A file security control method and device based on a flow number, a device, and a storage medium

By generating and pasting electronic signature data based on serial numbers, the problems of unlimited document copies and lack of traceability are solved, and unique identification and traceability of document circulation are achieved.

CN122133172APending Publication Date: 2026-06-02AEROSPACE NETWORK SECURITY TECH (SHENZHEN) CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
AEROSPACE NETWORK SECURITY TECH (SHENZHEN) CO LTD
Filing Date
2024-12-02
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technology cannot limit the number of copies of a document, allowing recipients to freely forward, print, or perform other operations on the document. The document lacks a unique identifier and its flow and processing cannot be traced.

Method used

By generating serial number-based electronic signature data, including serial number image information, seal attribute information, and original signature information, an electronic seal file stream is generated and pasted into a specified location in the file as a unique identifier for the file.

Benefits of technology

It implements a limit on the number of file copies, provides a unique identifier and traceability for files, and records the file's flow and operation history.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133172A_ABST
    Figure CN122133172A_ABST
Patent Text Reader

Abstract

This invention discloses a file security control method, device, and storage medium based on serial numbers. The method involves determining an initial serial number based on the number of target files and a parameter configuration file; generating sequential serial numbers through counting and accumulation; and generating a serial number image based on the serial number and its attribute information. Next, user information is acquired to generate seal attribute information, and a seal image is generated based on the seal attribute information and the serial number image. The original signature information is acquired, and electronic signature data is generated based on the original signature information and the seal image. Finally, the electronic signature data is pasted into a designated location on the file according to set rules. Each document has a unique electronic signature, serving as a unique identifier for the document and effectively limiting the number of copies. This unique identifier allows for tracing the document's flow and operation records, solving the problem of lack of document traceability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of computer data processing technology and network security, and in particular to a file security management method, device, and storage medium based on serial numbers. Background Technology

[0002] Currently, electronic documents require secure control during transmission and reception to meet the security product needs of specific application scenarios such as secure isolation, cross-network exchange, and mobility control. Existing control measures mainly include: secure control gateways, encrypted data transmission, watermarking, and security level restrictions. These technologies can, to a certain extent, ensure the security of file transmission and effectively reduce file leaks.

[0003] However, there is no limit to the number of copies of documents that have already been sent. Recipients can forward, print, and perform other operations on the documents at will, which does not meet the requirements for document security management. The documents do not have a unique identifier, and there is no traceability of the flow and processing of the documents. After receiving the documents, the recipients have no way of knowing the original issuing unit and the original document information. In situations where traceability is required, it is impossible to trace the source of the documents. Summary of the Invention

[0004] To address these issues, this invention provides a technical solution to resolve the problems of recipients being able to arbitrarily forward and print documents, and the lack of unique identifiers for documents, resulting in a lack of traceability regarding document flow and processing. This invention provides a document security control method, device, and storage medium based on serial numbers to solve at least one of the aforementioned technical problems.

[0005] To achieve the above objectives, in a first aspect, the present invention provides a file security control method based on serial number, comprising:

[0006] Based on the number of target files and parameter configuration files, an initial serial number is determined. The initial serial number is generated into a sequential serial number through counting and accumulation.

[0007] Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information;

[0008] Obtain user information and generate seal attribute information based on the user information;

[0009] Generate seal image information based on the seal attribute information and serial number image information;

[0010] Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data.

[0011] Based on the electronic seal file stream and electronic signature data, the electronic signature data is pasted into a designated location in the file by setting rules.

[0012] Furthermore, the serial number attribute information includes the font size of the serial number.

[0013] Furthermore, the original signature information includes the seal maker's certificate and the signature algorithm identifier.

[0014] Secondly, the present invention also provides a file security control device based on serial number, including: a serial number generation module, an electronic seal file stream generation module, and an electronic signature data pasting module;

[0015] The serial number generation module determines the initial serial number based on the number of target files and parameter configuration file. The initial serial number is then used to generate sequential serial numbers through counting and accumulation.

[0016] Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information;

[0017] The electronic seal file stream generation module is used to acquire user information and generate seal attribute information based on the user information.

[0018] Generate seal image information based on the seal attribute information and serial number image information;

[0019] Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data.

