Optical disc data safe reading and monitoring method, device and equipment and medium

By encrypting CD-ROM data and recording traceability information, combined with identity authentication and environmental monitoring, the problem of untraceable CD-ROM data access behavior is solved, and data security supervision with full traceability is achieved.

CN121859341APending Publication Date: 2026-04-14CHENGDU WEISHITONG INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies cannot effectively trace optical disc data access behavior, resulting in the inability to accurately record the time, location, and device information of reading operations, making it difficult to trace the source and collect evidence, and posing challenges to data security supervision.

Method used

The system employs national cryptographic algorithms to encrypt and digest the data to be burned, generating optical disc identification information. During reading, device information is recorded to generate traceability information. Combined with identity authentication and environmental detection, the system achieves full traceability and supervision of optical disc data access behavior.

Benefits of technology

It enables full traceability and monitoring of CD data access behavior, prevents unauthorized reading, supports source tracing and responsibility determination, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121859341A_ABST
    Figure CN121859341A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a device and equipment for safely reading and supervising optical disk data, and a medium, and relates to the technical field of computers. Comprising the following steps: sequentially carrying out encryption operation and abstract calculation on to-be-recorded data by utilizing a preset encryption algorithm to obtain corresponding encrypted data and abstract information; generating optical disc identification information by using the summary information and the related information, and recording the encrypted data, the optical disc identification information and a preset data decryption tool to a target optical disc through optical disc recording operation; if the target equipment performs data reading operation on the target optical disk, reading equipment information of the target equipment by utilizing a preset data decryption tool so as to generate corresponding traceability information, and hiding and storing the traceability information in a storage space of the target equipment; and carrying out identity authentication and environment detection by utilizing a preset data decryption tool, and executing corresponding processing operation according to a result of identity authentication and environment detection. Therefore, the whole-course traceable supervision of the optical disk data access behavior is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for secure reading and monitoring of optical disc data. Background Technology

[0002] In critical data output scenarios such as those involving government agencies and enterprises, optical disc burning is typically used to physically output important data. Existing technical solutions generally include the following process: the requesting party submits the data to be burned and obtains approval; after approval, the burning system performs the burning operation and records an operation log. To further enhance data security, some organizations with high confidentiality requirements also add password authentication and environmental monitoring mechanisms to the optical disc reading process to prevent unauthorized access or data reading in insecure environments.

[0003] However, existing technologies still have significant shortcomings: traditional solutions focus on encrypted data storage, access control, and environmental security checks, but fail to effectively track and record optical disc reading activities. Once an unauthorized reading incident occurs, the system cannot accurately record the time, location, and specific device information used during the reading operation, making it impossible to effectively trace and prove the violation, thus posing difficulties for data security supervision.

[0004] As can be seen from the above, how to achieve full traceability and supervision of optical disc data access behavior is an urgent problem to be solved. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a method, apparatus, device, and medium for secure reading and monitoring of optical disc data, capable of achieving full traceability and monitoring of optical disc data access behavior. The specific solution is as follows:

[0006] Firstly, this application provides a method for secure reading and monitoring of optical disc data, including:

[0007] The system receives a burning request from a requester and uses a preset encryption algorithm to sequentially encrypt and digest the data to be burned, thereby obtaining the corresponding encrypted data to be burned and digest information. The burning request includes the data to be burned and the requester information corresponding to the requester. The requester information includes identity information and authentication password.

[0008] Using the digest information and the requester information, an optical disc identification information is generated. Based on the encrypted data to be burned, the optical disc identification information, and a preset data decryption tool, an optical disc burning operation is performed to obtain the target optical disc.

