereby greatly reducing the risk of data leakage. In addition, by establishing detailed download records and parsing tools, the source of digital file leakage can be quickly located. In the event of batch leakage or consecutive number leakage, the correct digital information and encrypted download information can be quickly parsed and traced in the database, thereby accurately locating the risk organization that caused the leakage, and thus improving the efficiency and accuracy of data security management. Attached Figure Description

[0068] Figure 1 This is a flowchart of the digital file security tracing method of the present invention;

[0069] Figure 2 This is an execution diagram of the digital file security tracing method of the present invention.

[0070] Figure 3 This is an execution diagram of the present invention for tracing information in a database using parsed information. Detailed Implementation

[0071] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0072] To address the lack of effective tracking and tracing mechanisms during the download and use of digital files, which makes it difficult to quickly pinpoint the source of data leaks, please refer to [link to relevant documentation]. Figures 1-3 This embodiment provides the following technical solution:

[0073] A method for secure traceability of digital documents, the method comprising:

[0074] Brands initiate digital product application orders in the system, providing the order quantity and digital rule information. After verifying the information, the platform automatically generates a unique digital file. The digital file contains a unique code and a digital URL link, such as 1234567890123456, https: / / cj8.ren.com / ?01234567890123456ABCDEF. The unique code consists of the first 16 digits, separated from the digital URL link information by a comma. The digital file is used to convert into a QR code and print it on the product surface.

[0075] The downloading organization finds the digital application form information that needs to be downloaded on the platform as needed, clicks the download button, and generates a download record;

[0076] Based on the download history, obtain the digital file, encrypt the digital file again, and then provide it for download.

[0077] The printing plant downloads the encrypted digital file to its local machine. Using the key provided by the platform, the printing plant decrypts the encrypted digital file, restores it to a printable plaintext digital file, and prints it into labels and packaging materials for use on products.

[0078] After a consumer scans the code, the original digital information is parsed from the URL scanned by the consumer and used for anti-counterfeiting information query.

[0079] When digital numbers are leaked in batches or consecutively, the leaked digital number information is obtained, and the digital numbers are analyzed using tools to extract the correct digital number information and encrypted download information. The analyzed information is then used to trace the source in the database and locate the risk organization that caused the leak. The tool is a dedicated parsing platform or system that integrates specific rules (such as URL rules), algorithms (such as decryption algorithms), and keys.

[0080] The technical effects of the above solution are as follows: When a brand initiates a digital product application order and provides relevant information, the platform generates a unique digital file, ensuring its initial security and identifiability. When an organization downloads the digital file from the platform, the system generates detailed download records, providing a basis for subsequent traceability. The digital file is then re-encrypted based on the download records before being made available for download, further enhancing its security during transmission and preventing unauthorized alteration or theft. Printing plants download the encrypted digital file and use it for product label printing, tightly binding the digital file to the product. This allows consumers to easily obtain the original digital information for anti-counterfeiting verification by scanning the code, enhancing their ability to distinguish genuine products from counterfeit ones. Furthermore, in the event of batch or consecutive leaks of digital files, specialized tools can be used to analyze the leaked information, quickly and accurately tracing the source of the leak and identifying potentially risky organizations, thereby effectively improving the security and traceability of digital files and reducing the risks associated with data breaches.

[0081] A method for secure traceability of digital files also includes:

[0082] During each download, the precise timestamp of the download is hashed to generate a 6-bit segment, which is then combined with a 5-bit ciphertext generated by unique digital encryption and a 1-bit download count identifier to form an indivisible dynamic checksum.

[0083] The dynamic verification code is tightly embedded in the final URL provided to the consumer. After the consumer scans the code, the timestamp information in the dynamic verification code is automatically extracted and parsed, and compared with the current time of the server.

