Cross-network illegal external connection monitoring method based on SM optical disc carrier whole life cycle management

CN122240426BActive Publication Date: 2026-08-07JIANGXI ZHUOAN DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JIANGXI ZHUOAN DIGITAL TECHNOLOGY CO LTD
Filing Date
2026-05-22
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

对于依赖终端Agent的DLP方案而言,其控制重点更多在终端侧行为审计,难以保证离线介质脱离受控终端后仍然维持一致的准入控制逻辑

Benefits of technology

将SM光盘的申请、审批、刻录、策略封装、终端探测、违规上报以及解密准入控制纳入同一技术链条中,实现了由局域网管理平台到光盘载体再到终端使用阶段的连续管控。与传统仅依赖登记封存或者静态口令解密的方式相比,本发明不是在光盘脱离内网后即失去控制,而是在刻录阶段即将广域网探测地址、告警地址、自启动监控小程序以及密文数据同步封装到光盘中,并在读取阶段触发环境探测,从而使SM光盘由单纯的数据存储介质转变为具备自带监测与受控访问能力的安全载体,能够有效解决离线介质出网即失控和流程链条断裂的问题;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122240426B_ABST
    Figure CN122240426B_ABST
Patent Text Reader

Abstract

The application discloses a cross-network illegal external connection monitoring method based on SM optical disc carrier full life cycle management, relates to the technical field of controlled medium management, and comprises the following steps: registering a CD writer asset in a local area network management platform and establishing a binding relationship; receiving an SM optical disc burning task and completing approval association; acquiring a wide area network detection address and an alarm address by a burning client, writing an SM file into an optical disc, and writing a self-starting monitoring applet and encrypted address configuration information; triggering the execution of the self-starting monitoring applet and performing access detection when the optical disc is inserted into a terminal; when the wide area network can be accessed, collecting an evidence package and reporting an alarm to a back end while preventing the decryption access to the SM file; and when the wide area network cannot be accessed and decryption conditions are met, allowing the decryption access to the SM file. Through the implementation of the SM optical disc closed-loop management, the active discovery and real-time blocking capability of cross-network illegal reading are improved, and the audit evidence collection and responsibility tracing effect are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of controlled media management technology, specifically a cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers. Background Technology

[0002] Currently, control over classified optical discs or data storage media requiring high security typically relies on physical management and static encryption methods. Physical management methods mainly include registration, sealing, manual distribution, and manual retrieval; static encryption methods mainly include setting access passwords for the disc content or using ordinary encryption software to encrypt and protect the files on the disc. These solutions can, to some extent, restrict unauthorized personnel from directly reading the data on the disc, but their control focus is primarily on the static access level of "whether the disc content can be opened," lacking the ability to continuously perceive and proactively manage the dynamic usage behavior of the disc after it leaves the internal network environment.

[0003] In existing technologies, solutions similar to this invention generally fall into two main categories. The first category is the ordinary encrypted optical disc solution, which typically controls access to the disc content by inputting a decryption password. The advantage of this solution is its relatively direct implementation, providing basic access protection for the disc content; however, it is essentially a static protection mechanism. Once the disc is removed from the controlled environment, the backend management system usually cannot detect whether the disc has been inserted into an internet terminal, is in an unauthorized external connection environment, or has been attempted to read, nor can it obtain relevant evidence of violations in a timely manner. The second category is the terminal DLP system solution. This type of solution typically monitors and restricts file transfers, media access, and sensitive data operations on terminals by pre-installing an agent client on enterprise intranet PCs. While this type of solution can achieve strong behavior auditing and security control within terminals with the agent installed, its monitoring capabilities are heavily dependent on the client's installation status. Once the disc is removed from the terminal environment with the pre-installed controlled client, its subsequent use can easily escape audit scrutiny, creating a management blind spot.

[0004] Furthermore, existing solutions generally suffer from broken audit chains. In many application scenarios, the application, approval, burning, and subsequent distribution of SM optical discs are often handled by different systems or personnel. The lack of a stable correlation mechanism between burning activities and approval records makes it difficult to accurately trace back to the specific approval form, applicant, usage time, and location of the offending terminal in cases of unauthorized external access, abnormal access, or data leakage. In other words, existing technologies struggle to achieve end-to-end closed-loop management from "application—approval—controlled burning" to "automatic violation alerts—precise accountability."

[0005] Furthermore, existing technologies generally lack control mechanisms that link environmental detection results with decryption access control. For ordinary encrypted optical disc solutions, as long as the corresponding password or decryption conditions are obtained, users can usually attempt to read the contents of the disc, and the system does not determine whether the current terminal is in an internet-reachable environment before decryption. For DLP solutions that rely on terminal agents, their control focus is more on terminal-side behavior auditing, making it difficult to ensure that offline media maintains consistent access control logic after being removed from the controlled terminal. This easily leads to a situation where, although confidential or high-security SM optical discs are controlled when burned within the intranet, once they are taken out of the intranet and connected to an external network terminal, existing systems either cannot detect them, cannot report them in time, or cannot effectively block them before reading, thus leading to the risk of offline media "losing control as soon as it leaves the network." Summary of the Invention

[0006] Based on the shortcomings of the existing technology described above, the purpose of this invention is to provide a cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers, so as to solve the above-mentioned technical problems.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers, comprising: Register the CD burner asset in the local area network management platform and establish a binding relationship between the CD burning terminal; Receive the SM CD burning task initiated by the applicant and approve it by the reviewer, and associate the original applicant's identity identifier with the task identifier corresponding to the burning task; The burning client obtains the WAN probe address and alarm address in encrypted form from the LAN management platform, encrypts the SM file and writes it to the optical disc using transparent encryption and decryption technology, and simultaneously burns the self-starting monitoring applet and the encrypted address configuration information to the non-encrypted area of ​​the optical disc; When the CD is inserted into the terminal, it triggers the execution of a self-starting monitoring applet, decrypts the WAN probe address, and performs access probe. When the detection results indicate that the current terminal can access the wide area network, the monitoring applet automatically starts to collect the terminal's public network exit address, latitude and longitude coordinates, system username, hardware feature code and original applicant's identity, generates an evidence package and sends it to the wide area network alarm backend through the current wide area network channel, while preventing the decryption and access of the SM file. When the detection result indicates that the current terminal cannot access the wide area network, decryption and access to the SM file are allowed, provided that the terminal has installed the corresponding client and the password is verified correctly.