[0009] If the target device performs a data reading operation on the target optical disc, the preset data decryption tool is used to read the device information of the target device, so as to generate corresponding traceability information based on the device information, and the traceability information is hidden and stored in the storage space of the target device; the traceability information includes time information, address information, hard disk serial number information, network card information, and optical disc information;

[0010] The preset data decryption tool is used for identity authentication and environment detection, and corresponding processing operations are performed based on the results of identity authentication and environment detection. The processing operations include using the preset data decryption tool to read data from the target optical disc or using the traceability information to monitor the data reading operation of the target device.

[0011] Optionally, the step of sequentially encrypting and digesting the data to be burned using a preset encryption algorithm to obtain the corresponding encrypted data to be burned and digest information includes:

[0012] The data to be burned is encrypted using a first preset encryption algorithm to obtain the corresponding encrypted data to be burned, and the encrypted data to be burned is digested using a second preset encryption algorithm to obtain the corresponding digest information; the first preset encryption algorithm is the national standard SM4 algorithm; the second preset encryption algorithm is the national standard SM3 algorithm.

[0013] Optionally, after hiding and storing the traceability information in the storage space of the target device, the method further includes:

[0014] If the target device has established a communication connection with the preset management center, the preset data decryption tool is used to upload the traceability information to the preset management center so that the preset management center can generate an optical disc track audit record based on the traceability information.

[0015] Optionally, the step of using the preset data decryption tool for identity authentication and environment detection includes:

[0016] The preset data decryption tool is used to perform identity authentication based on the authentication password to obtain the corresponding authentication result, and environmental detection is performed based on the Internet connection status of the target device to obtain the corresponding detection result;

[0017] If the authentication password re-entered by the target device matches the authentication password burned in the target optical disc, an authentication result of successful identity authentication is obtained; otherwise, an authentication result of unsuccessful identity authentication is obtained.

[0018] If the target device's internet connection status is not connected, a detection result indicating that the environmental detection has passed is obtained; otherwise, a detection result indicating that the environmental detection has failed is obtained.

[0019] Optionally, if both the authentication result and the detection result indicate a pass, then the step of performing corresponding processing operations based on the results of identity authentication and environmental detection includes:

[0020] The preset data decryption tool is used to read the encrypted data hidden in the target optical disc and decrypt the encrypted data to obtain the target data.

[0021] Optionally, if either the authentication result or the detection result fails, the step of performing corresponding processing operations based on the results of identity authentication and environmental detection includes:

[0022] The preset data decryption tool is used to block the target device from reading data from the target optical disc, and an alarm message containing the traceability information is uploaded to a preset alarm center so that the preset alarm center can lock the target device based on the alarm message.

[0023] Optionally, after uploading the alarm information containing the traceability information to a preset alarm center so that the preset alarm center can lock the target device based on the alarm information, the method further includes:

[0024] By comparing the traceability information hidden and stored locally on the target device with the traceability information contained in the alarm information, evidence collection and responsibility determination for unauthorized reading behavior can be completed.

[0025] Secondly, this application provides a device for secure reading and monitoring of optical disc data, comprising:

[0026] The data encryption module is used to receive a burning request initiated by a requester, and to use a preset encryption algorithm to sequentially perform encryption operations and digest calculations on the data to be burned in order to obtain the corresponding encrypted data to be burned and digest information; the burning request includes the data to be burned and the requester information corresponding to the requester; the requester information includes identity information and authentication password;

[0027] The optical disc burning module is used to generate optical disc identification information using the digest information and the requester information, and to perform optical disc burning operation based on the encrypted data to be burned, the optical disc identification information and a preset data decryption tool to obtain the target optical disc;

[0028] The operation traceability module is used to read the device information of the target device using the preset data decryption tool if the target device performs a data reading operation on the target optical disc, so as to generate corresponding traceability information based on the device information, and to hide and store the traceability information in the storage space of the target device; the traceability information includes time information, address information, hard disk serial number information, network card information, and optical disc information;

[0029] The optical disc reading module is used to perform identity authentication and environment detection using the preset data decryption tool, and to perform corresponding processing operations based on the results of identity authentication and environment detection; the processing operations include using the preset data decryption tool to read data from the target optical disc or using the traceability information to monitor the data reading operations of the target device.