[0084] Different effective lifecycle thresholds are preset for different types of products based on their lifecycle characteristics (e.g., a shorter threshold is set for products with short shelf life, and a longer threshold is set for products with long shelf life). If the difference between the query time and the embedded timestamp exceeds the corresponding threshold, the code is directly determined to be an invalid risk code, the subsequent anti-counterfeiting information query process is terminated, and the consumer is notified that the query has timed out.

[0085] This mechanism enables dynamic control of time risks in the distribution process, even if the digital information has been printed on the product. It is especially suitable for anti-counterfeiting scenarios involving seasonal, promotional, or short-shelf-life products.

[0086] Meanwhile, a multi-dimensional behavioral baseline profile is independently established and dynamically updated for each downloading organization. The baseline includes download frequency, time period, quantity, type of downloaded files, and geographic access characteristics.

[0087] When the behavior of any downloading organization deviates from its historical baseline in real time, an early warning is automatically triggered based on a preset deviation threshold, which is dynamically adjusted according to the organization's historical behavior.

[0088] Once the warning is triggered, all download tasks for that organization and all subsequent download tasks will be forcibly suspended and will enter a manual review process. At the same time, all recent download records of the organization will be automatically linked for cross-comparison and analysis.

[0089] After the review is approved, the review conclusion and the timestamp of the resumed download are recorded, and the entire process of this warning and handling is included in the traceability database;

[0090] Through the above mechanism, not only is real-time monitoring of download behavior achieved, but proactive intervention is also possible when anomalies are detected. Combining manual review with system analysis, a closed-loop risk management system is formed, which is applicable to complex supply chain environments with multiple levels and multiple regions.

[0091] The technical effects of the above solution are as follows: By introducing a timeliness control mechanism that links dynamic verification codes with the product lifecycle, it can solve the security risks caused by the passage of time in the circulation process of printed digital documents. It is especially suitable for scenarios with clear time sensitivity, such as seasonal, promotional, and short-shelf-life products, thus achieving an organic combination of static printing and dynamic verification. At the same time, by constructing an intelligent early warning and intervention system based on multi-dimensional behavioral baseline profiles, it can not only monitor conventional indicators such as download frequency, time period, and quantity, but also establish a precise behavioral model by introducing dimensions such as download file type and regional access characteristics. Combined with dynamically adjusted deviation thresholds and cross-comparison analysis mechanisms, it can proactively identify and intercept abnormal behavior in complex supply chain environments, forming a closed-loop management system of monitoring, early warning, intervention, and traceability. This significantly improves the security and reliability of digital files in the distribution, use, and traceability stages.

[0092] A method for secure traceability of digital documents also includes a blockchain-based distributed traceability and evidence storage mechanism:

[0093] After each download operation is completed, a digital fingerprint is generated from the key information of the download record. The key information includes the download timestamp, download organization identifier, file hash value, and dynamic verification code.

[0094] The digital fingerprint is synchronously stored in a private blockchain network composed of multiple nodes to form an immutable chain of traceability evidence.

[0095] In the event of a digital data breach, the integrity and authenticity of the traceability data can be verified by comparing the blockchain-stored records with the database records.

[0096] The technical effects of the above solution are as follows: By generating digital fingerprints from key information in the download records and storing them synchronously in a private blockchain network, an immutable distributed traceability evidence chain can be constructed. Utilizing the decentralized nature and data immutability of blockchain, malicious modification or deletion of traceability data during storage can be prevented, thus ensuring the integrity and authenticity of traceability information. In the event of a digital data breach, comparing the blockchain-stored records with database records can quickly and reliably verify data consistency, thereby accurately locating the breach and enhancing the credibility and evidentiary value of the traceability results. This provides strong technical support for accountability and damage assessment.

[0097] Based on the download history, retrieve the digital file, encrypt it again, and then provide it for download, including:

[0098] Based on the order for the downloaded digital item, retrieve the file generated and stored on the server. The retrieved file contains the digital item and the corresponding URL link.

[0099] Based on the downloaded document information, obtain the download order information and record the order ID. The download order information includes the download time, number of downloads, download organization, and download user.