[0008] The present invention is further configured to record the applicant's identity identifier, the reviewer's identity identifier, the task identifier, and the approval time information when receiving an SM optical disc burning task initiated by the applicant and approved by the reviewer, and associate the applicant's identity identifier, the reviewer's identity identifier, and the task identifier with the corresponding burning terminal.

[0009] The present invention is further configured such that the optical disc includes a non-ciphertext area and a ciphertext data area. The non-ciphertext area stores a self-starting monitoring applet and encrypted address configuration information using a standard file system format. The ciphertext data area stores the ciphertext stream of the SM file after being processed by transparent encryption and decryption technology. The data in the ciphertext data area is presented as a binary object that cannot be directly recognized and opened by the standard system before being decrypted and mounted.

[0010] The present invention is further configured such that the encrypted address configuration information is a policy encryption package, which stores the encrypted wide area network detection address and alarm backend address; after the self-starting monitoring applet is triggered and executed, it decrypts the policy encryption package, reads the wide area network detection address and alarm backend address, and performs environmental detection and alarm reporting.

[0011] The present invention is further configured such that, when the terminal has a matching client installed, the matching client listens for system events of optical drive loading, automatically mounts the optical drive and executes the self-starting monitoring applet after detecting that the optical disc is loaded; when the terminal does not have a matching client installed and the operating system pops up an autoplay prompt, the self-starting monitoring applet is executed after user confirmation; when autoplay is not confirmed, the self-starting monitoring applet is manually started to perform environmental detection.

[0012] The present invention is further configured such that the access detection includes: a self-starting monitoring applet initiating a detection request to a preset WAN detection server; the preset WAN detection server returning a preset correct response after receiving the detection request; the self-starting monitoring applet determining whether the current terminal is in an environment where the WAN can be accessed based on whether the preset correct response is received, wherein, when the preset correct response is received, it is determined that the current terminal can access the WAN; when the preset correct response is not received, it is determined that the current terminal cannot access the WAN.

[0013] The present invention is further configured such that the evidence package includes a unique physical identifier code recorded during the production stage of the optical disc, an approval task serial number associated with the local area network management platform, the original applicant's identity identifier, the public network exit address of the current terminal, the local area network physical address, latitude and longitude coordinates, positioning accuracy weight, system username, motherboard serial number, network card feature code, operating system features, and a UTC timestamp of the violation. By performing symmetric encryption on each field in the evidence package using a symmetric key pre-set during the burning stage, an encrypted evidence package is formed. At the same time, a serial number and a message timestamp are added to the evidence package. After receiving the encrypted evidence package, the WAN alarm backend uses the corresponding key to decrypt and restore the encrypted evidence package, and performs uniqueness verification and anti-replay verification based on the serial number and message timestamp.

[0014] The present invention is further configured such that, after approval by the reviewer, the local area network management platform concatenates the task identifier, applicant identity identifier, reviewer identity identifier, approval time information, and burner asset identifier in a preset order, calculates the approval chain digest according to the SM3 algorithm, and encrypts the approval chain digest and writes it into the policy encryption package.

[0015] The invention is further configured such that, after writing the ciphertext stream of the SM file into the ciphertext data area, the unique physical identifier of the optical disc, the starting sector number of the ciphertext data area, the ending sector number of the ciphertext data area, and multiple verification values ​​obtained by performing a preset verification algorithm on multiple sampled sectors extracted at fixed sector intervals are read; the unique physical identifier of the optical disc, the starting sector number, the ending sector number, and the multiple verification values ​​are concatenated in a preset order; a media binding digest is calculated according to the SM3 algorithm; the media binding digest is encrypted and written into the policy encryption package; and a terminal registration identifier is saved in the registered client, which is generated by concatenating the motherboard serial number and the network card feature code.

[0016] The invention is further configured such that, after completing environmental detection, the supporting client obtains the motherboard serial number and network card feature code of the current terminal, and concatenates the motherboard serial number and network card feature code to form the current terminal registration value; the current terminal registration value is compared with the terminal registration identifier stored in the supporting client, and the approval chain digest and media binding digest in the policy encryption package are verified; when the environmental detection result shows that the current terminal cannot access the wide area network, and the current terminal registration value is consistent with the terminal registration identifier, and the approval chain digest verification is passed, the media binding digest verification is passed, and the password verification is correct, the supporting client generates a decryption control token based on the approval chain digest, media binding digest, and terminal registration identifier, and decrypts the key encapsulation information corresponding to the SM file using the decryption control token; when any condition is not met, the plaintext content of the SM file is refused to be output. Specifically, when the environmental detection result shows that the current terminal can access the wide area network, a violation alarm is triggered; when the terminal registration identifier comparison fails, it is recorded as an unauthorized terminal reading event; when the media binding digest verification fails, it is recorded as a suspected media copying event; and when the approval chain digest verification fails, it is recorded as an approval chain inconsistency event.

