Enterprise-oriented qr code management, service and security assurance method and device

By building a unified QR code management platform and security system, the problems of management silos and security risks in enterprise-level QR code applications have been solved, realizing centralized and unified management of QR codes and efficient and secure data utilization, thereby improving operational efficiency and data value mining capabilities.

CN122263932APending Publication Date: 2026-06-23ZHEJIANG TOBACOO CO
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG TOBACOO CO
Filing Date
2026-03-09
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing QR code application models suffer from problems such as fragmented functions, isolated management, lack of lifecycle management, prominent data security risks, and insufficient exploitation of data value. In particular, enterprise-level applications lack centralized management, deep integration, and advanced security control capabilities.

Method used

A unified QR code management platform is constructed, employing a tree-like topology and a five-layer hierarchical mechanism for encoding management, achieving full lifecycle management, and defining attributes in conjunction with a tagging mechanism; QR code generation, beautification, and printing services are configured, and a code analysis system and security system are established, ensuring data security through encryption algorithms and access control policies.

Benefits of technology

It enables centralized and unified management of QR codes, improves operational efficiency and data security, unlocks the value of data assets, meets the high security requirements of enterprise-level applications, and has good scalability and adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122263932A_ABST
    Figure CN122263932A_ABST
Patent Text Reader

Abstract

The present application belongs to the field of information technology and data management, and relates to a two-dimensional code management, service and security guarantee method and device for enterprise level, which comprises the following steps: constructing a unified two-dimensional code management platform, adopting a tree topology structure and a five-layer classification mechanism to uniformly encode and manage two-dimensional codes, and combining a label mechanism to multi-dimensionally define two-dimensional code attributes; performing full life cycle management on two-dimensional codes; configuring the generation, beautification, template customization, printing and interface of providing external services of two-dimensional codes through an API interface; establishing a code analysis system to collect, count, analyze and visualize two-dimensional code usage data; and constructing a code security system through automatic content review, localized deployment, encryption algorithm, API security reinforcement and access control strategy. The present application has good expansibility and adaptability, and can improve operation efficiency and service capability, strengthen data security guarantee and excavate data asset value through centralized, unified and standardized management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information technology and data management technology, and in particular to enterprise-level methods and devices for QR code management, services and security. Background Technology

[0002] QR code technology has been widely used in various industries due to its advantages such as large information capacity, ease of generation and reading, and low cost.

[0003] However, as applications become more widespread and scale up, existing QR code application models have revealed numerous problems:

[0004] Functional fragmentation and management silos: Each department and business line independently builds and uses the QR code system, resulting in duplicated system functions and inconsistent data standards, forming "information silos" that are difficult to plan and manage in a unified manner.

[0005] Lack of lifecycle management: There is a lack of a unified process for QR code application, review, issuance, update, deactivation and cancellation.

[0006] Data security risks are prominent: QR codes may carry sensitive information, but current technologies lack effective encryption methods and content security review mechanisms. Meanwhile, the openness of API interfaces introduces security threats such as unauthorized access and data breaches.

[0007] The value of data has not been fully realized: the data generated by scanning codes is scattered across various independent systems and has not been effectively aggregated, integrated, and analyzed. As a result, it cannot provide data support for business decisions and process optimization, and the value of data assets has been buried.

[0008] Currently, there are some QR code generation tools or SaaS service platforms on the market, but they are mainly geared towards the simple, single-point application needs of individuals or micro-enterprises. They lack the capabilities in centralized management, deep integration, advanced security control, and enterprise-level data analysis, and cannot meet the complex needs of large organizations for comprehensive governance and empowerment of QR codes.

[0009] Therefore, there is an urgent need for a systematic solution that can achieve unified management, standardized services, in-depth analysis, and security assurance for enterprise-level QR codes. Summary of the Invention

[0010] To address the aforementioned technical problems, this invention provides an enterprise-level method for QR code management, service, and security, employing the following technical solution, including the following steps: A unified QR code management platform is constructed, which adopts a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category and QR code generation code, and combine a tag mechanism to define QR code attributes in multiple dimensions. The QR code is managed throughout its entire lifecycle, from application, approval, registration, issuance, update, deactivation to cancellation. Configure the interfaces for generating, beautifying, customizing templates, printing, and providing services to the outside world through API interfaces for the QR codes; Establish a code analysis system to collect, statistically analyze, and visualize the usage data of the QR codes, and realize data overview, multi-dimensional early warning, in-depth data analysis, and report generation; We build a QR code security system to ensure the security and controllability of QR code data from generation to destruction through automatic content review, localized deployment, encryption algorithms, API security reinforcement, and access control policies.