[0100] Each digital element in the digital file is re-encrypted based on the downloaded information, and two encryption schemes are provided based on different customer needs;

[0101] According to the encryption requirements, each digital code is re-encrypted, and the encrypted digital code is rewritten into a new file to form a new digital file, which is then provided for download.

[0102] During the encryption process, the behavioral characteristics of the encryption operation are collected in real time, including encryption time, memory usage pattern, and CPU usage characteristics.

[0103] The multidimensional behavioral features are jointly analyzed by a deep neural network model based on a spatiotemporal attention mechanism. This model uses a bidirectional LSTM network to capture time-series dependencies and combines a graph convolutional network to mine the spatial correlation between features, thereby achieving multidimensional identification of abnormal encryption patterns.

[0104] When abnormal encryption behavior is detected, the system immediately activates a multi-level response mechanism: first, it automatically stops the current encryption process and isolates the relevant processes; then, it triggers a blockchain-based security audit process, records the hash value of the abnormal behavior characteristics on the blockchain in real time, and simultaneously starts the source tracing analysis engine to conduct a backtracking analysis of the entire lifecycle of this encryption operation, generates a security assessment report, and pushes it to the security management center.

[0105] The technical effects of the above solution are as follows: The system enhances the security and controllability of digital file distribution through a dynamic encryption mechanism. When a user initiates a download, the system obtains the original file in real time and generates a unique encryption key based on order details such as user identity, organization affiliation, and access records. This ensures that the same digital file presents different ciphertexts to different customers, effectively preventing unauthorized dissemination and use. Simultaneously, by automatically associating download behavior with the order ID, the system achieves end-to-end tracking of operations. Furthermore, by providing two encryption schemes on demand, the system meets diverse customer security needs while avoiding the management burden of statically storing multiple versions of files. The resulting encrypted file maintains distribution efficiency while ensuring data security, improving service reliability and compliance. In addition, by collecting and analyzing multi-dimensional behavioral characteristics of encryption operations in real time during the encryption process, and using a spatiotemporal attention mechanism model that integrates bidirectional LSTM and graph convolutional networks for joint analysis, the system can achieve high-precision, multi-dimensional identification of abnormal encryption patterns, thereby enhancing the proactive defense capabilities of the encryption process.

[0106] Two encryption schemes are offered to meet different customer needs:

[0107] One approach, targeting higher security requirements, encrypts both the digital data itself and its corresponding URL link. Specifically:

[0108] Extract the original digital URL from the digital file;

[0109] The data portion of the original digital URL is encrypted using a symmetric encryption method. The process of symmetric encryption is existing technology in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0110] After encryption, the encrypted data part is combined with the order ID to form a new string, in the format of "encrypted data part + order ID", for example, digital 1234567890123456 + order ID;

[0111] After two encryptions, the final encrypted URL is obtained. The encrypted URL contains the data that has undergone two symmetric encryption processes. The original digital file URL can be obtained by decryption.

[0112] This final encrypted URL is used for subsequent storage, transmission, or other related operations to ensure the security of digital files;

[0113] Another method requires that the URL number be viewable, in which only the number itself is encrypted, while the URL link remains viewable. Specifically:

[0114] Get the original digital URL from the digital file, and get the digital verification code, which is the last 6 digits of the URL link.

[0115] The verification code needs to be regenerated, and the generation rules are as follows:

[0116] Obtain the unique code in the file, perform a symmetric encryption algorithm to generate encrypted ciphertext, and compress the ciphertext into 5 letters;

[0117] Additionally, the last digit of the checksum is set to the number of downloads. The number of downloads is recorded from 1 to Z, a total of 33 letters, including 1 to 9 and A to Z. The letters I and O are removed from A to Z. In subsequent downloads, when the recorded value exceeds 9, A is recorded, and the number of downloads is increased sequentially until Z.

[0118] The first download records 1 record, and each subsequent download increments by 1, with a maximum of 33 download records supported. Each download changes the verification code to new content, encrypting and forming a new digital file.