[0017] This invention provides a cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers. It establishes a binding relationship between burning terminals by registering burning machine assets in a local area network (LAN) management platform; receiving SM optical disc burning tasks initiated by applicants and obtaining approval from an auditor; associating the original applicant's identity identifier with the task identifier; the burning client obtains encrypted WAN detection addresses and alarm addresses from the LAN management platform, encrypts the SM file using transparent encryption / decryption technology, and writes it to the optical disc; simultaneously, it burns a self-starting monitoring applet and encrypted address configuration information to the non-encrypted area of ​​the optical disc; when the optical disc is inserted into the terminal... This triggers the execution of a self-starting monitoring applet, which decrypts the WAN probe address and performs an access probe. When the probe results indicate that the current terminal can access the WAN, the self-starting monitoring applet collects the terminal's public network exit address, latitude and longitude coordinates, system username, hardware signature, and original applicant's identity identifier, generates an evidence package, and sends it to the WAN alarm backend through the current WAN channel, while simultaneously preventing decryption access to the SM file. When the probe results indicate that the current terminal cannot access the WAN, provided that the terminal has installed the corresponding client and the password verification is correct, decryption access to the SM file is allowed. The beneficial effects include: This invention integrates the application, approval, burning, policy encapsulation, terminal detection, violation reporting, and decryption access control of SM optical discs into a single technical chain, achieving continuous control from the local area network management platform to the optical disc carrier and then to the terminal usage stage. Compared with traditional methods that rely solely on registration and sealing or static password decryption, this invention does not lose control once the optical disc leaves the intranet. Instead, it simultaneously encapsulates the wide area network detection address, alarm address, self-starting monitoring applet, and encrypted data into the optical disc during the burning stage, and triggers environmental detection during the reading stage. This transforms the SM optical disc from a simple data storage medium into a secure carrier with built-in monitoring and controlled access capabilities, effectively solving the problems of offline media losing control once it leaves the network and the breakage of the process chain. By employing a pre-detection, pre-decryption control mechanism, the system significantly enhances its proactive identification and prevention capabilities against unauthorized external network access. When the CD is inserted into the terminal, the automatically starting monitoring app first decrypts the WAN detection address in the policy encryption package and initiates a detection request to the preset WAN detection server. If it determines that the current terminal has received a correct preset response and can access the WAN, it immediately collects evidence of the violation and reports it to the alarm backend via the WAN path, simultaneously preventing decryption access to the SM file. Decryption access is only permitted if the detection results indicate that the current terminal cannot access the WAN and the corresponding client and password verification conditions are met. Therefore, compared to existing passive defense solutions, this approach advances the detection of violations from post-event auditing to the pre-read verification stage, enabling proactive identification and real-time blocking of unauthorized reads and reducing the risk of confidential data being directly opened in an external network environment. By using structured evidence collection, encryption protection, and approval chain association, the verifiability, traceability, and accuracy of accountability for violations are improved. Upon detecting unauthorized external connections, the system collects not only the terminal's public network exit address, latitude and longitude coordinates, system username, hardware characteristics, and the original applicant's identity, but also further incorporates the CD's unique physical identifier, approval task serial number, terminal environment evidence, and UTC timestamp into the evidence package. The content of the evidence package is encrypted using a pre-set symmetric key, and uniqueness and replay protection are verified using serial numbers and message timestamps. The correspondence between decryption control and audit records is further enhanced through approval chain digests, media binding digests, and terminal registration identifiers. Thus, each violation alert can be associated with a corresponding approval task, a specific CD, a specific terminal, and a specific time, which helps improve the credibility of evidence collection and the ability to trace accountability for violations.

[0018] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings: Figure 1 The flowchart illustrates a cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers, as an exemplary embodiment of the present invention. Detailed Implementation

[0020] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.

[0021] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0022] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.

[0023] A method for monitoring unauthorized external connections across networks based on the full lifecycle management of SM optical disc media, such as... Figure 1 As shown, it includes: Register the CD burner asset in the local area network management platform and establish a binding relationship between the CD burning terminal; Receive the SM CD burning task initiated by the applicant and approve it by the reviewer, and associate the original applicant's identity identifier with the task identifier corresponding to the burning task; The burning client obtains the WAN probe address and alarm address in encrypted form from the LAN management platform, encrypts the SM file and writes it to the optical disc using transparent encryption and decryption technology, and simultaneously burns the self-starting monitoring applet and the encrypted address configuration information to the non-encrypted area of ​​the optical disc; When the CD is inserted into the terminal, it triggers the execution of a self-starting monitoring applet, decrypts the WAN probe address, and performs access probe. When the detection results indicate that the current terminal can access the wide area network, the monitoring applet automatically starts to collect the terminal's public network exit address, latitude and longitude coordinates, system username, hardware feature code and original applicant's identity, generates an evidence package and sends it to the wide area network alarm backend through the current wide area network channel, while preventing the decryption and access of the SM file. When the detection result indicates that the current terminal cannot access the wide area network, decryption and access to the SM file are allowed, provided that the terminal has installed the corresponding client and the password is verified correctly.

[0024] First, it should be noted that SM optical discs refer to optical disc media for data storage with confidential or high security requirements; cross-network unauthorized external connection refers to the act of attempting to read controlled media that should be used in a physically isolated or intranet environment on a terminal connected to the Internet (wide area network); full lifecycle management covers the entire process control of optical discs from application for burning, approval, physical burning, distribution and use to monitoring and feedback of unauthorized activities.

[0025] Specifically, the first step is to register the CD / DVD burner assets and establish a binding relationship between the burning terminals in the local area network (LAN) management platform. The LAN management platform uniformly registers all burners permitted to participate in SM disc burning, assigning a unique device identifier to each burner and recording its corresponding terminal information, network affiliation information, and authorization status information, thus establishing a stable mapping relationship between the burner assets and specific burning terminals. By pre-establishing this mapping relationship, any subsequent SM disc burning activity can be traced back to a specific device source, providing fundamental support for the association between approval chain information, burning terminal information, and disc media information, thereby ensuring that the source of disc generation is under control and traceable.

