Security management and control method and system for secret-related document output based on secret level dynamic identification

CN121834865BActive Publication Date: 2026-08-21BEIJING JIAHUA LONGMA TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202512045534.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-31
Publication Date
2026-08-21
Estimated Expiration
2045-12-31

AI Technical Summary

Technical Problem

针对现有技术的不足,本发明提供了基于密级动态识别的涉密文档输出安全管控方法及系统,解决了现有技术未对涉密文档输出全过程建立连续一致的动态约束机制,导致多阶段链路中的风险状态难以被整体识别与持续管控的问题

Benefits of technology

(1)该基于密级动态识别的涉密文档输出安全管控方法及系统,通过将涉密文档在登录判定至设备执行全过程中的密级变化过程进行连续刻画,实现对输出行为整体一致性的动态管控,避免仅依赖单一节点状态进行放行所带来的链路失真风险。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121834865B_ABST
    Figure CN121834865B_ABST
Patent Text Reader

Abstract

The application discloses a secret-level dynamic identification-based secret document output security management and control method and system, and relates to the technical field of secret resource security management and control. The secret-level dynamic identification-based secret document output security management and control method and system comprises the following steps: S1, collecting and preprocessing evolution state data, link execution data and time span data in a secret document output process, and constructing a standardized document security data set; S2, evaluating output link consistency and controlling an output execution path; S3, performing secret-level checking on the effective state of the output link, and determining whether an output request enters an isolated recording state; and S4, comprehensively judging the closed state of the output behavior in the time dimension and the process dimension, and determining a corresponding retention organization mode. The method solves the problem that a continuous and consistent dynamic constraint mechanism is not established for the whole process of secret document output in the prior art, so that the risk state in the multi-stage link is difficult to be identified and continuously controlled as a whole.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security management and control technology for classified resources, specifically to a method and system for security management and control of classified document output based on dynamic identification of classification level. Background Technology

[0002] With the continuous improvement of enterprise informatization and digital office levels, the frequency of generation, circulation, and output of classified documents within enterprises is constantly increasing. Printing, exporting, and sending out documents have become high-risk aspects of information security management. To reduce the risk of leakage of classified information during the output process, existing technologies typically constrain and manage document output behavior through user authentication, document classification labeling, approval process control, and output device permission management. In specific implementations, some output control solutions divide user permissions based on login network location. By mapping the user's network address to a predefined classification area, the range of document classification levels the user can select is limited. Simultaneously, combined with an automatic approval process matching mechanism, an approval path corresponding to the document's classification level is triggered after the user submits an output request, thus achieving permission verification before output. On the other hand, to prevent classified documents from being output on devices that do not meet security requirements, some systems also configure classification labels for output devices and verify the consistency between the document classification level and the device classification level during the execution phase to reduce the risk of "high-class documents printed in a low-class manner" or "unauthorized output." After output is completed, existing technologies typically generate and centrally store content snapshots as a basis for post-audit and traceability. Some solutions further introduce independent audit access environments, using network location and role-based access control to isolate and manage the viewing and processing of content snapshots, thereby enhancing the security of the audit process itself. These technical measures, to a certain extent, achieve segmented control over the output of confidential documents, providing support for enterprises to build a basic output security defense.

[0003] For example, the invention patent with announcement number CN117131534B discloses a blockchain-based method for the security management of classified documents, specifically relating to the field of document management technology. The method includes the following steps: verifying the identity of users accessing classified documents; marking verified users as authorized users and obtaining access records for the current period to form an access data table; statistically analyzing abnormal access situations of authorized users within the current monitoring period, confirming and marking abnormal factors; conducting risk analysis on the blockchain operating environment where the classified documents are located, statistically calculating the operating environment risk coefficient, and comparing it with a preset operating environment risk coefficient threshold to determine whether it exceeds the preset operating environment risk coefficient threshold. This application, through real-time monitoring of classified documents, collects raw data from authorized users, establishes an operating environment risk coefficient, a security operation coefficient, and a comprehensive management index. The comprehensive management index is used to assess the security of classified documents and determine whether they are in a secure state.

[0004] For example, the invention patent with publication number CN112115433B relates to the field of computer technology, and in particular to a method for tracing classified documents, a document retrieval server, and a security server. The method includes: receiving a request from a user terminal to retrieve a classified document; obtaining the corresponding classified document according to the request; generating feature information of the retrieved classified document based on the request; generating a transparent layer based on the feature information; and merging the classified document and the transparent layer into an uneditable copy of the classified document and sending it to the user terminal. Using this embodiment, the retrieved copy of the classified document can be tracked, thereby alerting users to the importance of classified documents and preventing subsequent disclosure of classified documents to external networks.

[0005] However, existing classified document output control schemes often focus on verifying the status of a single node or stage. For example, they assume that the output conditions are met after the approval node is completed, or they only perform a security level consistency check at the moment of device execution. They lack a continuous characterization of the correlation between multiple stages such as login determination, security level selection, approval execution, device swiping, and content retention. In high-frequency output and concurrent operation scenarios, there may be queue delays, job insertions, or state drifts between approval and device execution. Single-point verification methods cannot reflect the dynamic changes in the overall output chain status. In addition, existing audit retention methods are mostly based on content snapshots. There is a lack of structured correlation between audit information and the security level changes and link verification status that the document undergoes during the output process. This results in audit analysis often remaining at the result level, making it difficult to trace the consistency and integrity of the output behavior throughout the entire process.

[0006] To address the above issues, there is an urgent need for a method and system for the security management of classified document output based on dynamic identification of classification levels. Summary of the Invention

[0007] Technical problems to be solved To address the shortcomings of existing technologies, this invention provides a method and system for security management of classified document output based on dynamic identification of classification levels. This solves the problem that existing technologies do not establish a continuous and consistent dynamic constraint mechanism for the entire process of classified document output, making it difficult to identify and continuously manage risk states in multi-stage links.

[0008] Technical solution To achieve the above objectives, the present invention provides the following technical solution: a method and system for security control of classified document output based on dynamic identification of classification level, comprising: S1, collecting evolutionary state data, link execution data, and time span data during the output process of classified documents; preprocessing the evolutionary state data, link execution data, and time span data to construct a standardized document security dataset; S2, based on the standardized document security dataset, performing a consistency assessment on the consistency of the output link from the classification level evolution state throughout the entire output process of classified documents, and controlling the output execution path based on the consistency assessment results; S3, based on the standardized document security dataset, performing classification level verification on the effective state of the output link, and determining whether the output request enters the isolation record state based on the classification level verification results; S4, using the consistency assessment results and classification level verification results as input, comprehensively judging the closed state of the output behavior in the time dimension and process dimension, and determining the corresponding retention organization method based on the comprehensive judgment results.

[0009] Further, the specific steps for collecting evolution status data, link execution data, and time span data during the output process of classified documents are as follows: Divide the same classified document into four stages in a complete output link, including the login determination stage, the classification level selection stage, the approval execution stage, and the device execution stage, and generate a stage identifier record associated with the document's unique identifier for each stage; collect evolution status data corresponding to the same classified document at different stages, including: the classification level identifier value corresponding to each stage and its sequential number in the output link; collect link execution data of the classified document during the output process, including: document classification level identifier value, output device classification level identifier value, current user session classification level area identifier value, output device classification level area identifier value, approval completion identifier sequence number, approval identifier sequence number corresponding to the job in the device execution queue, output job identifier sequence number, and the currently selected job identifier sequence number at the device card swipe point; collect time span data corresponding to the output behavior, including: the actual duration of the same classified document at different stages, the start timestamp of the output behavior, and the end timestamp of the output behavior.