[0119] The technical effects of the above solutions are as follows: In the first solution, the security of the data is greatly enhanced through two symmetric encryption processes. This double encryption method makes it difficult to crack the data even if it is intercepted during transmission and storage, effectively protecting the privacy and security of digital files. In the second solution, although the URL link remains viewable, the digital data itself is encrypted by a symmetric encryption algorithm and a new verification code is generated. This encryption process can also prevent the digital information from being illegally tampered with and stolen, ensuring the security of digital files.

[0120] In summary, two encryption schemes are provided, which can be selected according to different customer needs. This flexible scheme design can ensure security while also meeting users' requirements for ease of operation.

[0121] like Figure 3 As shown, the parsed information is used to trace back within the database, including:

[0122] Download history can be traced using the order ID, specifically as follows:

[0123] Scan to obtain URL link information containing the target tag;

[0124] Extract the data after the target tag according to the preset URL rules, and remove the characters of a specified length at the end (i.e., remove the last 6 characters of the content) to obtain the encrypted code;

[0125] The encrypted digital code is decrypted using a symmetric encryption key to obtain the original digital code and the associated order ID;

[0126] The original digital code obtained through decryption is used to query the database to confirm its existence and validity, thereby eliminating interference from counterfeit or invalid digital codes.

[0127] If the original digital file exists, use the decrypted order ID to query the information about the original digital file when it was downloaded, including the download time, number of downloads, download organization, and download user;

[0128] Risk organization positioning is conducted based on the downloaded information obtained;

[0129] Locking a single download event by the number of downloads, specifically:

[0130] Scan to obtain URL link information containing the target tag;

[0131] The data after the target tag is extracted according to the preset URL rules, and the characters of a specified length at the end (i.e., the last 6 characters of the content are removed) are used to obtain the encrypted code.

[0132] Use the encrypted code as the original code, and query the database to see if the original code exists to confirm that the code is correct and valid.

[0133] Assuming the numbers are correct, extract the last 6 digits from the URL. The last digit represents the number of downloads (e.g., if the data obtained is A, it means the 10th download).

[0134] Based on the original data, query the original application order corresponding to the original data, and obtain the historical download count of the original application order by the order ID;

[0135] By identifying the number of times a digital file is downloaded, information about the specific digital file being downloaded can be used to pinpoint the risky organization that leaked the digital file. The historical download data includes the download time, number of downloads, downloading organization, and downloading user.

[0136] The technical effects of the above solution are as follows: Scanning and parsing URL links containing target markers can quickly locate key encrypted codes, thereby enabling the rapid identification of download records related to specific orders from massive amounts of data, greatly improving traceability efficiency. By combining order IDs and encrypted codes, detailed information of each download event can be accurately traced, making the flow of data clearly traceable, thus providing strong support for data management. Furthermore, locking down a single download event by the number of downloads allows for precise identification of the specific information of each download, enabling the rapid identification of potentially risky organizations when data leaks or other anomalies are discovered.

[0137] In summary, by using preset URL rules and encryption / decryption mechanisms, the entire data download process can be monitored and managed. Furthermore, by tracing download history through order IDs and identifying individual download events by download count, it is possible to quickly locate potentially leaked digital data from risky organizations, greatly enhancing the ability to control data flow and trace responsibility for security incidents.

[0138] A multi-dimensional behavioral baseline profile is independently established and dynamically updated for each download organization, specifically:

[0139] Collect historical behavioral data of download organizations over a continuous time period to construct a multi-dimensional behavioral feature set, including download frequency time series distribution, cluster analysis of typical download periods, statistical distribution of single download quantity, download file type preference matrix, and geographic density heat map of access IP.

[0140] Each dimension feature is normalized and weighted, and a weighted moving average algorithm based on time decay factor is used to dynamically update the baseline values ​​of each dimension to ensure that the behavioral profile evolves adaptively with the operation cycle.