[0026] After an applicant initiates an SM disc burning task through the local area network management platform, the platform receives the task and initiates the approval process. The platform records the applicant's identity, task identifier, and application time, and submits the task to an approver for review. Upon approval, the platform further records the approver's identity and approval time, associating the applicant's identity, approver's identity, task identifier, and approval time with the aforementioned burning terminal. By establishing a correspondence between the original applicant's identity and the task identifier, and further associating the approval chain information with the burning terminal, the subsequently burned SM discs have a clear source of identity and task at the carrier level. When abnormal external connections are detected during the disc's subsequent use, the system can trace back to the specific applicant, approver, and specific burning task from the disc's corresponding records, avoiding the problem of a broken chain of responsibility due to reliance solely on manual records.

[0027] After approval, the burning client obtains the encrypted WAN probe address and alarm address from the LAN management platform, and simultaneously obtains the SM file to be written to the optical disc. Instead of directly writing the WAN probe address and alarm address to the optical disc in plaintext, the burning client first encrypts and encapsulates these two types of addresses to form address configuration information, and then writes this information, along with the self-starting monitoring applet, to the non-encrypted area of ​​the optical disc. At the same time, the burning client uses transparent encryption and decryption technology to encrypt the SM file and writes the encrypted SM file ciphertext stream to the encrypted data area of ​​the optical disc. Using this method, the optical disc structurally forms a dual-zone storage mode that separates control information from business data. This allows the monitoring program and policy parameters to be recognized and executed on the terminal side, while the SM file itself remains encrypted, preventing users from bypassing the monitoring program to directly access business data.

[0028] The optical disc consists of a non-encrypted area and an encrypted data area. The non-encrypted area is organized using a standard file system format and stores a self-starting monitoring applet and encrypted address configuration information. The encrypted data area stores the encrypted stream of the SM file after transparent encryption and decryption. The reason for placing the self-starting monitoring applet and address configuration information in the non-encrypted area is to ensure that the terminal can recognize and access the program entry point when loading the optical disc, thereby triggering subsequent control flows. The reason for placing the encrypted stream of the SM file in the encrypted data area, and making this area appear as a binary object that cannot be directly recognized and opened by the standard system before decryption and mounting, is to ensure that the SM file remains in a state of being unreadable until controlled conditions are met. Therefore, the non-encrypted area serves as the control entry point and parameter carrier, while the encrypted data area serves as the business data protection area. Structurally independent but functionally complementary, they together form a controlled packaging mechanism for the SM optical disc.

[0029] The encrypted address configuration information is organized using a policy-encrypted package. This package stores the encrypted WAN probe address and alarm backend address. When the self-starting monitoring app is triggered, it first decrypts the policy-encrypted package, reads the WAN probe address and alarm backend address, and then proceeds with the environment probe and alarm reporting process accordingly. Using a policy-encrypted package instead of directly exposing the plaintext addresses prevents unauthorized users from learning the probe and alarm targets by pre-reading the CD-ROM contents and then disrupting the monitoring logic through methods such as blocking access, forging responses, or modifying pointers. By encrypting and encapsulating the address information, monitoring parameters are only restored and used during the actual program execution phase, thereby improving the security of probe parameters and the effectiveness of the monitoring process.

[0030] When the burning client performs optical disc packaging, it also incorporates approval chain information and burning terminal information into the controlled optical disc generation process. Specifically, upon receiving an SM optical disc burning task initiated by an applicant and obtaining approval from the reviewer, the platform associates the applicant's identity identifier, reviewer's identity identifier, task identifier, and approval time information with the corresponding burning terminal. This ensures that the optical disc possesses management attributes consistent with the approval chain even before physical generation. With this setup, the optical disc is no longer merely a physical medium for storing SM files, but becomes a controlled carrier that simultaneously carries business data, control programs, policy parameters, and approval-related information. Once this controlled carrier enters the usage phase, it can perform environmental detection, evidence collection, and accountability based on the pre-packaged policy information and approval chain mapping, thereby achieving a closed loop from "application—approval—burning" to "use—monitoring—traceability."

[0031] When the CD is inserted into the terminal, the self-starting monitoring applet is executed first. To ensure that this self-starting monitoring applet can be executed in different terminal environments, a layered triggering method is used to start the program. When the terminal has the accompanying client installed, the client listens for system events related to CD-ROM drive loading beforehand. Upon detecting that the CD is loaded, it automatically mounts the CD-ROM drive and executes the self-starting monitoring applet in the non-encrypted area of ​​the CD. When the terminal does not have the accompanying client installed but the operating system supports an autoplay prompt mechanism, the operating system displays an autoplay prompt after recognizing the CD being loaded, and executes the self-starting monitoring applet after user confirmation. When the autoplay prompt is not confirmed or the terminal environment does not support autoplay triggering, the self-starting monitoring applet is executed manually. By setting up a three-level startup path of client event triggering, system autoplay triggering, and manual triggering, the CD can complete the loading of the monitoring program under different terminal configurations as much as possible, thereby avoiding the problem of the monitoring program failing to execute due to relying on a single triggering mechanism.

[0032] After the self-starting monitoring app is triggered, it first accesses the policy encryption package in the non-encrypted area of ​​the CD-ROM, decrypts the encrypted address configuration information stored therein, and extracts the WAN probe address and alarm backend address. After completing the address extraction, the self-starting monitoring app does not immediately enter the SM file access stage, but instead prioritizes the access probe process to determine the current terminal's network environment. Setting the access probe before decryption ensures that the SM file reading process is based on the premise that the network environment has been confirmed, preventing the terminal from directly entering the plaintext access process when in an unauthorized external connection environment. Thus, access probe plays a pre-gating role in the overall control chain, and the probe result directly determines whether to enter the violation processing branch or the controlled decryption judgment branch.