[0010] Furthermore, the specific steps for preprocessing evolutionary state data, link execution data, and time span data to construct a standardized document security dataset are as follows: After collecting the evolutionary state data, the integrity of the security classification identifier values ​​corresponding to each stage is verified, and stage records with missing security classification identifiers are removed; the consistency of the sequence numbers in the output link is checked, and they are reordered according to the stage order in the output process; after reordering, the security classification identifier values ​​of adjacent stages are aligned; after collecting the link execution data, the document security classification identifier value, the output device security classification identifier value, the current user session security classification area identifier value, and the security classification area identifier value of the output device are... The format is standardized; uniqueness verification is performed on the approval completion identifier number, the approval identifier number corresponding to the job in the equipment execution queue, the output job identifier number, and the currently selected job identifier number at the equipment card swipe point, and duplicate and missing records are removed; after collecting the time span data, the legality of the actual duration of each stage is verified, and stage records with negative durations and abnormal interruptions are removed; the time sequence consistency check is performed on the start timestamp and end timestamp of the output behavior; the evolution state data, link execution data, and time span data that have completed the standardization process are normalized using the minimum-maximum linear normalization algorithm to construct a standardized document security dataset.

[0011] Furthermore, the specific steps for evaluating the consistency of the output link based on the standardized document security dataset and the evolution of the classification level throughout the entire output process of classified documents are as follows: Calculate the absolute value of the difference between the classification level identifier values ​​between adjacent stages to obtain the stage classification level transition amplitude value; subtract the actual duration of the current stage from the actual duration of the next stage to obtain the time interval between adjacent stages; subtract the sequence number of the current stage from the sequence number of the next stage in the output link to obtain the stage sequence advancement amount; divide the stage classification level transition amplitude value by the time interval between adjacent stages and then multiply it by the stage sequence advancement amount to obtain the single-stage classification level evolution contribution amount; add up the single-stage classification level evolution contributions of each stage to obtain the classification level consistency evolution value.

[0012] Furthermore, the specific steps for controlling the output execution path based on the consistency assessment result are as follows: After calculating the security level consistency evolution value, the security level consistency evolution value corresponding to the current output link is compared with the consistency evolution threshold; when the security level consistency evolution value is less than or equal to the consistency evolution threshold, the security level area identifier value bound to the current output session remains unchanged, and the already matched approval process result is used to directly send the current output request into the device selection and card swiping execution stage; during the device execution stage, a list of output devices consistent with the current document security level identifier value is presented to the user according to the output device security level whitelist rules, and the corresponding physical output operation is executed after card swiping confirmation; at the same time, the content snapshot corresponding to the output task is sent according to the current encrypted transmission path. The content viewing section within the bastion host network segment is written directly to the output request. When the security level consistency evolution value exceeds the consistency evolution threshold, the current output request is terminated and the device execution phase is initiated. The generated device card swipe trigger state is frozen, and no executable output device is presented to the user. At the same time, the output request is re-associated with the corresponding current user session security level area identifier value. An approval process consistent with the current user session security level area identifier value is initiated to re-verify the steps. The current security level consistency evolution value, the security level identifier values ​​at each stage, and the actual duration at each stage are written to the bastion host content viewing section to form an independent record. Only accounts located within the bastion host network segment with audit role permissions are allowed to view and process the independent record until the current output link is closed.

[0013] Furthermore, the specific steps for verifying the security level of the output link based on the standardized document security dataset are as follows: Subtract the output device security level identifier from the current document security level identifier value and take the square of the result to obtain the document-device security level deviation value; subtract the output device's security level region identifier value from the current user session security level region identifier value and take the square of the result to obtain the session device region deviation value; multiply the document-device security level deviation value and the session device region deviation value, add one, and take the natural logarithm to obtain the security level region coupling deviation; calculate the approval completion identifier sequence number minus the device execution team... The absolute value of the difference between the approval identifier sequence numbers corresponding to the tasks in the column is used to obtain the approval identifier difference; the absolute value of the difference between the output task identifier sequence number and the currently selected task identifier sequence number at the device card swiping point is used to obtain the task identifier difference; the approval identifier difference is multiplied by the task identifier difference and then the square root is calculated to obtain the execution link comprehensive deviation; the security level area coupling deviation is added to the execution link comprehensive deviation to obtain the security level area coupling deviation reuse; the security level area coupling deviation reuse is divided by the sum of the security level area coupling deviation reuse and one to obtain the link security level verification value.

[0014] Furthermore, the specific steps for determining whether an output request enters the isolation record state based on the security level verification result are as follows: After calculating the link security level verification value, the output process is directly diverted based on whether the current link security level verification value is zero; when the link security level verification value is zero, the established mapping relationship between the approval result and the device security level whitelist is maintained, the output request is directly sent to the card swiping execution queue of the corresponding output device, and after the output is completed, the content snapshot is written to the bastion host content viewing part for retention according to the encrypted transmission path; when the link security level verification value is not zero, the process of the current output request entering the device execution queue is interrupted, the card-swipeable output device option is not opened, and the original state of the output request in the approval completion stage is retained; the link security level verification value, the corresponding approval completion identifier number, the output device security level identifier value, and the current user session security level area identifier value are written to the bastion host content viewing part to form an independent record, and only accounts located in the bastion host network segment and with audit role permissions are allowed to perform subsequent processing on the independent record.

[0015] Furthermore, the specific steps for comprehensively determining the closure status of the output behavior in the time and process dimensions, using the consistency assessment result and the security level verification result as input, are as follows: The square of the security level consistency evolution value is added to one and then the natural logarithm is taken to obtain the security level evolution logarithm mapping value; one is subtracted from the link security level verification value to obtain the link closure maintenance value; the output behavior end timestamp of the classified document is subtracted from the output behavior start timestamp and then divided by the output behavior end timestamp to obtain the output behavior time span value; the security level evolution logarithm mapping value, the link closure maintenance value, and the output behavior time span value are multiplied together to obtain the output link audit mapping value.

[0016] Further, the specific steps for determining the corresponding retention organization method based on the comprehensive judgment result are as follows: Real-time comparison of the current output link audit mapping value with the audit mapping threshold, where the audit mapping threshold includes a first audit threshold and a second audit threshold, and the first audit threshold is greater than the second audit threshold; when the output link audit mapping value is less than or equal to the second audit threshold, the content snapshot of the current output task and the security level identifier value formed at each stage are written into the bastion host content viewing part. Simultaneously, during the writing process, the security level consistency evolution value, the link security level verification value, and the output behavior start timestamp and output end timestamp are written as associated fields into the same record entry, and the audit index number of the output task is generated synchronously on the output device side, and the binding registration of the index number and the output job identifier sequence number is completed; when the output link audit mapping value is greater than the second audit threshold and less than or equal to the first audit threshold, the content snapshot corresponding to the current output task is... The evolution status data during the output process is written to the bastion host content viewing section, and the approval completion identifier number, the approval identifier number corresponding to the job in the device execution queue, and the currently selected job identifier number at the device card swipe point are appended to the same record entry. At the same time, the complete record status of the output task in the bastion host content viewing section is maintained, and it is not merged or overwritten when the job on the output device side ends. When the output link audit mapping value is greater than the first audit threshold, the current output task stops generating new audit index writing operations on the output device side. The generated content snapshot, evolution status data, security level consistency evolution value, link security level verification value, and the corresponding output behavior start timestamp and output behavior end timestamp are written to the bastion host content viewing section and stored as a separate audit record entry. At the same time, the audit record entry is restricted to be accessed and processed only when the bastion host network segment access conditions are met and the audit role permissions are available.