[0141] Set a dynamic deviation threshold matrix, which is automatically adjusted according to the confidence interval based on the historical statistical values ​​of the volatility of each dimension of behavior.

[0142] When the deviation of any dimension's real-time behavioral data from the baseline exceeds the corresponding threshold, or when multiple dimensions deviate simultaneously, a warning signal of the corresponding level is triggered, and the process enters the manual review stage after the warning is triggered.

[0143] The technical effects of the above solution are as follows: By constructing and dynamically updating a multi-dimensional behavioral baseline profile of the downloading organization, refined modeling and real-time anomaly detection of downloading behavior are achieved. This enables the system to adaptively learn the normal behavioral patterns of each organization and accurately identify single or collaborative behavioral anomalies based on dynamic deviation thresholds. Consequently, it can quickly trigger tiered warnings when potential data leaks or violations occur. This mechanism not only significantly improves the accuracy and timeliness of risk identification and reduces false alarms and false negatives, but also ensures the traceability and reliability of the handling process through manual review and source tracing closed loop. This comprehensively strengthens the security control and risk defense capabilities of the digital file transfer process.

[0144] The manual review process after an alert is triggered further includes:

[0145] Automatically generate early warning reports, including deviation dimension radar charts, real-time behavior and baseline comparison curves, a list of associated download tasks, and recommendations of potentially risky organizations based on behavioral graph similarity;

[0146] Auditors use the auditing terminal to retrieve all operation logs, file download metadata, access IP geographic location change maps, and comparative analysis data of other organizations' behavior within the set period before the warning time of the organization under warning;

[0147] The reviewers will make a comprehensive judgment based on the multi-dimensional chain of evidence and categorize the review conclusions into three types: false alarm recovery, partial restriction of permissions or permanent ban and initiation of judicial remedies. The reviewers will also need to fill in the review comments and supporting evidence.

[0148] After the review is approved, the digital identity of the reviewer, the review timestamp, the processing conclusion and the fingerprint of the related evidence chain are recorded, and all data of this warning event is archived to the traceability database for subsequent model optimization and judicial evidence collection.

[0149] For cases confirmed as false alarms, the organization's behavioral baseline will be smoothed and corrected based on the audit findings, and such behavioral patterns will be given higher tolerance in subsequent monitoring.

[0150] The technical effects of the above solution are as follows: By constructing a structured early warning report and a multi-dimensional evidence chain retrieval mechanism, the accuracy and decision-making efficiency of manual review are significantly improved, enabling rapid identification of real threats and false alarms. Furthermore, based on behavioral graph similarity, potential risk recommendations and regional comparative analysis enhance the global perspective and correlation judgment ability of risk identification. By classifying review conclusions and associating them with digital identities and timestamps, the rationality and traceability of handling measures are ensured, and a complete evidence chain is provided for subsequent judicial evidence collection. At the same time, the behavioral baseline can be smoothly corrected and the monitoring strategy can be dynamically adjusted in the event of false alarms, thereby realizing the self-learning and continuous optimization of the risk prevention and control mechanism. This ensures security while continuously improving the system's intelligent adaptability and operational efficiency.

[0151] How it works: By initiating a digital product application order and providing relevant information, a unique digital file is generated. Detailed download records are also created during the download of the digital file, providing a basis for subsequent traceability. The digital file is then re-encrypted based on the download records, further enhancing its security during transmission and preventing unauthorized modification or theft during download. When batch or consecutive digital files are leaked, specialized tools analyze the leaked information to quickly and accurately trace the source of the leak, thereby identifying potentially risky organizations. This effectively improves the security traceability of digital files and reduces the risks associated with data breaches.

[0152] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0153] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention.