[0033] After the self-starting monitoring app is triggered, it first accesses the policy encryption package in the non-encrypted area of ​​the optical disc, decrypts the encrypted address configuration information stored therein, and extracts the WAN probe address and alarm backend address. After the address extraction is completed, the self-starting monitoring app prioritizes the access probe process to determine the network environment of the current terminal. During access probe, the self-starting monitoring app sends a probe request to the preset WAN probe server, which returns a preset correct response upon receiving the probe request. The self-starting monitoring app determines whether the current terminal is in an environment with WAN accessibility based on whether the preset correct response is received; when the preset correct response is received, the current terminal is determined to be able to access the WAN; when the preset correct response is not received, the current terminal is determined to be unable to access the WAN. By using a probe request and correct response method to complete environment identification, the reachability of the external network can be determined directly based on whether a valid communication path is established between the current terminal and the preset WAN probe server. This moves the network environment determination forward to before the SM file decryption and access, ensuring that subsequent control processes are based on the confirmed network environment.

[0034] To ensure the efficiency of the access detection process, the self-starting monitoring applet sends a detection request to the preset WAN detection server upon triggering and receives the return result within a preset waiting time. If a preset correct response is received within the preset waiting time, a determination result that the current terminal can access the WAN is immediately output; if no preset correct response is received within the preset waiting time, a determination result that the current terminal cannot access the WAN is output. This determination result serves as the direct input for subsequent control processes: when it is determined that the current terminal can access the WAN, the system enters the violation evidence collection and alarm reporting branch and blocks decryption access to the SM file; only when it is determined that the current terminal cannot access the WAN is the subsequent supporting client allowed to further determine whether to allow decryption access based on the terminal installation status, password verification results, and other controlled conditions.

[0035] When the access detection results indicate that the current terminal can access the wide area network, the self-starting monitoring applet immediately switches to the violation processing flow and no longer proceeds to the subsequent decryption and release judgment. At this time, the self-starting monitoring applet first collects terminal environment information and media association information related to the current illegal external connection behavior, including the current terminal's public network exit address, latitude and longitude coordinates, system username, hardware characteristic information, and the original applicant's identity identifier. Among them, the public network exit address is used to identify the network exit corresponding to the current terminal's external access, the latitude and longitude coordinates are used to identify the location of the violation, the system username is used to locate the actual logged-in user of the current terminal, the hardware characteristic information is used to form a device-level identification of the illegal terminal, and the original applicant's identity identifier is used to establish the correspondence between the illegal behavior and the source of the CD application. By collecting the above information simultaneously, the subsequent evidence of violation can cover core elements such as "who applied, who used, where used, through what device, and under what network environment," thereby providing a data foundation for confirming the violation and tracing responsibility.

[0036] When generating the evidence package, the unique physical identifier recorded during the production stage of the optical disc, the approval task serial number associated with the local area network management platform, the original applicant's identity identifier, the current terminal's public network exit address, local area network physical address, latitude and longitude coordinates, positioning accuracy weight, system username, motherboard serial number, network card feature code, operating system characteristics, and the UTC timestamp of the violation are all uniformly encapsulated into the same data structure. Specifically, the unique physical identifier is used to uniquely identify the current SM optical disc carrier; the approval task serial number is used to trace the current violation back to the specific approval chain; the local area network physical address is used to supplement the terminal's local network characteristics; the positioning accuracy weight is used to characterize the credibility of the collected location information; the motherboard serial number and network card feature code are used to further characterize the current terminal's hardware fingerprint; the operating system characteristics are used to assist in identifying the software environment of the violating terminal; and the UTC timestamp is used to uniformly identify the time of the violation. By structurally encapsulating the evidence fields, subsequent alarm data can avoid remaining at the level of scattered logs, instead forming evidence entities with a unified format and clear field meanings, facilitating parsing, storage, and auditing by the WAN alarm backend.

[0037] After the evidence package is formed, each field in the evidence package is symmetrically encrypted using the symmetric key pre-set during the burning stage, forming an encrypted evidence package. By using symmetric encryption, the evidence package no longer exposes specific illegal evidence information in plaintext when generated and sent on the terminal side, thereby reducing the risk of interception, direct parsing, or malicious use during transmission. The symmetric key is associated with the current optical disc carrier, enabling illegal evidence generated on the same optical disc during its lifecycle to be protected and recovered using the corresponding key system.

[0038] To further enhance the uniqueness and temporal reliability of the evidence package, a serial number and a message timestamp are added to it. The serial number identifies the order of different messages generated by the same optical disc during multiple alarms, and the message timestamp identifies the generation time of the current alarm message. After the evidence package is encapsulated and symmetrically encrypted, the self-starting monitoring applet sends the encrypted evidence package to the WAN alarm backend through the WAN channel available to the current terminal. Upon receiving the encrypted evidence package, the WAN alarm backend decrypts and restores it using the corresponding key, recovering the original field content. Then, it performs uniqueness verification and anti-replay verification based on the serial number and message timestamp. When the same serial number is found to be submitted repeatedly, the message timestamp is obviously abnormal, or the serial number and time sequence are inconsistent, it can be determined that the message has a replay risk or abnormal repeated submission behavior.