[0017] The second aspect of this invention provides a security control system for the output of classified documents based on dynamic identification of security levels, comprising: a multi-stage data acquisition module for collecting evolutionary state data, link execution data, and time span data during the output process of classified documents, preprocessing the evolutionary state data, link execution data, and time span data to construct a standardized document security dataset; a cross-stage security level consistency evolution analysis module for evaluating the consistency of the output link based on the security level evolution state throughout the entire output process of classified documents using the standardized document security dataset, and controlling the output execution path based on the consistency evaluation results; a link security level constraint continuous verification module for verifying the effective state of the output link based on the standardized document security dataset, and determining whether the output request enters the isolation record state based on the security level verification results; and a link integrity retention and audit mapping module for comprehensively judging the closed state of the output behavior in the time and process dimensions using the consistency evaluation results and security level verification results as input, and determining the corresponding retention organization method based on the comprehensive judgment results.

[0018] Beneficial effects The present invention has the following beneficial effects: (1) The method and system for security control of classified document output based on dynamic identification of classification level continuously depicts the process of classification level change of classified document from login judgment to device execution, thereby realizing dynamic control of overall consistency of output behavior and avoiding the risk of link distortion caused by relying on the status of a single node for release.

[0019] (2) The method and system for security control of classified document output based on dynamic identification of security level continuously constrains and verifies the output link status after approval, so that the output execution is always subject to the change of the current link status, and prevents the execution deviation problem caused by concurrent operation or queue delay.

[0020] (3) The method and system for security control of classified document output based on dynamic identification of classification level can achieve complete process retention of each output request by structurally associating the execution process of output behavior with stage identification information, thereby improving the traceability and completeness of the audit object.

[0021] (4) The method and system for security control of classified document output based on dynamic identification of security level, by combining the independent retention and access control structure of the bastion host, forms an independent and restricted audit environment for output behavior, so that the output content and its behavior trajectory are controlled synchronously, thereby improving the overall audit security and management standardization.

[0022] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description

[0023] Figure 1 This is a flowchart of the security control method for outputting classified documents based on dynamic identification of security level according to the present invention. Figure 2 This is a structural diagram of the classified document output security control system based on dynamic classification level identification of the present invention; Figure 3 This is a bar chart showing the output link audit mapping values ​​involved in this invention; Figure 4 This is a flowchart illustrating the safety management process for printing operations as described in this invention. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] Please see Figures 1-4 This invention provides a technical solution: a method and system for security control of classified document output based on dynamic identification of classification level, comprising: S1, collecting evolution status data, link execution data, and time span data during the output process of classified documents; preprocessing the evolution status data, link execution data, and time span data to construct a standardized document security dataset; S2, based on the standardized document security dataset, performing a consistency assessment on the consistency of the output link from the classification level evolution status throughout the entire output process of classified documents, and controlling the output execution path based on the consistency assessment result; S3, based on the standardized document security dataset, performing a classification level verification on the effective status of the output link, and determining whether the output request enters the isolation record state based on the classification level verification result; S4, using the consistency assessment result and the classification level verification result as input, comprehensively judging the closed state of the output behavior in the time dimension and process dimension, and determining the corresponding retention organization method based on the comprehensive judgment result.

[0026] Specifically, the steps for collecting evolutionary status data, link execution data, and time span data during the output process of classified documents are as follows: To ensure the controllability and uniqueness of the scope of classified document output behavior during the link analysis process, the same classified document is first clearly divided into four consecutive stages in a complete output link, namely, the login determination stage, the classification level selection stage, the approval execution stage, and the device execution stage. For each stage, a stage identifier record is generated and associated one-to-one with the unique identifier of the classified document to represent the status position of the document in the corresponding stage. The stage identifiers are numbered sequentially within the same output link, and the sequential numbering is represented by natural numbers. The identifiers are kept unique within the same output link to avoid identifier confusion between different stages and different output behaviors.

[0027] Based on this, evolutionary status data of the same classified document at different stages are collected. The evolutionary status data includes the classification level identifier value corresponding to each stage and the sequential number of that stage in the output link. Among them, the classification level identifier value is limited to the range of a predefined classification level set, which includes three classification levels: top secret, confidential, and secret, and is mapped to non-overlapping numerical identifiers to ensure the distinguishability and consistency of classification level expression in numerical space; the sequential number is used to reflect the chronological relationship of the stages in the output link to ensure that the classification level evolution analysis can be carried out based on a clear time and process sequence.

[0028] Simultaneously, link execution data is collected during the output process of classified documents. This data describes the actual matching status of the output link in the approval and device execution stages. It includes the document's security classification identifier, the output device's security classification identifier, the security classification zone identifier of the current user session, the security classification zone identifier of the output device, the approval completion identifier, the approval identifier corresponding to the job in the device execution queue, the output job identifier, and the identifier of the currently selected job at the device's card reader. All identifiers are limited to natural numbers and remain unique within their respective applicable link ranges to accurately verify the correspondence between approval results, the device execution queue, and the actual output job.

[0029] The data collected covers the time span of output activities. This time span data is used to characterize the integrity and continuity of the output of classified documents in the time dimension, including the actual duration of the same classified document at different stages, as well as the start and end timestamps of the output activities. By jointly recording the duration of each stage and the overall start and end times, a reliable time benchmark can be provided for subsequent output chain integrity assessment and audit mapping analysis, thereby ensuring the traceability and consistency of the classified document output process in both the process and time dimensions.

[0030] This implementation plan unifies the modeling and constraints of the stages, status identifiers, and behavioral characteristics of the same classified document in a complete output chain. By clearly defining the boundaries of each stage—login determination, classification level selection, approval execution, and device execution—and generating a unique stage identifier record for each stage, it ensures that the positional relationship and evolution sequence of the document throughout the entire output process are clear and traceable. Simultaneously, by systematically collecting the classification level identifier values, sequence numbers, chain execution identifiers, and time span information for each stage, classification level changes, approval results, and device execution status can be correlated and verified within the same semantic space. This provides an accurate, continuous, and comparable data foundation for subsequent cross-stage classification level consistency analysis, continuous verification of chain constraints, and auditing of output behavior integrity, avoiding audit deviations caused by identifier conflicts and unclear stage boundaries.

[0031] Specifically, the preprocessing of evolutionary state data, link execution data, and time span data to construct a standardized document security dataset involves the following steps: After completing the collection of evolutionary state data, the integrity of the security classification identifier values ​​corresponding to each stage is first verified, and stage records with missing security classification identifiers are identified and removed to ensure that subsequent analysis is based only on valid stages with clear security classification attributes. Subsequently, the consistency of the sequential numbers in the output link is checked, and the stage records are reordered according to the order of login judgment, security classification selection, approval execution, and device execution in the output process. After the order is reordered, the security classification identifier values ​​of adjacent stages are aligned one by one to ensure the continuous expression of security classification evolution in the process dimension and avoid evolutionary breaks caused by stage misalignment.

[0032] After completing the collection of link execution data, the document security level identifier, output device security level identifier, current user session security level area identifier, and output device security level area identifier are processed with unified encoding and format specifications to enable direct comparison of security level and area identifiers from different sources within the same identifier space. At the same time, the uniqueness of the approval completion identifier, the approval identifier corresponding to the job in the device execution queue, the output job identifier, and the currently selected job identifier at the device card swipe point are verified, duplicate records are cleaned up and empty records are removed, thereby ensuring that the mapping relationship between the approval link, the device queue, and the actual output behavior remains one-to-one.