[0030] Thirdly, this application provides an electronic device, comprising:

[0031] Memory, used to store computer programs;

[0032] A processor is used to execute the computer program to implement the aforementioned method for secure reading and monitoring of optical disc data.

[0033] Fourthly, this application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned method for secure reading and monitoring of optical disc data.

[0034] This application provides a method for secure reading and monitoring of optical disc data. It receives a burning request from a requester and uses a preset encryption algorithm to sequentially encrypt and digest the data to be burned, obtaining the corresponding encrypted data and digest information. The burning request includes the data to be burned and requester information corresponding to the requester. Optical disc identification information is generated using the digest information and the requester information. An optical disc burning operation is then performed based on the encrypted data to be burned, the optical disc identification information, and a preset data decryption tool to obtain the target optical disc. The requester information includes identity information and an authentication password. If the target device performs data reading on the target optical disc... The read operation utilizes the preset data decryption tool to read the device information of the target device, thereby generating corresponding traceability information based on the device information, and hiding and storing the traceability information in the storage space of the target device. The traceability information includes time information, address information, hard disk serial number information, network card information, and optical disc information. The preset data decryption tool is used for identity authentication and environment detection, and corresponding processing operations are performed based on the results of identity authentication and environment detection. The processing operations include using the preset data decryption tool to read data from the target optical disc or using the traceability information to monitor the data reading operation of the target device.

[0035] As can be seen from the above, this application combines data encryption and burning with trusted verification, environmental monitoring, and traceability recording of the reading process. This not only effectively prevents important data from being read illegally in unauthorized or networked environments, but also automatically hides traceability information containing device characteristics and optical disc identification on the local reading device. At the same time, it supports uploading relevant information to the management center to form an audit trail, thereby enabling full traceability and supervision of optical disc data access behavior. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0037] Figure 1 This is a flowchart of a method for secure reading and monitoring of optical disc data disclosed in this invention;

[0038] Figure 2 This is a schematic diagram of a device for secure reading and monitoring of optical disc data disclosed in this invention;

[0039] Figure 3 This is a structural diagram of an electronic device disclosed in this invention. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] In critical data output scenarios such as those of government agencies and enterprises, optical disc burning is commonly used to physically output important data. Existing technical solutions generally include the following process: the requesting party submits the data to be burned and obtains approval; after approval, the burning system performs the burning operation and records an operation log. To further enhance data security, some organizations with high confidentiality requirements also add password authentication and environmental monitoring mechanisms to the optical disc reading process to prevent unauthorized access or data reading in insecure environments. However, existing technologies still have significant shortcomings: traditional solutions focus on encrypted data storage, access control, and environmental security checks, but fail to effectively track and record optical disc reading behavior. Once an unauthorized reading incident occurs, the system cannot accurately record the time, location, and specific device information used during the reading operation, making it impossible to effectively trace and obtain evidence of the violation, thus posing difficulties for data security supervision. Therefore, this application provides an optical disc data security reading and supervision solution that enables full traceability and supervision of optical disc data access behavior.

[0042] See Figure 1 As shown in the figure, this application discloses a method for secure reading and monitoring of optical disc data, including:

[0043] Step S11: Receive the burning request initiated by the requester, and use the preset encryption algorithm to perform encryption operations and digest calculation on the data to be burned in sequence to obtain the corresponding encrypted data to be burned and digest information.

[0044] In this embodiment, the requesting party (such as an employee or authorized user who needs to output data) initiates a burning request through a dedicated burning terminal or system client. The burning request includes, but is not limited to, the important data file to be burned, and the requesting party information corresponding to the requesting party. The requesting party information includes, but is not limited to, identity information used to identify the requesting party (such as employee number, department, name, etc.) and an authentication password set by the requesting party or assigned by the system.