[0039] After decrypting and restoring the encrypted evidence packet using the corresponding key, the WAN alarm backend can parse, store, and audit the recovered violation evidence fields, and write verified violation records into the alarm database. Since this sending process relies on the current terminal being determined to have WAN access, the evidence packet can be transmitted immediately upon violation, without relying on a pre-installed dedicated audit agent on the terminal or waiting for manual reporting. This allows the system to promptly obtain three key pieces of evidence—terminal environment, media source, and approval relationship—when a CD is illegally inserted into a WAN terminal and attempted to be read, forming a traceable violation record. Simultaneously with evidence packet reporting, an automatically starting monitoring applet continues to block decryption access to the SM file, ensuring that violation alarms and access blocking are synchronized on the same control node.

[0040] While reporting the evidence package, the automatically starting monitoring app immediately blocks decryption access to the SM file. This blocking action doesn't simply log the information and allow the user to continue reading; it directly interrupts the subsequent plaintext output path, preventing the terminal from entering the controlled decryption stage of the SM file when in a WAN-reachable environment. With this setting, violation alerts and decryption blocking are linked on the same control node, avoiding the delayed control problem of "although a violation is detected, the SM file has already been read." By linking environment determination, evidence feedback, and access blocking, the system can simultaneously implement alarm logging and access blocking even in violation environments, enhancing proactive protection against cross-network unauthorized reading attempts.

[0041] When the access probe indicates that the current terminal cannot access the WAN, the system does not directly allow SM file decryption but instead proceeds to a controlled decryption process. At this point, the terminal must meet two prerequisites: the installation of the compatible client and a correct password. The client installation status ensures the terminal has the capability to perform transparent encryption / decryption control, decryption mounting, and access gating; the password verification result confirms the current user has the appropriate access authorization. Only when the conditions of the terminal's inability to access the WAN, the compatible client's installation, and the correct password are simultaneously met will the system allow decryption access to the SM file. By adding the conditions of "client existence" and "correct password" in addition to the "non-WAN environment," the system avoids directly granting SM file read permissions based solely on network security, ensuring that controlled decryption is based on the simultaneous fulfillment of network, terminal, and identity conditions.

[0042] Once the decryption access conditions are met, the accompanying client takes over the subsequent decryption and access process. The client mounts the ciphertext stream of the SM file in the ciphertext data area to the controlled access path and performs transparent decryption when the user accesses the corresponding file content. This allows the user to obtain the desired plaintext result, while the original data in the ciphertext data area remains in ciphertext storage. In other words, SM file decryption and access is not achieved by converting the entire CD-ROM content into plaintext before making it available to the user. Instead, it is transparently decrypted according to the access process under the control of the accompanying client, ensuring that the decryption action always remains within a controlled terminal environment. Therefore, even in non-WAN environments, the system can not only enable the normal use of SM files but also maintain a secure state where ciphertext storage and controlled access coexist.

[0043] Through the aforementioned control process, when the access detection results indicate that the current terminal can access the WAN, the system performs evidence packet generation, symmetric encryption, serial number and message timestamp appending, WAN reporting, server-side decryption and restoration, and decryption blocking. When the access detection results indicate that the current terminal cannot access the WAN, the system further combines the installation status of the accompanying client and the password verification results to determine whether to allow decryption access. In this way, the SM CD-ROM can form a branching control logic of "instant evidence collection and blocking in non-compliant environments, and controlled decryption access in compliant environments" during the usage phase, thereby integrating environment identification, evidence preservation, accountability, and plaintext access control into a unified security management process for the usage phase.

[0044] Furthermore, after approval by the reviewer, the local area network management platform extracts the task identifier, applicant identity identifier, reviewer identity identifier, approval time information, and burner asset identifier corresponding to this SM disc burning task, and concatenates them in a preset order to form the basic data string of the approval chain. This preset order is fixed in advance on the platform side, ensuring that the same combination of fields produces consistent data organization results under different times and terminal conditions. Subsequently, the SM3 algorithm is executed on the basic data string of the approval chain to obtain the approval chain digest. This approval chain digest is used to characterize the core management attributes directly related to the approval process during this SM disc generation, enabling approval process information to participate in subsequent controlled access judgments in a fixed-length digest form. After the approval chain digest is generated, it is not directly exposed in plaintext in the visible area of ​​the disc, but is encrypted and written into a policy encryption package to ensure that the approval chain information is only read and verified when the controlled program is executed, thereby preventing the approval-related information from being directly parsed or tampered with after the disc leaves the controlled environment.

[0045] After the approval chain summary is written into the policy encryption package, the package not only contains the WAN probe address and alarm backend address, but also the approval chain identification information corresponding to this CD-ROM generation process. With this setting, the CD-ROM's subsequent usage no longer relies solely on network environment and password conditions to determine access permission; instead, approval chain information is incorporated into the verification process, ensuring consistency between the CD-ROM's usage and the approval records corresponding to its generation. If the approval chain summary extracted during subsequent reading is inconsistent with the verification result on the client side, it indicates a disconnect, forgery, or inconsistency between the current reading behavior and the original approval chain, thus providing additional criteria for refusing decryption access.

[0046] After writing the ciphertext stream of the SM file into the ciphertext data area, the media-side feature information corresponding to this ciphertext data area is further read, including the unique physical identifier of the optical disc, the starting sector number of the ciphertext data area, the ending sector number of the ciphertext data area, and the contents of multiple sampled sectors extracted at fixed sector intervals. For each sampled sector, a preset verification algorithm is executed to calculate the corresponding verification value. Then, the unique physical identifier of the optical disc, the starting sector number, the ending sector number, and the multiple verification values ​​are concatenated in a preset order to form a media binding basic data string. Subsequently, the SM3 algorithm is executed on the media binding basic data string to calculate the media binding digest. The media binding digest is used to characterize the correspondence between the current optical disc carrier and the ciphertext data area arrangement, so that subsequent decryption access is not only constrained by the approval chain but also by the current physical media state. If the optical disc content is copied to other media, the ciphertext data is reassembled, or the sampled sector content undergoes abnormal changes, the recalculated media binding information will be inconsistent with the original media binding digest, thereby identifying media copying, reassembly, or tampering.