[0033] After completing the time span data collection, the legality of the actual duration corresponding to each stage is verified, and invalid stage records with negative durations or those caused by abnormal interruptions are removed. Then, a timing consistency check is performed on the start timestamp and end timestamp of the output behavior to ensure that the start and end relationship of the overall output behavior on the timeline is clear and there is no backtracking conflict.

[0034] After completing the above verification and organization operations, the evolutionary state data, link execution data, and time span data that have passed the standardization process are uniformly normalized using the minimum-maximum linear normalization algorithm. This maps data of different dimensions to a unified numerical range, ultimately forming a standardized document security dataset with comparability and continuity, providing a stable data foundation for subsequent consistency analysis, link verification, and audit mapping calculations.

[0035] This implementation plan eliminates data uncertainties caused by missing stages, disordered sequences, conflicting identifiers, and time anomalies by systematically verifying, rearranging, and normalizing evolutionary state data, link execution data, and time span data. This ensures a continuous and accurate representation of the evolutionary relationship of the classified document output process in both the workflow and time dimensions. By unifying the classification level and regional identifier formats and strengthening the unique constraints of various serial numbers, a stable one-to-one correspondence is established between approval identifiers, equipment execution behaviors, and actual output operations. Based on this, multi-source heterogeneous data is mapped to a unified numerical range, forming a document security data foundation with consistent structure and comparable scale. This provides reliable input for subsequent analysis of classification level consistency evolution, link constraint verification, and audit mapping calculations, avoiding interference from noise in the original data to the security judgment results.

[0036] Specifically, based on a standardized document security dataset, the consistency assessment of the output link consistency from the evolution of the classification level throughout the entire process of classified document output involves the following steps: Calculate the absolute value of the difference between the classification level identifier values ​​between adjacent stages to obtain the stage classification level transition amplitude value; subtract the actual duration of the current stage from the actual duration of the next stage to obtain the time interval between adjacent stages; subtract the sequence number of the current stage from the sequence number of the next stage in the output link to obtain the stage sequence advancement amount; divide the stage classification level transition amplitude value by the time interval between adjacent stages and then multiply it by the stage sequence advancement amount to obtain the single-stage classification level evolution contribution amount; sum the single-stage classification level evolution contributions of each stage to obtain the classification level consistency evolution value.

[0037] The formula for calculating the security level consistency evolution value is: In the formula, The value of the security classification identifier corresponding to the i-th stage is used to quantify the security level status of the classified document at this stage. It is the basic expressive quantity for depicting the evolution path of the security classification. It comes from the security classification area mapping table, document security classification labeling information, approval level record table, and output device security classification label table, and the level identifier corresponding to the current stage. Indicates the first The security classification label value corresponding to the stage is used to quantify the security level status of classified documents at that stage. It is the basic expressive quantity for depicting the evolution path of security classification. It comes from the security classification area mapping table, document security classification label information, approval level record table, and output device security classification label table, and the level label corresponding to the current stage. It represents the actual duration of the i-th stage, used to quantify the length of time a classified document stays in that stage, and is an important time scale reflecting the rhythm of changes in classification level. It is derived from the timestamp information automatically recorded by the system at the beginning and end of the stage. Indicates the first The actual duration of a phase is used to quantify how long classified documents remain in that phase. It is an important time scale reflecting the rhythm of changes in classification levels and is derived from the timestamp information automatically recorded by the system at the beginning and end of the phase. Indicates the first The sequential number of the stage in the output link is used to characterize the structural position of the current security level in the entire output process. It is a structural identifier that ensures that the security level evolution unfolds along the predetermined process direction. It comes from the fixed sequential numbering of the login stage, security level selection stage, approval stage and equipment execution stage in the output process definition. It represents the sequential number of the i-th stage in the output link, which is used to characterize the structural position of the current security level in the entire output process. It is a structural identifier that ensures the security level evolution unfolds along the predetermined process direction. It comes from the fixed sequential numbering of the login stage, security level selection stage, approval stage and equipment execution stage in the output process definition.

[0038] This implementation plan continuously depicts the changing relationships between the classification levels of classified documents at each stage of the entire output process. By uniformly quantifying the evolution of the classification status corresponding to the login determination stage, classification level selection stage, approval execution stage, and device execution stage, the classification constraints originally scattered across different process nodes are integrated into a directly comparable overall result. This avoids the link break problem caused by judging based on the classification status of only a single stage. Through the calculation of this formula, the implicit classification level changes between approval completion and device execution can be explicitly reflected in the unified result, ensuring that the output control process is always based on the complete link classification level evolution state, providing a stable and consistent judgment basis for the continued execution, re-verification, and isolation processing of output requests.

[0039] Specifically, the steps for controlling the output execution path based on the consistency assessment results are as follows: After calculating the security level consistency evolution value, the security level consistency evolution value corresponding to the current output link is compared one by one with the pre-configured consistency evolution threshold to determine the stability and risk level of the output link in the process dimension. The device whitelist is uniformly maintained by the security administrator according to the document security level mapping table. Each output device in the whitelist has a one-to-one correspondence with a clear security level identifier value, and the whitelist only covers the range of devices that are consistent with the security level mapping table. When security policy adjustments and output device transfers occur, the whitelist content is synchronously updated to ensure that the range of selectable devices is always consistent with the current security level policy.

[0040] When the security level consistency evolution value is less than or equal to the consistency evolution threshold, the security level area identifier value bound to the current output session remains unchanged, and the approved process result that has been matched is used, allowing the current output request to enter the device selection and card swipe execution stage. During the device execution stage, the set of output devices that match the current document's security level identifier value is displayed to the user according to the device whitelist rules. After card swipe confirmation is completed, the corresponding physical output operation is executed. At the same time, the content snapshot corresponding to the output task is written to the content viewing section within the bastion host network segment according to the current encrypted transmission path to form a traceable output record.

[0041] When the security level consistency evolution value exceeds the consistency evolution threshold, the current output request is immediately blocked from entering the device execution stage, and the generated device card-swiping trigger state is frozen to prevent the output behavior from continuing. Simultaneously, no executable output devices are displayed to the user. Subsequently, the output request is re-bound to the security level area identifier value corresponding to the current user session, and an approval process review step consistent with that security level area identifier value is initiated. The current security level consistency evolution value, the security level identifier values ​​corresponding to each stage, and the actual duration of each stage are uniformly written into the bastion host content viewing section, forming a separate audit record. This record can only be accessed and processed by accounts located within the bastion host network segment with audit role permissions until the current output link is explicitly closed, thereby ensuring that high-risk output behaviors are fully audited and constrained within the control scope.

[0042] This implementation plan introduces a security level consistency evolution threshold determination mechanism to clearly separate the stability of the output link from the subsequent execution path. This ensures that low-risk output behaviors can smoothly complete device execution under the constraints of predetermined approval results and security level areas, while high-risk output behaviors are intercepted in time before entering physical execution and transferred to the enhanced audit process. By combining the device whitelist rules maintained by the security administrator and consistent with the security level mapping, it ensures that the range of executable output devices is always controlled and strictly matches the current document security level, thereby preventing deviations from the security level in the device selection process. When the security level consistency evolution value exceeds the threshold, the card swipe trigger state is frozen, the approval verification corresponding to the security level area is restarted, and an independent audit record is generated. This ensures that abnormal output behaviors remain traceable and constrained in both the process and time dimensions. Ultimately, this achieves hierarchical control, risk isolation, and audit focus for the output behavior of classified documents, improving the accuracy and security of overall output management.