[0045] Furthermore, upon receiving a burning request, the built-in encryption module is invoked to securely process the data contained in the request using a preset encryption algorithm. Specifically, the process of using the preset encryption algorithm to sequentially encrypt the data to be burned and perform digest calculations to obtain the corresponding encrypted data to be burned and digest information can include: encrypting the data to be burned using a first preset encryption algorithm to obtain the corresponding encrypted data to be burned, and then performing digest calculations on the encrypted data to be burned using a second preset encryption algorithm to obtain the corresponding digest information; the first preset encryption algorithm is the Chinese national standard SM4 algorithm; and the second preset encryption algorithm is the Chinese national standard SM3 algorithm. That is, the first preset encryption algorithm is used to encrypt the data to be burned, generating encrypted data that cannot be directly read. Next, the second preset encryption algorithm is used to perform a hash operation on the encrypted data to generate a fixed-length digest information. This digest information is unique; any slight modification to the original data will result in a completely different digest information, thus it can be used to verify data integrity.

[0046] Step S12: Generate optical disc identification information using the digest information and the requester information, and perform optical disc burning operation based on the encrypted data to be burned, the optical disc identification information, and a preset data decryption tool to obtain the target optical disc.

[0047] In this embodiment, the calculated digest information is associated and combined with the requester information to generate disc identification information that uniquely identifies this disc. Subsequently, the system packages the encrypted data to be burned, the disc identification information, and a preset data decryption tool together. The data decryption tool is a standalone application. Finally, the disc burning operation is performed, writing the packaged content to a blank disc to generate the target disc. In this embodiment, the encrypted data to be burned is stored as a hidden file on the disc, invisible to ordinary file browsing, further increasing the difficulty of direct data copying.

[0048] Step S13: If the target device performs a data reading operation on the target optical disc, the preset data decryption tool is used to read the device information of the target device so as to generate corresponding traceability information based on the device information, and the traceability information is hidden and stored in the storage space of the target device.

[0049] In this embodiment, when a user inserts the target CD into a computer (target device) and attempts to access it, the data decryption tool from the target CD needs to be copied to the computer and run. After the data decryption tool is started, before performing any user interaction or data decryption, it will automatically perform a tracing operation: reading the target device's hardware and environmental information to generate tracing information. This tracing information includes, but is not limited to, the timestamp of the operation, the target device's IP address or geographical location information, hard drive serial number, network card MAC address, and CD identification information read from the CD. Furthermore, the data decryption tool encrypts the tracing information and writes it to the target device's local storage space as a hidden file. Simultaneously, the data decryption tool attempts to probe the network environment. If the current target device and the preset management center server are on the same trusted network and the connection is stable, the data decryption tool will automatically upload the tracing information to the management center. Specifically, after hiding and storing the traceability information in the storage space of the target device, it may further include: if the target device has established a communication connection with the preset management center, then using the preset data decryption tool to upload the traceability information to the preset management center, so that the preset management center can generate an optical disc track audit record based on the traceability information.

[0050] Step S14: Use the preset data decryption tool to perform identity authentication and environment detection, and perform corresponding processing operations based on the results of identity authentication and environment detection; the processing operations include using the preset data decryption tool to read data in the target optical disc or using the traceability information to monitor the data reading operation of the target device.

[0051] In this embodiment, the preset data decryption tool is used to perform identity authentication and environment detection based on the authentication password and the current network status of the target device. Specifically, the identity authentication and environment detection using the preset data decryption tool may include: using the preset data decryption tool to perform identity authentication based on the authentication password to obtain a corresponding authentication result, and performing environment detection based on the internet connection status of the target device to obtain a corresponding detection result; wherein, if the authentication password re-entered by the target device matches the authentication password burned into the target optical disc, an authentication success result is obtained; otherwise, an authentication failure result is obtained; if the internet connection status of the target device is not connected, an environment detection success result is obtained; otherwise, an environment detection failure result is obtained. For example, in a specific embodiment, the data decryption tool will pop up an interface, requiring the user to enter an authentication password, and compare it with the original authentication password burned into the optical disc to complete identity authentication. The data decryption tool will detect the current network status of the target device, especially determining whether it is connected to the internet, to complete the environment detection. Understandably, the rules for environmental monitoring can be determined based on the actual application situation. For example, it may be stipulated that data reading must be carried out in a completely offline environment.