[0047] After the media binding digest is generated, it is also encrypted and written into the policy encryption package. In this way, the policy encryption package becomes a comprehensive control information carrier simultaneously carrying network probing parameters, approval chain digests, and media binding digests. Since the approval chain digest reflects the management chain attribute of "how the optical disc should be generated," and the media binding digest reflects the media chain attribute of "whether the optical disc currently maintains its original physical and data structure state," both, after being jointly written into the policy encryption package, can simultaneously serve as input information for decryption control during subsequent reading stages. This expands the access judgment from a single network probing mechanism to a composite constraint mechanism of "approval consistency + media consistency + environment consistency."

[0048] To incorporate terminals into the controlled access chain, a terminal registration identifier is pre-stored in the registered client software. This identifier is formed by concatenating the motherboard serial number and network interface card (NIC) signature in a fixed order, ensuring that each authorized terminal has a relatively unique and repeatedly extractable identifier. This identifier is not written to the optical disc but is stored locally in the controlled environment of the client software. It is used during the reading phase to determine whether the currently inserted optical disc belongs to the pre-registered authorized terminals. By introducing the terminal registration identifier, the decryption and access of the SM optical disc depends not only on the disc itself and the approval chain information but also on the device-side condition of "whether it is being read on a designated terminal," thereby improving terminal-level access control capabilities.

[0049] After environmental detection, if the current terminal is not determined to be accessible to the wide area network, it enters a further terminal consistency verification and decryption access judgment process. The accompanying client first obtains the current terminal's motherboard serial number and network card signature, and concatenates them in the same order as in the registration phase to form the current terminal registration value. Subsequently, the current terminal registration value is compared with the terminal registration identifier stored in the accompanying client to determine if the current terminal is a registered terminal. If they match, it means the current terminal is consistent with an authorized registered terminal; if they do not match, it means the current terminal is not within the pre-authorized scope. In this way, the terminal hardware identity can be included in the controlled access process without changing the optical disc data area structure.

[0050] After completing the terminal registration value comparison, the accompanying client further verifies the approval chain digest and media binding digest in the policy encryption package. The approval chain digest verification confirms whether the task, applicant, reviewer, approval time, and burner asset identifier corresponding to the current reading behavior are consistent with the approval chain during the optical disc generation stage. The media binding digest verification confirms whether the physical identifier and encrypted data area structure of the current optical disc are still consistent with the generation stage. If the approval chain digest verification fails, it indicates that the current optical disc usage behavior does not correspond to the original approval chain; if the media binding digest verification fails, it indicates that the current media may have undergone media copying, data area reorganization, or content replacement; if the terminal registration value fails to match the terminal registration identifier, it indicates that the current terminal is not a registered authorized terminal. Therefore, the consistency of the SM optical disc reading environment can be judged from three dimensions: approval chain, media chain, and terminal chain.

[0051] When environmental detection indicates that the current terminal cannot access the WAN, and the current terminal registration value matches the terminal registration identifier, and the approval chain digest verification, media binding digest verification, and password verification are all successful, the accompanying client generates a decryption control token based on the approval chain digest, media binding digest, and terminal registration identifier. This decryption control token is not static data fixed on the optical disc, but rather a control result dynamically generated by the accompanying client based on the current terminal state, media state, and approval chain state during reading. With this setup, even if an attacker obtains the encrypted data on the optical disc, they cannot directly construct a valid decryption control token without the correct terminal, correct approval chain, and correct media state. After generating the decryption control token, the accompanying client further uses it to decapsulate the key encapsulation information corresponding to the SM file, thereby obtaining valid key material for transparent decryption access. Subsequently, the accompanying client performs controlled decryption when the user accesses the SM file, ensuring that plaintext output only occurs when all verification conditions are met.

[0052] If any condition is not met, the system will not allow the plaintext content of the SM file to be output. If the environmental detection results indicate that the current terminal can access the wide area network, a violation alarm will be triggered directly, and the aforementioned violation handling process will execute evidence collection and alarm feedback. If the terminal registration value fails to match the terminal registration identifier, it will be recorded as an unauthorized terminal reading event, indicating that the current optical disc has been inserted into an unregistered terminal. If the media binding digest verification fails, it will be recorded as a suspected media copying event, indicating that the current optical disc may no longer be in its original controlled media state. If the approval chain digest verification fails, it will be recorded as an approval chain inconsistency event, indicating that the current usage behavior cannot be mapped to the original approval chain. By classifying and recording different failure reasons, the system can not only uniformly reject unauthorized decryption access, but also subdivide the sources of failure at the audit level, enabling subsequent administrators to distinguish between different types of security events such as unauthorized external connections, unauthorized terminal reading, media copying, and approval chain anomalies.

[0053] By introducing approval chain digests, media binding digests, terminal registration identifiers, and decryption control tokens, the decryption access of SM optical discs is no longer determined solely by whether the network environment is secure and whether the password is correct. Instead, it is now based on the joint validity of approval consistency, media consistency, terminal consistency, and identity consistency. This extends and strengthens the entire control chain of the optical disc from generation and distribution to use, enabling simultaneous verification during the terminal reading stage of whether the optical disc was generated through the correct process, whether it retains its original media state, whether the terminal is a registered terminal, and whether the current user has access rights. This significantly improves the ability to control the entire lifecycle of the SM optical disc carrier.