[0020] The electronic signature data pasting module is used to paste the electronic signature data to a set location in the file based on the electronic seal file stream and electronic signature data, according to set rules.

[0021] Furthermore, the serial number attribute information includes the font size of the serial number.

[0022] Furthermore, the original signature information includes the seal maker's certificate and the signature algorithm identifier.

[0023] Thirdly, the present invention provides a computing device, comprising:

[0024] Memory, used to store program instructions;

[0025] The processor is used to call program instructions stored in the memory and execute the file security control method based on serial number as described above according to the obtained program instructions.

[0026] Fourthly, the present invention provides a computer-readable storage medium, including computer-readable instructions, which, when read and executed by a computer, implement the above-described file security control method based on serial number. The readable medium can be multiple, and the multiple readable media can operate independently of each other.

[0027] Compared with existing technologies, this invention determines an initial serial number based on the number of target files and parameter configuration files. It then generates sequential serial numbers through counting and accumulation, and generates a serial number image based on the serial number and its attribute information. Next, it obtains user information to generate seal attribute information, and generates a seal image based on the seal attribute information and the serial number image. Finally, it obtains the original signature information and generates electronic signature data based on the original signature information and the seal image. Finally, it pastes the electronic signature data into a designated location on the file according to set rules. Each document has a unique electronic signature, serving as a unique identifier for the document and effectively limiting the number of copies. Based on this unique identifier, the document's circulation trajectory and operation records can be traced, solving the problem of lack of document traceability. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 A flowchart illustrating an embodiment of the file security control method based on serial number provided by the present invention;

[0030] Figure 2 A flowchart of an embodiment of the file security control method based on serial number provided by the present invention;

[0031] Figure 3 A structural block diagram of an embodiment of the document security control device based on serial number provided by the present invention;

[0032] Figure 4 This is a schematic diagram of the structure of an electronic device provided by the present invention. Detailed Implementation

[0033] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0034] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in the specification of this application means the presence of features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.

[0035] To make the objectives, technical solutions, and advantages of this application clearer, the specific embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0036] The core of this invention is to provide a file security control method based on serial numbers. Figure 1 The diagram shown is a flowchart of the file security control method based on serial numbers provided in this embodiment. To better understand this method, it is now combined with... Figure 1 The technical solution of this embodiment will be described in detail:

[0037] Step S1: Based on the number of target files and the parameter configuration file, determine the initial serial number. The initial serial number is generated into an ordered serial number by counting and accumulating.

[0038] Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information;

[0039] Step S2: Obtain user information and generate seal attribute information based on the user information;

[0040] Generate seal image information based on the seal attribute information and serial number image information;

[0041] Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data.

[0042] Step S3: Based on the electronic seal file stream and electronic signature data, paste the electronic signature data into the designated location in the file by setting rules.

[0043] In a preferred embodiment, the serial number attribute information includes the serial number font size.

[0044] In a preferred embodiment, the original signature information includes the seal maker's certificate and the signature algorithm identifier.

[0045] In this embodiment, an initial serial number is determined based on the number of target files and parameter configuration files. A sequential serial number is generated through counting and accumulation. A serial number image is then generated based on the serial number and its attribute information. Next, user information is obtained to generate seal attribute information, and a seal image is generated based on the seal attribute information and the serial number image. The original signature information is obtained, and electronic signature data is generated based on the original signature information and the seal image. Finally, the electronic signature data is pasted into a designated location on the file according to set rules. Each document has a unique electronic signature, serving as a unique identifier for the document and effectively limiting the number of copies. Based on this unique identifier, the document's circulation trajectory and operation records can be traced, solving the problem of lack of document traceability.

[0046] To facilitate understanding, a specific embodiment will be provided below to further explain this application.

[0047] Example 1:

[0048] Figure 2 The diagram shown is the overall flowchart provided in this embodiment. (See also...) Figure 2 include:

[0049] Step S101: Determine the initial serial number based on the current number of files and the parameter configuration file, and then generate a sequential serial number by using a counter accumulator.

[0050] The serial number image is generated based on the font size of the serial number, the temporary storage address of the serial number image, and the current serial number configured in the configuration file, and then stored as a temporary file on the file server.