[0043] Specifically, based on a standardized document security dataset, the specific steps for performing security level verification on the valid status of the output link are as follows: The document-device security level deviation is obtained by subtracting the output device security level from the current document security level and taking the square of the result. The squaring operation is used to amplify the deviation caused by the inconsistency in security levels and to ensure that the deviation result is non-negative. The session device region deviation is obtained by subtracting the output device security level region from the current user session security level region and taking the square of the result. This is used to characterize the degree of numerical offset between the session security level region and the device security level region. The document-device security level deviation is multiplied by the session device region deviation and then the natural logarithm is added to obtain the security level region coupling deviation. The addition of one term is used to avoid the undefined logarithm when the deviation is zero. It is also specified that when both types of deviations are zero, the logarithmic result is ln(1)=0, and this zero value is used as the subsequent flow division decision. The valid numerical input in the segment participates in the determination of whether to enter the zero deviation branch, and a fixed numerical precision is used in the calculation process to prevent the zero value judgment from being distorted due to floating point error; the absolute value of the difference between the approval completion identifier sequence number and the approval identifier sequence number corresponding to the job in the device execution queue is calculated to obtain the approval identifier difference; the absolute value of the difference between the output job identifier sequence number and the currently selected job identifier sequence number at the device card swiping point is calculated to obtain the job identifier difference; the approval identifier difference and the job identifier difference are multiplied and the square root is calculated to obtain the execution link comprehensive deviation; the security level area coupling deviation is added to the execution link comprehensive deviation to obtain the security level area coupling deviation reuse; the security level area coupling deviation reuse is divided by the sum of the security level area coupling deviation reuse and one to obtain the link security level verification value.

[0044] The formula for calculating the link security level check value is: ; In the formula, This represents the document security classification identifier value, which is used to characterize the security level status of a classified document during the output application stage. It is the basic identifier for the security classification constraints of the output link and is derived from the document security classification field registered in the document output application record. This represents the security level identifier value of the output device, which is used to characterize the security level status of the target output device in the device whitelist. It is the direct basis for security level verification during the physical output stage and comes from the security level tag field associated with the device in the output device security level whitelist table. This represents the current user session security zone identifier value, which is used to characterize the network security zone status of the user login session. It is a network environment identifier that restricts the scope of output operations and comes from the security zone record generated by the login IP identification and security zone dynamic binding module. This represents the security zone identifier value to which the output device belongs. It is used to characterize the security zone status corresponding to the network accessed by the output device. It is a direct identifier for network boundary verification on the device side and comes from the zone identifier field in the mapping relationship table between the network segment accessed by the output device and the security zone. This indicates the approval completion identifier, a unique identifier used to characterize the completion of the document output approval process. It is a key index linking the approval result with the execution stage and originates from the approval sequence number record written by the system at the end of the approval process. This indicates the approval identifier sequence number corresponding to the job in the device execution queue. It is used to characterize the binding relationship between the current job to be executed by the device and the approval result. It is the direct basis for identifying queue misalignment and concurrent insertion, and it comes from the approval identifier field recorded in the job queue to be executed on the device side. This represents the output job identifier sequence number, which is used to characterize the unique job number corresponding to the document output request when it is generated. It is the job association identifier that runs through the output chain and comes from the job sequence number field generated and recorded by the system when the output job is created. This indicates the currently selected job identifier number at the device's card swipe point. It is used to characterize the actual output job selected by the device when the card swipe is triggered. It is a direct identifier for job consistency verification during the physical execution phase and originates from the job sequence number field bound in the device's card swipe trigger record.

[0045] In this implementation plan, the scattered security classification information, network area information, approval identification information, and job queue status within the critical segment from approval completion to device card swiping trigger are uniformly mathematically mapped, transforming the link constraint process, which originally relied on multi-point logical verification, into a single continuous numerical judgment process. This formula simultaneously incorporates deviations between document security classification and device security classification, deviations between user session area and device area, and misalignments between approval identification and device execution queue into the same calculation framework. This avoids link mismatches caused by concurrent queuing, job insertion, and status delays being ignored by single-point verification. This formula ensures that the approval result remains subject to link consistency constraints until entering the physical execution stage, guaranteeing that the output link maintains structural closure and a verifiable state throughout the entire process.

[0046] Specifically, the steps for determining whether an output request should enter the isolation record state based on the security level verification result are as follows: After completing the calculation of the link security level verification value, the output process is directly split according to whether the current link security level verification value is zero. The zero value judgment enables the immediate distinction between completely consistent output links and output links with deviations, so that the split logic is consistent with the aforementioned security level area coupling deviation calculation result.

[0047] When the link security level verification value is zero, the established mapping relationship between the approval result and the device security level whitelist remains unchanged, indicating that the current output behavior does not deviate in terms of security level matching, regional affiliation, and execution order. The output request is directly sent to the card swiping execution queue of the corresponding output device. After the card swiping confirmation and physical output operation are completed, the content snapshot corresponding to the output task is written to the bastion host content viewing part for retention according to the predetermined encrypted transmission path, so as to form a complete and continuous output record.

[0048] When the link security level verification value is not zero, the process of the current output request entering the device execution queue is immediately interrupted. No output device options that can be executed by swiping a card are opened to the user. At the same time, the original state of the output request in the approval completion stage is maintained and does not change, so as to prevent deviation from the link from continuing to advance on the device side. The current link security level verification value, the corresponding approval completion identifier number, the output device security level identifier value, and the current user session security level area identifier value are all written into the bastion host content viewing part to form an independent record. This independent record can only be viewed and processed by accounts located in the bastion host network segment with audit role permissions until the output link is audited and processed, thereby ensuring that any deviation from the output behavior is always under control and traceable.

[0049] In this implementation plan, by directly determining whether the link security level verification value is zero, the output process is divided into a consistent execution path and a deviation control path at the approval completion node, thereby achieving rapid differentiation between low-risk output behavior and output behavior with deviations. When the verification value is zero, it is confirmed that the output link is completely consistent in terms of security level matching, regional affiliation, and execution order, so that the output request can smoothly enter the card swiping execution and complete the retention under the constraints of the established approval result and device whitelist, ensuring normal output efficiency. When the verification value is not zero, by timely blocking device execution and generating an independent audit record, the potential risk output behavior is restricted to the approval stage, ensuring that the deviation status is centrally audited and constrained before entering physical output, thereby achieving accurate interception, risk isolation, and traceable management of abnormal links without affecting the normal output channel.

[0050] Specifically, using the consistency assessment results and security classification verification results as input, the comprehensive determination of the closure status of the output behavior in the time and process dimensions is carried out in the following steps: 1) The square of the security classification consistency evolution value is added to one and then the natural logarithm is taken to obtain the security classification evolution logarithm mapping value; 2) The link security classification verification value is subtracted from one to obtain the link closure maintenance value; 3) The output behavior time span value is obtained by subtracting the output behavior start time stamp from the output behavior end time stamp of the classified document and then dividing by the output behavior end time stamp; 4) The security classification evolution logarithm mapping value, the link closure maintenance value, and the output behavior time span value are multiplied together to obtain the output link audit mapping value.

[0051] The formula for calculating the output link audit mapping value is: ; In the formula, The security classification consistency evolution value is used to quantify the degree of security classification change of classified documents throughout the entire process from the login determination stage to the device execution stage. It is a direct indicator reflecting the security classification evolution status in the output link. This represents the link security level verification value, used to quantify the consistency between key identifiers after approval and during the device card swiping execution stage. It is a direct indicator reflecting whether the output link maintains a continuous constraint state. The timestamp indicating the end of the output behavior is used to quantify the time position of the completion and termination of the output link of classified documents. It is the endpoint marker that describes the time span of the output behavior and comes from the timestamp information automatically recorded by the system when the output execution is completed and the output request is interrupted. It represents the start timestamp of the output behavior, used to quantify the time position when the output link of classified documents begins to be established. It is the starting point identifier for describing the time span of the output behavior, and comes from the timestamp information automatically recorded by the system when the document output request is generated.