[0054] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for monitoring cross-network unauthorized external connections based on the full lifecycle management of SM optical disc carriers, characterized in that: include: Register the CD burner asset in the local area network management platform and establish a binding relationship between the CD burning terminal; The system receives SM optical disc burning tasks initiated by applicants and obtains approval from reviewers. It records the applicant's identity identifier, reviewer's identity identifier, task identifier, and approval time information. It associates the applicant's identity identifier, reviewer's identity identifier, and task identifier with the corresponding burning terminals, and associates the applicant's identity identifier with the task identifier corresponding to the burning task. After approval by the reviewer, the local area network management platform concatenates the task identifier, applicant's identity identifier, reviewer's identity identifier, approval time information, and burner asset identifier in a preset order, calculates the approval chain digest according to the SM3 algorithm, and encrypts the approval chain digest and writes it into the policy encryption package. The burning client obtains the encrypted WAN probe address and alarm address from the LAN management platform, and encrypts the SM file using transparent encryption and decryption technology, writing it to the optical disc. Simultaneously, it burns the self-starting monitoring applet and encrypted address configuration information to the non-encrypted area of ​​the disc. After writing the encrypted SM file stream to the encrypted data area, it reads the disc's unique physical identifier, the starting sector number of the encrypted data area, the ending sector number of the encrypted data area, and multiple check values ​​obtained by performing a preset verification algorithm on multiple sampled sectors extracted at fixed sector intervals. The disc's unique physical identifier, starting sector number, ending sector number, and multiple check values ​​are concatenated in a preset order, and a media binding digest is calculated using the SM3 algorithm. The media binding digest is then encrypted and written to the policy encryption package. The terminal registration identifier is saved in the registered client; this identifier is generated by concatenating the motherboard serial number and network card feature code. When the CD is inserted into the terminal, it triggers the execution of a self-starting monitoring applet, decrypts the WAN probe address, and performs access probe. When the detection results indicate that the current terminal can access the wide area network, the monitoring applet automatically starts to collect the terminal's public network exit address, latitude and longitude coordinates, system username, hardware feature code and applicant's identity identifier, generates an evidence package and sends it to the wide area network alarm backend through the current wide area network channel, while preventing the decryption and access of SM files. When the detection result indicates that the current terminal cannot access the WAN, the supporting client obtains the motherboard serial number and network card feature code of the current terminal, and concatenates the motherboard serial number and network card feature code to form the current terminal registration value; compares the current terminal registration value with the terminal registration identifier stored in the supporting client, and verifies the approval chain digest and media binding digest in the policy encryption package; when the environment detection result indicates that the current terminal cannot access the WAN, and the current terminal registration value matches the terminal registration identifier, and the approval chain digest verification passes, the media binding digest verification passes, and the password verification is correct, the supporting client generates a decryption control token based on the approval chain digest, media binding digest, and terminal registration identifier, and decrypts the key encapsulation information corresponding to the SM file using the decryption control token; when any condition is not met, the plaintext content of the SM file is refused to be output.

2. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carrier as described in claim 1, characterized in that, The optical disc includes a non-ciphertext area and a ciphertext data area. The non-ciphertext area uses a standard file system format to store the self-starting monitoring applet and encrypted address configuration information. The ciphertext data area stores the ciphertext stream of SM files after transparent encryption and decryption technology. Before being decrypted and mounted, the data in the ciphertext data area is presented as binary objects that cannot be directly recognized and opened by the standard system.

3. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carrier as described in claim 2, characterized in that, The encrypted address configuration information is a policy encryption package, which stores the encrypted WAN probe address and alarm backend address. When the self-starting monitoring applet is triggered and executed, it decrypts the policy encryption package, reads the WAN probe address and alarm backend address, and performs environmental detection and alarm reporting.

4. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carrier as described in claim 1, characterized in that, When the terminal has the accompanying client installed, the client listens for system events related to CD-ROM loading. Upon detecting that a CD-ROM is loaded, it automatically mounts the CD-ROM drive and executes the self-starting monitoring applet. When the terminal does not have the accompanying client installed and the operating system displays an autoplay prompt, the self-starting monitoring applet is executed after user confirmation. When autoplay is not confirmed, the self-starting monitoring applet is manually started to perform environmental detection.

5. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers according to claim 1, characterized in that, The access probe process includes: the self-starting monitoring applet sends a probe request to a preset WAN probe server; the preset WAN probe server returns a preset correct response upon receiving the probe request; the self-starting monitoring applet determines whether the current terminal is in an environment where the WAN can be accessed based on whether the preset correct response is received. Specifically, if the preset correct response is received, it is determined that the current terminal can access the WAN; if the preset correct response is not received, it is determined that the current terminal cannot access the WAN.

6. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carriers according to claim 1, characterized in that, The evidence package includes a unique physical identifier entered during the CD-ROM production stage, the approval task serial number associated with the local area network management platform, the applicant's identity identifier, the current terminal's public network exit address, local area network physical address, latitude and longitude coordinates, positioning accuracy weight, system username, motherboard serial number, network card feature code, operating system characteristics, and a UTC timestamp of the violation. Each field in the evidence package is symmetrically encrypted using a pre-set symmetric key during the burning stage, forming an encrypted evidence package. A serial number and message timestamp are also added to the evidence package. Upon receiving the encrypted evidence package, the WAN alarm backend decrypts and restores it using the corresponding key, performing uniqueness verification and replay protection verification based on the serial number and message timestamp.

7. The cross-network unauthorized external connection monitoring method based on the full lifecycle management of SM optical disc carrier as described in claim 1, characterized in that, Environmental detection results indicate that a violation alarm is triggered when the current terminal can access the wide area network. When the terminal registration identifier comparison fails, it is recorded as an unauthorized terminal reading event. When the media binding digest verification fails, it is recorded as a suspected media copying event. When the approval chain digest verification fails, it is recorded as an approval chain inconsistency event.

Citation Information

Patent Citations

  • Security defending system for single host

    CN103413083A

  • Alarm tool for illegal external connection of encrypted optical disc

    CN119475323A