[0051] Step S201: Obtain the user certificate from the server, construct the seal attribute information, construct the seal image information based on the serial number image generated in the first part, and then construct the electronic seal data using the seal information, the seal maker's certificate, and the signature algorithm identifier as the original signature text, and finally generate the electronic seal file stream.

[0052] Step S301: Based on the serial number pasting location in the configuration file, the electronic seal file stream, and the file path where the serial number needs to be pasted, call the OFDSigner's addApPos method to paste the serial number to the specified location in the file. At this point, serial number generation and pasting are complete.

[0053] In one embodiment, the present invention provides a file security control device based on serial number, see [link to previous embodiment]. Figure 3 The diagram shown is a structural block diagram of the file security control device based on serial number provided in this embodiment. The device includes:

[0054] The serial number generation module determines the initial serial number based on the number of target files and parameter configuration file. The initial serial number is then used to generate sequential serial numbers through counting and accumulation.

[0055] Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information;

[0056] The electronic seal file stream generation module is used to acquire user information and generate seal attribute information based on the user information.

[0057] Generate seal image information based on the seal attribute information and serial number image information;

[0058] Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data.

[0059] The electronic signature data pasting module is used to paste the electronic signature data to a set location in the file based on the electronic seal file stream and electronic signature data, according to set rules.

[0060] In a preferred embodiment, the serial number attribute information includes the serial number font size.

[0061] In a preferred embodiment, the original signature information includes the seal maker's certificate and the signature algorithm identifier.

[0062] In this embodiment, an initial serial number is determined based on the number of target files and parameter configuration files. A sequential serial number is generated through counting and accumulation. A serial number image is then generated based on the serial number and its attribute information. Next, user information is obtained to generate seal attribute information, and a seal image is generated based on the seal attribute information and the serial number image. The original signature information is obtained, and electronic signature data is generated based on the original signature information and the seal image. Finally, the electronic signature data is pasted into a designated location on the file according to set rules. Each document has a unique electronic signature, serving as a unique identifier for the document and effectively limiting the number of copies. Based on this unique identifier, the document's circulation trajectory and operation records can be traced, solving the problem of lack of document traceability.

[0063] The serial number-based file security control device of this embodiment is used to implement the aforementioned serial number-based file security control method. Therefore, the specific implementation of the serial number-based file security control device can be found in the specific implementation of the serial number-based file security control method section above. The specific implementation can be referred to the description of the corresponding embodiments. The device provided by this invention is attached to the method provided by this invention, and its specific effects can be referred to the above method, which will not be repeated here.

[0064] In one embodiment, a computing device is provided, comprising:

[0065] Memory, used to store program instructions;

[0066] A processor, configured to implement the steps of the serial number-based file security control method as described above when executing the computer program.

[0067] As an example, Figure 4 A schematic diagram of the structure of an electronic device to which this application embodiment applies is shown, such as... Figure 4 As shown, the electronic device 2000 includes a processor 2001 and a memory 2003. The processor 2001 and the memory 2003 are connected, for example, via a bus 2002. Optionally, the electronic device 2000 may also include a transceiver 2004. It should be noted that in practical applications, the transceiver 2004 is not limited to one type, and the structure of the electronic device 2000 does not constitute a limitation on the embodiments of this application.

[0068] In this embodiment, the processor 2001 is used to implement the method shown in the above method embodiment. The transceiver 2004 may include a receiver and a transmitter. In this embodiment, the transceiver 2004 is used to enable the electronic device of this embodiment to communicate with other devices during execution.

[0069] Processor 2001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 2001 may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0070] Bus 2002 may include a pathway for transmitting information between the aforementioned components. Bus 2002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 2002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0071] The memory 2003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0072] Optionally, the memory 2003 stores application code that executes the scheme of this application, and its execution is controlled by the processor 2001. The processor 2001 executes the application code stored in the memory 2003 to implement the investment and financing project recommendation method provided in any embodiment of this application.

[0073] The electronic device provided in this application is applicable to any of the above-described methods, and will not be described again here.