Claims

1. A method for secure provenance of digital files, characterized in that, Comprise: The brand initiates the commodity digital application order in the system, and provides the application order quantity and digital rule information. After the platform checks the information, the unique digital file is automatically generated; The download organization finds the digital application information that needs to be downloaded in the platform according to the needs, clicks the download button, and generates a download record; According to the download record, the digital file is obtained, and the digital file is encrypted again and provided for download; The printing factory downloads the encrypted digital file to the local, and prints it into labels and packaging materials and uses it in the commodity; After the consumer scans the code, the original digital information is parsed through the URL scanned by the consumer, and is used for anti-fake information query; When the digital code is leaked in batches or consecutively, the leaked digital information is obtained, the digital code is parsed through the tool, the correct digital information and encrypted download information are parsed, and the parsed information is used for tracing in the database to locate the risk organization causing the leakage; Also comprise: At each download, the accurate time stamp of this download is generated through a hash operation to generate a 6-bit segment, and is combined with a 5-bit letter ciphertext generated by encrypting and compressing the unique digital code and a 1-bit download count identifier to form an inseparable dynamic check code; The dynamic check code is tightly embedded in the final URL provided to the consumer. After the consumer scans the code, the dynamic check code is automatically stripped and the timestamp information in the dynamic check code is parsed and compared with the current time of the server; According to the life cycle characteristics of different types of commodities, preset different effective life cycle thresholds; if the difference between the query time and the embedded timestamp exceeds the corresponding threshold, it is directly determined that the code is a invalid risk code, the subsequent anti-fake information query process is terminated, and the consumer is prompted that the query is overdue; At the same time, a multi-dimensional behavior baseline portrait of each download organization is independently established and dynamically updated, which includes download frequency, time period, quantity, download file type and regional access feature information; When the behavior of any download organization deviates from its historical baseline in real time, an early warning is automatically triggered based on a preset deviation threshold, which is dynamically adjusted according to the historical behavior of the organization; After the early warning is triggered, all download tasks of this time and the organization in the future are forcibly suspended, and enter the manual review process, while automatically associating all download records of the organization in the near future for cross comparison and analysis; After the review is passed, the review conclusion and the timestamp of resuming the download are recorded, and the whole process of the early warning and processing is included in the traceability database.

2. A method of secure provenance of a digital file as claimed in claim 1, wherein, According to the download record, the digital file is obtained, and the digital file is encrypted again and provided for download, comprising: According to the download digital order, the order is generated and stored in the server file, which contains the digital code and the URL link corresponding to the digital code; According to the downloaded document information, the information of the download order is obtained, and the order ID is recorded, wherein the download order information includes download time, download count, download organization and download user; According to the download information, each digital code in the digital file is encrypted again, and two encryption schemes are provided based on different customer needs; According to the encryption requirements, each digital code is re-encrypted, and the encrypted digital code is written into a new file to form a new digital file, which is provided for download; Among them, two encryption schemes are provided based on different customer needs, including: The code itself and the corresponding URL link are both encrypted; The code itself is encrypted, and the URL link remains viewable.

3. A method of secure provenance of a digital file as claimed in claim 2, wherein, For high security requirements, the code itself and the corresponding URL link are both encrypted, specifically: Extract the original code URL from the code file; Use symmetric encryption to encrypt the data part of the original code URL; After encryption, combine the encrypted data part with the order ID to form a new string; After two encryptions, the final encrypted URL is obtained, which contains data processed by two symmetric encryptions, and the original code file URL is obtained by decryption.

4. The method of claim 2, wherein, Encrypt the code itself, and the URL link remains viewable, specifically: Get the original code URL in the code file, and get the code verification code; The verification code needs to be regenerated, and the generation rule is: Get the unique code in the file, perform symmetric encryption algorithm, generate encrypted ciphertext, and compress the ciphertext to 5 letters; In addition, set the last digit of the verification code to the number of downloads, and the number of times is recorded from 1 to Z, a total of 33 letters, including 1-9, A-Z, among them, A-Z excluding I, O letters; Record 1 for the first time, and add 1 for subsequent downloads, with a maximum of 33 download records, and the verification code will change to new content every time the code is downloaded, and a new code file is formed by encryption. Among them, the code verification code is the last 6 digits of the URL link, and when the record value exceeds 9, the record A will be recorded, and the increase will continue until Z.