[0052] Furthermore, corresponding processing operations are performed based on the results of identity authentication and environmental monitoring. Specifically, if both the authentication result and the detection result indicate that the data passes, the corresponding processing operations based on the results of identity authentication and environmental monitoring may include: using the preset data decryption tool to locate and read the hidden encrypted data to be burned from the target optical disc, decrypting it using the corresponding national cryptographic algorithm, and restoring the original target data for normal viewing or use by the user. If either the authentication result or the detection result indicates that the data fails, the corresponding processing operations based on the results of identity authentication and environmental monitoring may include: using the preset data decryption tool to block the target device from reading data from the target optical disc, and physically ejecting the target optical disc; generating an alarm message containing the current traceability information, and uploading the alarm message to a preset alarm center so that the preset alarm center can lock the target device based on the alarm message.

[0053] Furthermore, once security management personnel learn of a violation through the alarm center, they can initiate an investigation. Specifically, the process of uploading alarm information containing the traceability information to a preset alarm center, so that the preset alarm center can lock the target device based on the alarm information, also includes: comparing the traceability information hidden and stored locally on the target device with the traceability information contained in the alarm information to complete the evidence collection and responsibility determination for the unauthorized reading behavior. In one specific implementation, investigators can use specialized tools to extract the locally encrypted and hidden traceability information from the locked target device. This local information is then cross-compared with the alarm information received by the alarm center and the audit records stored in the management center. Since these three originate from the same reading behavior and the information is interconnected and corroborated (including the same time, device fingerprint, and optical disc ID), a complete, reliable, and tamper-proof chain of evidence can be formed, thereby accurately completing the evidence collection and responsibility determination for the unauthorized reading behavior and achieving a closed loop of security supervision.

[0054] As can be seen from the above, this application embodiment encrypts data using national cryptographic algorithms during the burning stage and binds it with the requester's information to generate a unique optical disc identifier. During the reading stage, it automatically and covertly records traceability information containing device characteristics and the optical disc identifier to the local machine, and simultaneously implements dual verification of identity authentication and environmental detection, thereby achieving proactive protection and real-time blocking of data reading behavior. At the same time, by cross-comparing the local traceability information, the audit records uploaded to the management center, and the violation alarm information, a complete and reliable chain of evidence is constructed. Thus, while ensuring the security of data content, it achieves closed-loop supervision of optical disc data access behavior that is traceable and accountable throughout the entire process.

[0055] See Figure 2 As shown in the figure, this application discloses a device for secure reading and monitoring of optical disc data, including:

[0056] The data encryption module 11 is used to receive the burning application initiated by the requester, and to use a preset encryption algorithm to sequentially perform encryption operations and digest calculation on the data to be burned in order to obtain the corresponding encrypted data to be burned and digest information; the burning application includes the data to be burned and the requester information corresponding to the requester; the requester information includes identity information and authentication password.

[0057] The optical disc burning module 12 is used to generate optical disc identification information using the digest information and the requester information, and to perform optical disc burning operation based on the encrypted data to be burned, the optical disc identification information and a preset data decryption tool to obtain the target optical disc.

[0058] The traceability module 13 is used to read the device information of the target device using the preset data decryption tool if the target device performs a data reading operation on the target optical disc, so as to generate corresponding traceability information based on the device information, and to hide and store the traceability information in the storage space of the target device; the traceability information includes time information, address information, hard disk serial number information, network card information, and optical disc information.