[0074] This invention provides a file security management method based on serial numbers, which has significant advantages and beneficial effects compared with existing technologies. It determines an initial serial number based on the number of target files and parameter configuration files, generates sequential serial numbers through counting and accumulation, and generates a serial number image based on the serial number and its attribute information. Next, it obtains user information to generate seal attribute information, and generates a seal image based on the seal attribute information and the serial number image. It then obtains the original signature information and generates electronic signature data based on the original signature information and the seal image. Finally, it pastes the electronic signature data into a designated location on the file according to set rules. Each document has a unique electronic signature, serving as a unique identifier for the document and effectively limiting the number of copies. Based on this unique identifier, the document's flow and operation records can be traced, solving the problem of lack of document traceability.

[0075] In one embodiment, a computer-readable storage medium is provided, including computer-readable instructions. When a computer reads and executes the computer-readable instructions, it implements the steps of the file security management method based on serial numbers described above. The file security management method based on serial numbers provided by this invention has significant advantages and beneficial effects compared with existing technologies. It determines an initial serial number based on the number of target files and a parameter configuration file; generates an ordered serial number through counting and accumulation; generates a serial number image based on the serial number and its attribute information; generates seal attribute information by acquiring user information; generates a seal image based on the seal attribute information and the serial number image information; acquires the original signature information; and generates electronic signature data based on the original signature information and the seal image information. Finally, it pastes the electronic signature data into a designated location on the file according to set rules. Each document has a unique electronic signature, which serves as a unique identifier for the document, effectively limiting the number of copies. Based on this unique identifier, the document's flow and operation records can be traced, solving the problem of lack of document traceability.

[0076] Through the above description of the embodiments, those skilled in the art will understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the specific device can be divided into different functional modules to complete all or part of the functions described above.

[0077] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0078] In the embodiments covered by this application, it should be understood that the disclosed apparatus, devices, and methods can be implemented in other ways. For example, the division of modules is merely a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple modules or components may be combined or integrated into another device, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, or it may be an electrical, mechanical, or other form of connection.

[0079] The modules described as separate components may or may not be physically separate. Similarly, the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0080] Furthermore, the functional modules in the various embodiments of this application can be implemented either in hardware or as software functional modules. If these functional modules are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program product is stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid state disks (SSDs)).

[0081] The above description is merely an example and illustration of the structure of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined in the claims, all of which should fall within the protection scope of the present invention.

Claims

1. A file security control method based on serial number, characterized in that, include: Based on the number of target files and the parameter configuration file, an initial serial number is determined. The initial serial number is generated into an ordered serial number by counting and accumulating. Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information; Obtain user information and generate seal attribute information based on the user information; Generate seal image information based on the seal attribute information and serial number image information; Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data. Based on the electronic seal file stream and electronic signature data, the electronic signature data is pasted into a designated location in the file by setting rules.

2. The file security control method based on serial number according to claim 1, wherein the serial number attribute information includes the serial number font size.

3. The document security control method based on serial number according to claim 1, characterized in that the original signature information includes the seal maker certificate and the signature algorithm identifier.

4. A document security control device based on serial number, characterized in that, The device includes: Serial number generation module, electronic seal file stream generation module, electronic signature data pasting module; The serial number generation module determines the initial serial number based on the number of target files and parameter configuration file. The initial serial number is then used to generate sequential serial numbers through counting and accumulation. Serial number attribute information is generated based on the serial number, and serial number image information is generated based on the serial number and the serial number attribute information; The electronic seal file stream generation module is used to acquire user information and generate seal attribute information based on the user information. Generate seal image information based on the seal attribute information and serial number image information; Obtain the original signature information, and generate electronic signature data based on the original signature information and seal image information; generate an electronic seal file stream from the electronic signature data. The electronic signature data pasting module is used to paste the electronic signature data to a set location in the file based on the electronic seal file stream and electronic signature data, according to set rules.

5. The document security control device based on serial number according to claim 4, characterized in that, The serial number attribute information includes the font size of the serial number.

6. The document security control device based on serial number according to claim 5, wherein the original signature information includes the seal maker certificate and the signature algorithm identifier.

7. A computing device, characterized in that, include: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the method as described in any one of claims 1 to 3 according to the obtained program instructions.

8. A computer-readable storage medium, characterized in that, It includes computer-readable instructions, which, when read and executed by a computer, implement any one of the methods of claims 1 to 3. The readable medium may be multiple, and the multiple readable media can operate independently of each other.