5. The method of claim 1, wherein, Use the parsed information to trace back in the database, including tracing back the download history through the order ID and locking single download events through the number of downloads.

6. A method of secure provenance of a digital file as claimed in claim 5, wherein, Tracing back the download history through the order ID, specifically: Scan to get URL link information containing target markers; According to the preset URL rule, extract the data after the target marker, and remove the specified length of characters at the end to get the encrypted code; Use the symmetric encryption key to parse the encrypted code to get the original code and the associated order ID; Use the original code obtained by decryption to query in the database to confirm whether the original code exists and is valid, which is used to exclude fake or invalid code interference; If the original code exists, use the order ID obtained by decryption to query the information when the original code is downloaded, including download time, download times, download organization, and download user; According to the download information obtained by querying, the risk organization is located.

7. A method of secure provenance of a digital file as claimed in claim 6, wherein, Lock single download event through the number of downloads, specifically: Scan to get URL link information containing target markers; According to the preset URL rule, extract the data after the target marker, and remove the specified length of characters at the end to get the encrypted code; Use the encrypted code as the original code to query whether the original code exists in the database to confirm that the code is correct and valid; Under the premise of confirming that the code is correct, extract the last 6 digits of the URL, where the last digit represents the number of downloads; According to the original code, query the original application order corresponding to the original code, and obtain the historical download times of the original application order through the order ID; According to the information of the number of downloads of the digital code when downloading the digital file, the risk organization that leaks the digital code is located, wherein the historical download data information includes download time, number of downloads, download organization and download user.

8. The method of claim 1, wherein, The digital file contains unique digital code and digital URL link information, and the unique digital code is composed of the first 16 digits. The digital file is used to convert into a QR code and printed on the surface of the product.

9. The method of claim 1, wherein, A multi-dimensional behavior baseline portrait is established and dynamically updated for each download organization, specifically: Collecting historical behavior data of the download organization in a continuous time period, constructing a multi-dimensional behavior feature set including download frequency time series distribution, typical download time period clustering analysis, single download quantity statistical distribution, download file type preference matrix and regional access IP geographic density heat map; Each dimension feature is normalized and weighted, and the weighted moving average algorithm based on time decay factor is used to dynamically update the baseline value of each dimension, ensuring that the behavior portrait evolves adaptively with the operation period; Set a dynamic deviation threshold matrix, which automatically adjusts according to the confidence interval based on the historical statistical value of the volatility of each dimension behavior; When the deviation of any dimension real-time behavior data from the baseline exceeds the corresponding threshold, or multiple dimensions occur simultaneously, trigger the corresponding level of early warning signal, and after the early warning is triggered, enter the manual review process.

10. A method of secure provenance of a digital file as claimed in claim 9, wherein, The manual review process after the early warning further includes: Automatic generation of early warning report, including deviation dimension radar chart, real-time behavior and baseline comparison curve, associated download task list, and potential risk organization recommendation based on behavior graph similarity; The reviewer retrieves all operation logs, file download metadata, access IP geographic location transition chart and behavior comparison analysis data of other organizations in the same region of the early warning organization within a set period before the early warning time point through the review terminal; The reviewer makes a comprehensive judgment according to the multi-dimensional evidence chain, and divides the review conclusion into three categories: false alarm recovery, restriction of part of the rights or permanent disablement and start of judicial traceability, and needs to fill in the review opinion and basis; After the review is passed, record the digital identity of the reviewer, review timestamp, processing conclusion and associated evidence chain fingerprint, and archive the full data of this early warning event to the traceability database for subsequent model optimization and judicial evidence; For the situation confirmed as false alarm, according to the review conclusion, the behavior baseline of the organization is corrected smoothly, and higher tolerance is given to this kind of behavior pattern in subsequent monitoring.