[0052] In this implementation example, the security level consistency evolution value of audit unit 1 is set to 0.30, the link security level verification value is set to 0.20, the output behavior end timestamp is set to 120, and the output behavior start timestamp is set to 20. Set the security level consistency evolution value of audit unit 2 to 0.50, the link security level verification value to 0.30, the output behavior end timestamp to 130, and the output behavior start timestamp to 25. Set the security level consistency evolution value of audit unit 3 to 0.40, the link security level verification value to 0.25, the output behavior end timestamp to 125, and the output behavior start timestamp to 22. Set the security level consistency evolution value of audit unit 4 to 0.60, the link security level verification value to 0.35, the output behavior end timestamp to 140, and the output behavior start timestamp to 30. Set the security level consistency evolution value of audit unit 5 to 0.70, the link security level verification value to 0.40, the output behavior end timestamp to 150, and the output behavior start timestamp to 35. Set the security level consistency evolution value of audit unit 6 to 0.50, the link security level verification value to 0.30, the output behavior end timestamp to 145, and the output behavior start timestamp to 33. Set the security level consistency evolution value of audit unit 7 to 0.80, the link security level verification value to 0.45, the output behavior end timestamp to 160, and the output behavior start timestamp to 40. Set the security level consistency evolution value of audit unit 8 to 0.60, the link security level verification value to 0.35, the output behavior end timestamp to 155, and the output behavior start timestamp to 38. Set the security level consistency evolution value of audit unit 9 to 0.40, the link security level verification value to 0.25, the output behavior end timestamp to 150, and the output behavior start timestamp to 36. Calculate the output link audit mapping value for each audit unit, as shown in Table 1.

[0053] Table 1 Output Link Audit Mapping Value Data Table like Figure 3 The image shows a bar chart of the output link audit mapping values ​​provided in this application example. (See Table 1 and...) Figure 3 It can be seen that the output link audit mapping value of output link audit unit 7 is the highest, indicating that this output behavior is at a high level in terms of the evolution of security level consistency, the continuity of link security level verification, and the proportion of output behavior time span. This comprehensively reflects that it has stronger link integrity and audit sensitivity characteristics throughout the entire process from approval completion to device execution. When comparing the audit mapping threshold in real time, this type of output link is more likely to exceed the first audit threshold, thereby triggering isolation retention and independent audit strategies. It is suitable to be included in the scope of high-intensity audit control to prevent high-risk output behavior from continuing to spread on the device side. The output link audit mapping value of audit unit 1 is the lowest, indicating that its security level evolution range is limited, and the link verification strength and the proportion of time span are both low. In the threshold comparison process, it is more likely to fall into the range below the second audit threshold. The corresponding output task can be managed by conventional retention and index binding methods, thereby reducing the occupation of device-side and bastion host retention resources. Overall, the distribution of output link audit mapping values ​​shown in the bar chart can effectively support the execution of the tiered threshold strategy, enabling a clear separation between regular retention, enhanced retention, and isolated retention for output behaviors with different audit intensities, thereby improving the targeting of output link audit control and the rationality of resource use.

[0054] Specifically, the steps for determining the corresponding retention organization method based on the comprehensive judgment result are as follows: Real-time comparison is performed between the current output link audit mapping value and the pre-configured audit mapping threshold. The audit mapping threshold includes a first audit threshold and a second audit threshold, with the first audit threshold being greater than the second audit threshold. This is used to classify the output link according to the audit intensity dimension. During this classification process, the set of fields written to the bastion host content viewing section varies depending on the judgment interval, but all generated record entries must at least include a unique document identifier, session ID, device ID, and the corresponding timestamp interval to ensure consistency and traceability of records at different retention levels in the basic identifier dimension.

[0055] When the output link audit mapping value is less than or equal to the second audit threshold, the content snapshot corresponding to the current output task and the security level identifier value formed in each stage are written to the bastion host content viewing part. During the writing process, the security level consistency evolution value, link security level verification value, and the output behavior start timestamp and output behavior end timestamp are written as related fields into the same record entry, so that the record can fully reflect the basic audit status of the output behavior in the process and time dimensions. At the same time, the audit index number of the output task is generated synchronously on the output device side, and the binding registration between the audit index number and the output job identifier sequence number is completed to support subsequent fast location and query based on the index.

[0056] When the output link audit mapping value is greater than the second audit threshold and less than or equal to the first audit threshold, the content snapshot corresponding to the current output task and the evolution status data collected during the output process are written to the bastion host content viewing section. In the same record entry, the approval completion identifier number, the approval identifier number corresponding to the job in the device execution queue, and the currently selected job identifier number of the device card swipe point are appended to the record entry to fully describe the correspondence between the approval link and the device execution link. Within this range, the record of the output task in the bastion host content viewing section is kept in a complete and preserved state and is not merged or overwritten when the output device side job ends, so as to carry out continuous tracking and review analysis of output behaviors with medium audit intensity.

[0057] When the output link audit mapping value exceeds the first audit threshold, the current output task stops generating new audit indexes on the output device side. The generated content snapshot, evolution status data, security level consistency evolution value, link security level verification value, and the corresponding output behavior start timestamp and output behavior end timestamp are uniformly written into the bastion host content viewing section and stored as an independent audit record entry. At the same time, access restrictions are imposed on this record, allowing access only when the bastion host network segment access conditions are met and the audit role permissions are available. This ensures that high-audit-intensity output behaviors are strictly controlled at both the retention and access levels.

[0058] like Figure 4 The diagram shown illustrates the print job security management process provided in this application example. It depicts a print job control logic centered on security level constraints from a business link perspective, emphasizing layer-by-layer verification and linkage constraints on printing behavior at the user, process, and device levels. The process begins with the user logging into the print client. Instead of directly entering the job submission stage, it automatically identifies the user's login IP address to determine the user's region. Based on this, it simultaneously obtains the security level upper limit constraint corresponding to the region and available approval information, ensuring that subsequent printing behavior is within a clearly defined regional security boundary from the outset. The user then initiates a print job, explicitly selecting the job security level and matching it with the corresponding approval process during submission, thus binding the sensitivity of the job content to the responsible approval entity. Once the job is officially submitted, the process enters the approval and judgment stage, branching based on the approval result: if the approver fails to approve the application, the printing link is logically interrupted, the job does not enter the device execution stage, and a corresponding approval failure log is generated for post-event auditing and traceability; if the approval is successful, the job is allowed to enter the device-side execution preparation stage, but it is not directly output at this point. On the printing device side, users must verify their identity by swiping a card to ensure consistency between the actual operator and the submitter. After identity verification, a crucial security level consistency check is performed, comparing the job security level declared in the print job with the device security level supported and configured by the current printer. If they do not match, the print job is forcibly blocked even if approval has been granted, preventing the job from being printed on that device and avoiding the risk of unauthorized printing due to insufficient device security level capabilities. Only when the print job security level matches the printer security level will the printing device perform the actual job output operation and generate a complete print log record upon completion. The entire process, through multiple key nodes including area identification, job security level selection, approval result control, device identity verification, and security level matching determination, constructs a closed-loop printing control chain. This makes printing no longer a single device action but a secure process constrained by multiple conditions, effectively supporting the controllability, traceability, and accountability of printing activities.