[0059] The optical disc reading module 14 is used to perform identity authentication and environment detection using the preset data decryption tool, and to perform corresponding processing operations based on the results of identity authentication and environment detection; the processing operations include using the preset data decryption tool to read data in the target optical disc or using the traceability information to monitor the data reading operation of the target device.

[0060] In some specific embodiments, the data encryption module 11 may specifically include:

[0061] The data encryption unit is used to encrypt the data to be burned using a first preset encryption algorithm to obtain the corresponding encrypted data to be burned, and to perform digest calculation on the encrypted data to be burned using a second preset encryption algorithm to obtain the corresponding digest information; the first preset encryption algorithm is the national standard SM4 algorithm; the second preset encryption algorithm is the national standard SM3 algorithm.

[0062] In some specific embodiments, the optical disc reading module 14 may specifically include:

[0063] The identity authentication and environment monitoring unit is used to perform identity authentication based on the authentication password using the preset data decryption tool to obtain the corresponding authentication result, and to perform environment detection based on the internet connection status of the target device to obtain the corresponding detection result; wherein, if the authentication password re-entered by the target device is consistent with the authentication password burned in the target optical disc, an authentication success result is obtained, otherwise an authentication failure result is obtained; if the internet connection status of the target device is not connected, an environment detection success result is obtained, otherwise an environment detection failure result is obtained.

[0064] The first processing execution unit is configured to, if both the authentication result and the detection result indicate that the authentication result and the detection result are both passed, use the preset data decryption tool to read the encrypted data hidden in the target optical disc and decrypt the encrypted data to obtain the target data.

[0065] The second processing execution unit is used to block the target device's data reading operation on the target optical disc using the preset data decryption tool if either the authentication result or the detection result fails, and to upload alarm information containing the traceability information to the preset alarm center so that the preset alarm center can lock the target device based on the alarm information.

[0066] In some specific embodiments, the optical disc data security reading and monitoring device may further include:

[0067] An auditing unit is used to upload the traceability information to the preset management center using the preset data decryption tool if the target device has established a communication connection with the preset management center, so that the preset management center can generate an optical disc track audit record based on the traceability information.

[0068] The violation evidence collection unit is used to collect evidence and determine responsibility for violations by comparing the traceability information hidden and stored locally on the target device with the traceability information contained in the alarm information.

[0069] Furthermore, embodiments of this application also disclose an electronic device, Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the optical disc data secure reading and monitoring method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0070] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0071] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0072] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including computer programs capable of performing the optical disc data secure reading and monitoring method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.

[0073] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned method for secure reading and monitoring of optical disc data. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0074] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0075] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0076] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0077] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0078] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for secure reading and monitoring of optical disc data, characterized in that, include: The system receives a burning request from a requester and uses a preset encryption algorithm to sequentially encrypt and calculate the digest of the data to be burned, thereby obtaining the corresponding encrypted data to be burned and digest information; the burning request includes the data to be burned and the requester information corresponding to the requester. The requester information includes identity information and authentication password; Using the digest information and the requester information, an optical disc identification information is generated. Based on the encrypted data to be burned, the optical disc identification information, and a preset data decryption tool, an optical disc burning operation is performed to obtain the target optical disc. If the target device performs a data reading operation on the target optical disc, the preset data decryption tool is used to read the device information of the target device so as to generate corresponding traceability information based on the device information, and the traceability information is hidden and stored in the storage space of the target device. The traceability information includes time information, address information, hard drive serial number information, network card information, and optical disc information; The preset data decryption tool is used for identity authentication and environment detection, and corresponding processing operations are performed based on the results of identity authentication and environment detection. The processing operations include using the preset data decryption tool to read data from the target optical disc or using the traceability information to monitor the data reading operation of the target device.