[0059] This implementation scheme achieves refined traffic management for output behaviors with different audit intensities by comparing the output link audit mapping value with the hierarchical audit threshold in real time. This clearly distinguishes output behaviors in terms of retention depth, index binding method, and access control strength. In the low audit intensity range, rapid retention is achieved using basic fields and index binding, ensuring audit coverage and execution efficiency for normal output behaviors. In the medium audit intensity range, approval identifiers and device execution association information are extended and recorded in a complete manner, supporting continuous tracking and review analysis of output behaviors with certain risk characteristics. In the high audit intensity range, device-side index expansion is suspended and independent controlled record entries are generated, concentrating high-risk output behaviors into restricted access and strengthening audit focus. Simultaneously, by uniformly defining document unique identifiers, session identifiers, device identifiers, and timestamp ranges as basic fields for all records, consistency in the identifier dimension is ensured for audit data at different retention levels, thereby improving the traceability, distinguishability, and rationality of resource use in the output link audit process.

[0060] The second aspect of this invention provides a security control system for the output of classified documents based on dynamic identification of classification levels, comprising: a multi-stage data acquisition module, used to continuously collect key status information at different stages throughout the entire process of outputting classified documents. The collected data includes evolutionary status data reflecting the trend of document classification level changes, link execution data reflecting the approval execution and device interaction, and time span data representing the start and end relationship of output behavior. The system performs unified format verification, time alignment, and anomaly removal processing on the above multi-source data, thereby constructing a standardized document security dataset that can completely reflect the evolution process of classified document output behavior, providing a consistent data foundation for subsequent analysis. The cross-stage security classification consistency evolution analysis module is used to perform correlation analysis on the security classification evolution status of classified documents in multiple stages such as registration, approval, execution and retention based on a standardized document security dataset. By characterizing the continuity and stability of security classification changes in the output link, it quantitatively evaluates the consistency level of the output link and dynamically constrains the output execution path based on the consistency evaluation results to prevent output behaviors with abnormal security classification status jumps from directly entering the device execution stage. The Link Security Level Constraint Continuous Verification Module is used to continuously verify the security level of the output link from the completion of approval to the execution of the device based on a standardized document security dataset. By judging the matching relationship between key identification information and the current output security level, it identifies possible overstepping and mismatch situations, and determines whether the corresponding output request needs to enter the isolation record state based on the security level verification results, so as to prevent the output behavior that does not comply with the security level constraints from continuing to spread. The Link Integrity Retention and Audit Mapping Module is used to comprehensively determine the start and end closure status of output behavior in the time dimension and the execution closure status in the process dimension, using the consistency assessment results and the security level verification results as joint inputs. Based on the comprehensive judgment results, it determines the retention organization method of output records in the bastion host, thereby forming a clear layer between regular retention, enhanced retention and isolated retention, and realizing the complete retention and auditable mapping of the output link of classified documents.

[0061] In this implementation plan, the multi-stage data acquisition module plays a role in uniformly perceiving and structurally integrating the key behavioral states throughout the entire process of outputting classified documents. It continuously collects evolutionary state data reflecting the changing trend of document classification, link execution data reflecting the approval and equipment execution process, and time span data representing the start and end relationships of output behaviors. It also performs standardized processing on the above multi-source data to ensure that subsequent analysis can be carried out on the same timeline and within the same semantic framework, thereby providing a complete, continuous, and alignable data foundation for output link security analysis.

[0062] The cross-stage classification consistency evolution analysis module is designed to perform correlation analysis on the classification changes of classified documents in multiple output stages. By characterizing the continuity and stability of the classification in the output link, it evaluates the overall consistency level of the output link and uses the evaluation results as a constraint to regulate the output execution path. This prevents output behaviors with abnormal fluctuations in classification status from directly entering the device execution stage, thereby improving the security and controllability of the output link.

[0063] The function of the continuous verification module for link security level constraints is to continuously check the effective status of the output link from the completion of approval to the execution of the device. By verifying the matching relationship between the output security level and the key execution identifier, it identifies output requests that do not meet the security level constraints and determines whether the corresponding output behavior needs to be transferred to the isolation record state to prevent out-of-level and mismatched outputs from continuing to propagate in the link, thereby strengthening the enforcement of security level constraints in the output process.

[0064] The role of the link integrity retention and audit mapping module is to comprehensively determine the closed state of output behavior in the time and process dimensions. By integrating the consistency assessment results and the security level verification results, it determines whether the output link meets the audit requirements of completeness, continuity and traceability, and selects the corresponding retention organization method accordingly to achieve the orderly distribution of output records in different retention levels, providing a clear and mappable link basis for subsequent audit analysis.

[0065] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0066] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A method for security control of classified document output based on dynamic identification of classification level, characterized in that: include: S1. Collect evolution status data, link execution data, and time span data during the output process of classified documents. Preprocess the evolution status data, link execution data, and time span data to construct a standardized document security dataset. S2, based on a standardized document security dataset, performs consistency assessment on the output link consistency from the security level evolution state throughout the entire process of classified document output, and controls the output execution path based on the consistency assessment results; S3, based on a standardized document security dataset, performs security level verification on the valid status of the output link, and determines whether the output request enters the isolation record state based on the security level verification result. S4 takes the consistency assessment results and security level verification results as inputs, comprehensively judges the closed state of the output behavior in the time dimension and process dimension, and determines the corresponding retention organization method based on the comprehensive judgment results. The specific steps for determining the corresponding retention organization method based on the comprehensive judgment result are as follows: Real-time comparison of the current output link audit mapping value with the audit mapping threshold. The audit mapping threshold includes a first audit threshold and a second audit threshold, wherein the first audit threshold is greater than the second audit threshold. When the output link audit mapping value is less than or equal to the second audit threshold, the content snapshot of the current output task and the security level identifier value formed in each stage are written into the content viewing part of the bastion host. At the same time, during the writing process, the security level consistency evolution value, the link security level verification value, and the output behavior start timestamp and output end timestamp are written into the same record entry as associated fields. The audit index number of the output task is generated synchronously on the output device side, and the binding registration of the index number and the output job identifier sequence number is completed. When the output link audit mapping value is greater than the second audit threshold and less than or equal to the first audit threshold, the content snapshot corresponding to the current output task and the evolution status data during the output process are written to the bastion host content viewing part. The approval completion identifier number, the approval identifier number corresponding to the job in the device execution queue, and the currently selected job identifier number of the device card swipe point are appended to the same record entry. At the same time, the complete record status of the output task in the bastion host content viewing part is maintained and is not merged or overwritten when the job on the output device side ends. When the output link audit mapping value is greater than the first audit threshold, the current output task stops generating new audit index writing operations on the output device side. The generated content snapshot, evolution status data, security level consistency evolution value, link security level verification value, and the corresponding output behavior start timestamp and output behavior end timestamp are written to the bastion host content viewing part and stored as a separate audit record entry. At the same time, the audit record entry is restricted from being accessed and processed only if the bastion host network segment access conditions are met and the audit role permissions are available.

2. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for collecting evolutionary state data, link execution data, and time span data during the process of collecting classified document output data are as follows: The same classified document is divided into four stages in a complete output chain, including the login determination stage, the classification level selection stage, the approval execution stage, and the device execution stage, and a stage identifier record associated with the unique identifier of the document is generated for each stage. Collect evolution status data of the same classified document at different stages. The evolution status data includes: the classification level identifier value corresponding to each stage and the sequential number in the output link; Collect link execution data during the output process of classified documents. The link execution data includes: document classification identifier value, output device classification identifier value, current user session classification area identifier value, output device classification area identifier value, approval completion identifier number, approval identifier number corresponding to the job in the device execution queue, output job identifier number, and currently selected job identifier number at the device card swipe point. Collect time span data corresponding to the output behavior. The time span data includes: the actual duration of the same classified document at different stages, the start timestamp of the output behavior, and the end timestamp of the output behavior.

3. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for preprocessing evolutionary state data, link execution data, and time span data to construct a standardized document security dataset are as follows: After completing the collection of evolutionary state data, the integrity of the security level identifier values ​​corresponding to each stage is verified, and stage records with missing security level identifiers are removed; the consistency of the sequence numbers in the output link is checked, and they are reordered according to the stage order in the output process. After reordering, the security level identifier values ​​of adjacent stages are aligned. After completing the collection of link execution data, the document security level identifier, output device security level identifier, current user session security level zone identifier, and output device security level zone identifier are formatted in a unified manner. Perform uniqueness checks on the approval completion identifier number, the approval identifier number corresponding to the operation in the equipment execution queue, the output operation identifier number, and the currently selected operation identifier number at the equipment card swipe point, and eliminate duplicate and missing records; After collecting the time span data, the actual duration of each stage is validated for legality, and stage records with negative durations or abnormal interruptions are removed; the start timestamp and end timestamp of the output behavior are checked for time sequence consistency. The evolutionary state data, link execution data, and time span data that have undergone standardization are normalized using a minimum-maximum linear normalization algorithm to construct a standardized document security dataset.

4. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for evaluating the consistency of the output link based on the standardized document security dataset and the evolution of the security level throughout the entire output process of classified documents are as follows: Calculate the absolute value of the difference between the density level identifier values ​​between adjacent stages to obtain the stage density level transition amplitude value; Subtract the actual duration of the current stage from the actual duration of the next stage to obtain the time interval between adjacent stages. Subtract the sequence number of the current stage from the sequence number of the next stage in the output link to obtain the stage sequence advance amount; Divide the stage density transition amplitude value by the time interval between adjacent stages and then multiply it by the stage sequence advancement amount to obtain the single-stage density evolution contribution. The single-stage security level evolution contribution of each stage is added together to obtain the security level consistency evolution value.

5. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for controlling the output execution path based on the consistency evaluation result are as follows: After calculating the security level consistency evolution value, the security level consistency evolution value corresponding to the current output link is compared with the consistency evolution threshold. When the security level consistency evolution value is less than or equal to the consistency evolution threshold, the security level area identifier value bound to the current output session remains unchanged, the already matched approval process result is used, and the current output request is directly put into the device selection and card swiping execution stage; During the device execution phase, a list of output devices that match the current document's security level identifier value is presented to the user according to the output device security level whitelist rules, and the corresponding physical output operation is executed after card swipe confirmation; at the same time, a snapshot of the content corresponding to the output task is written to the content viewing section within the bastion host network segment according to the current encrypted transmission path; When the security level consistency evolution value exceeds the consistency evolution threshold, the current output request is terminated from entering the device execution stage, the generated device card swipe trigger state is frozen, and no executable output device is presented to the user. At the same time, the output request is re-associated with the corresponding current user session security level area identifier value, and an approval process consistent with the current user session security level area identifier value is initiated to re-verify the steps. The current security level consistency evolution value, the security level identifier values ​​at each stage, and the actual duration at each stage are written into the bastion host content viewing section to form an independent record. Only accounts located within the bastion host network segment with audit role permissions are allowed to view and process the independent record until the current output link is closed.

6. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for performing security level verification on the output link based on the standardized document security dataset are as follows: Subtracting the output device's security classification value from the current document security classification value and then taking the square of the result, we obtain the document device security classification deviation value. Subtract the security level zone identifier value of the output device from the current user session security level zone identifier value and take the square of the result to obtain the session device zone deviation value. Multiply the document device security level deviation value by the session device region deviation value, add one and take the natural logarithm to obtain the security level region coupling deviation. The absolute value of the difference between the approval completion identifier number and the approval identifier number corresponding to the job in the equipment execution queue is calculated to obtain the approval identifier difference. Calculate the absolute value of the difference between the output job identifier number and the currently selected job identifier number at the device card swipe point to obtain the job identifier difference; The total deviation of the execution link is obtained by multiplying the difference between the approval mark and the difference between the operation mark and then taking the square root. The coupling deviation of the high-security region is added to the comprehensive deviation of the execution link to obtain the coupling deviation reuse amount of the high-security region; The link security level verification value is obtained by dividing the coupling deviation multiplexing amount of the security level region by the sum of the coupling deviation multiplexing amount of the security level region and one.

7. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for determining whether an output request should enter the isolation record state based on the security level verification result are as follows: After calculating the link security level check value, the output process is directly split based on whether the current link security level check value is zero. When the link security level verification value is zero, the established mapping relationship between the approval result and the device security level whitelist is maintained, the output request is directly sent to the card swiping execution queue of the corresponding output device, and after the output is completed, the content snapshot is written to the bastion host content viewing part for retention according to the encrypted transmission path; When the link security level verification value is not zero, the process of the current output request entering the device execution queue is interrupted, the option of output device that can be swiped is not opened, and the original state of the output request in the approval completion stage is preserved. The link security level verification value, the corresponding approval completion identifier number, the output device security level identifier value, and the current user session security level area identifier value are written into the bastion host content viewing part to form an independent record. Only accounts located in the bastion host network segment and with audit role permissions are allowed to perform subsequent processing on the independent record.

8. The method for security control of classified document output based on dynamic classification level identification according to claim 1, characterized in that: The specific steps for comprehensively determining the closure state of the output behavior in the time and process dimensions, using the consistency assessment results and security level verification results as input, are as follows: The logarithm of the security level evolution value is obtained by adding one to the square of the security level consistency evolution value and taking the natural logarithm. Subtract the link security level check value from 1 to obtain the link closure maintenance value; Subtract the start timestamp of the output behavior from the end timestamp of the output behavior of the classified document, and then divide by the end timestamp of the output behavior to obtain the time span value of the output behavior. The output link audit mapping value is obtained by multiplying the logarithmic mapping value of the security level evolution, the link closure maintenance value, and the output behavior time span value.

9. A security control system for classified document output based on dynamic classification level identification, employing the security control method for classified document output based on dynamic classification level identification as described in any one of claims 1-8, characterized in that: include: The multi-stage data acquisition module is used to collect evolution status data, link execution data, and time span data during the output process of classified documents. It preprocesses the evolution status data, link execution data, and time span data to construct a standardized document security dataset. The cross-stage security level consistency evolution analysis module is used to evaluate the consistency of the output link based on the security level evolution status of the entire process of outputting classified documents, using a standardized document security dataset, and to control the output execution path based on the consistency evaluation results. The link security level constraint continuous verification module is used to perform security level verification on the valid status of the output link based on the standardized document security dataset, and determine whether the output request enters the isolation record state based on the security level verification result. The Link Integrity Retention and Audit Mapping Module is used to comprehensively determine the closed state of the output behavior in the time and process dimensions, taking the consistency assessment results and security level verification results as inputs, and determine the corresponding retention organization method based on the comprehensive judgment results.

Citation Information

Patent Citations

  • A confidential document tracing method, document calling server and security server

    CN112115433B

  • A method for secure management and control of confidential documents based on blockchain

    CN117131534B

  • Business hall service system supporting multi-user security data circulation

    CN121151091A

  • Protecting data files

    US20160357978A1