2. The method for secure reading and monitoring of optical disc data according to claim 1, characterized in that, The process of sequentially encrypting and digesting the data to be burned using a preset encryption algorithm to obtain the corresponding encrypted data to be burned and digest information includes: The data to be burned is encrypted using a first preset encryption algorithm to obtain the corresponding encrypted data to be burned, and the encrypted data to be burned is digested using a second preset encryption algorithm to obtain the corresponding digest information; the first preset encryption algorithm is the national standard SM4 algorithm; the second preset encryption algorithm is the national standard SM3 algorithm.

3. The method for secure reading and monitoring of optical disc data according to claim 1, characterized in that, After hiding and storing the traceability information in the storage space of the target device, the method further includes: If the target device has established a communication connection with the preset management center, the preset data decryption tool is used to upload the traceability information to the preset management center so that the preset management center can generate an optical disc track audit record based on the traceability information.

4. The method for secure reading and monitoring of optical disc data according to any one of claims 1 to 3, characterized in that, The step of using the preset data decryption tool for identity authentication and environment detection includes: The preset data decryption tool is used to perform identity authentication based on the authentication password to obtain the corresponding authentication result, and environmental detection is performed based on the Internet connection status of the target device to obtain the corresponding detection result; If the authentication password re-entered by the target device matches the authentication password burned in the target optical disc, an authentication result of successful identity authentication is obtained; otherwise, an authentication result of unsuccessful identity authentication is obtained. If the target device's internet connection status is not connected, a detection result indicating that the environmental detection has passed is obtained; otherwise, a detection result indicating that the environmental detection has failed is obtained.

5. The method for secure reading and monitoring of optical disc data according to claim 4, characterized in that, If both the authentication result and the detection result indicate a pass, then the corresponding processing operation based on the results of identity authentication and environmental detection includes: The preset data decryption tool is used to read the encrypted data hidden in the target optical disc and decrypt the encrypted data to obtain the target data.

6. The method for secure reading and monitoring of optical disc data according to claim 4, characterized in that, If either the authentication result or the detection result fails, the corresponding processing operation based on the results of identity authentication and environmental detection includes: The preset data decryption tool is used to block the target device from reading data from the target optical disc, and an alarm message containing the traceability information is uploaded to a preset alarm center so that the preset alarm center can lock the target device based on the alarm message.

7. The method for secure reading and monitoring of optical disc data according to claim 6, characterized in that, The step of uploading the alarm information containing the traceability information to a preset alarm center, so that the preset alarm center can lock the target device based on the alarm information, further includes: By comparing the traceability information hidden and stored locally on the target device with the traceability information contained in the alarm information, evidence collection and responsibility determination for unauthorized reading behavior can be completed.

8. A device for secure reading and monitoring of optical disc data, characterized in that, include: The data encryption module is used to receive a burning request initiated by the requester, and to use a preset encryption algorithm to sequentially perform encryption operations and digest calculation on the data to be burned in order to obtain the corresponding encrypted data to be burned and digest information; the burning request includes the data to be burned and the requester information corresponding to the requester; The requester information includes identity information and authentication password; The optical disc burning module is used to generate optical disc identification information using the digest information and the requester information, and to perform optical disc burning operation based on the encrypted data to be burned, the optical disc identification information and a preset data decryption tool to obtain the target optical disc; The operation traceability module is used to read the device information of the target device using the preset data decryption tool if the target device performs a data reading operation on the target optical disc, so as to generate corresponding traceability information based on the device information and hide the traceability information in the storage space of the target device; The traceability information includes time information, address information, hard drive serial number information, network card information, and optical disc information; The optical disc reading module is used to perform identity authentication and environment detection using the preset data decryption tool, and to perform corresponding processing operations based on the results of identity authentication and environment detection; the processing operations include using the preset data decryption tool to read data from the target optical disc or using the traceability information to monitor the data reading operations of the target device.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the optical disc data secure reading and monitoring method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store computer programs, wherein the computer programs, when executed by a processor, implement the optical disc data secure reading and monitoring method as described in any one of claims 1 to 7.