[0011] Preferably, the tree topology and five-level hierarchical mechanism are as follows: The organizational relationships are presented in a tree structure. The QR code is positioned based on a three-level standard structure of belonging organization, belonging platform, and belonging unit. Then, it is further subdivided into scenarios through belonging classification, and finally a unique QR code is generated. The labeling mechanism is used to define the technical type, scope of use, and content format attributes of the QR code.

[0012] Preferably, in the full lifecycle management: The application is initiated through the management interface or API interface, and the QR code is in an inactive state after the application is submitted. The approval process refers to the authorization process for the official use of QR codes. The registration process involves formally entering the approved QR code information into the system, assigning it to a designated level, unit, and label, and configuring its initial state. The distribution supports downloading QR code images individually or in batches, and is compatible with various printing methods; The update refers to modifying the associated form content or permissions without changing the issued QR code pattern.

[0013] Preferably, the QR code service includes: Single code creation and batch code generation services, where batch code generation is achieved by importing data from an Excel template; QR code beautification service, supporting template selection, text editing, image upload, and background setting; The QR code template service supports the creation, saving, and reuse of QR code styles and content templates for different scenarios; The QR code printing service supports arranging QR code labels on A4 paper or using compatible label printers. A unified API interface service provides various RESTful interfaces, including code management, data query, and form operations.

[0014] Preferably, the code analysis system includes: The dashboard provides a comprehensive overview of metrics, including the number of codes issued, scanning activity, usage, and user activity. The early warning module includes access threshold warning, redirect address validity warning, illegal access warning, and illegal content warning; The data analysis module enables statistical analysis of code issuance volume, scan volume, number of expired codes, and QR code activity by region, time, type, and label statistical criteria. The data reporting module provides code address data reports and dynamic data summary reports, and supports data export to Excel and PDF formats.

[0015] Preferably, the automatic content review includes reviewing the content of the target content accessed via the QR code, specifically covering: Image content moderation, identifying advertisements and inappropriate content; Text content moderation, identifying advertisements, text, and their variations; Document content review: analyze and review any prohibited content within the document. Video content review uses a combination of image, text, and voice technologies to filter out illegal content in videos; The audit supports custom blacklists, whitelists, and audit strategy configurations.

[0016] Preferably, the encryption algorithm includes at least one of the following: Binary image chaotic encryption: Encryption is achieved by generating a chaotic sequence and performing an XOR operation with the pixel values ​​of the QR code; Multi-level encryption: The QR code information is encrypted multiple times at different levels and decoded using different keys; Double encryption based on Rindael and XOR operation: combining the Rindael algorithm and XOR operation for high-strength encryption.

[0017] Preferably, the API security hardening includes: Prohibit the display of insecure resources, and limit page size and API call frequency; Enforce API authentication to prevent unauthorized access; Implement an authorization mechanism to ensure that authenticated users can only access data within their authorized scope; Strengthen server security by enforcing the use of HTTPS and deploying load balancing equipment.

[0018] Preferably, the access control policy is based on at least one of the following rules: IP address range rules; IP blacklist / whitelist rules; Access frequency limit rules; Application type rules; Timestamp verification rules.

[0019] To address the aforementioned technical problems, this invention also provides an enterprise-level QR code management, service, and security device, employing the following technical solution, including: The module is used to build a unified QR code management platform. It adopts a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category and QR code generation code, and combine a tag mechanism to define QR code attributes in multiple dimensions. The management module is used to manage the QR code throughout its entire lifecycle, from application, approval, registration, issuance, update, deactivation to cancellation. The configuration module is used to configure the generation, beautification, template customization, printing, and API interfaces of the QR code. The analysis module is used to establish a code analysis system to collect, statistically analyze, and visualize the usage data of the QR codes, and realize data overview, multi-dimensional early warning, in-depth data analysis, and report generation. The security module is used to build a QR code security system. Through automatic content review, localized deployment, encryption algorithms, API security hardening, and access control policies, it ensures that QR code data is secure and controllable throughout the entire process from generation to destruction.

[0020] Compared with the prior art, the present invention has the following main advantages: (1) Centralized and standardized management of QR codes has been achieved: Through the “one tree + five layers + label” model and full life cycle management, the problem of scattered QR code applications and chaotic management has been completely solved, and a unified QR code asset library for enterprises has been formed.

[0021] (2) Improved operational efficiency and service capabilities: Features such as batch code generation, templated design, and API integration significantly reduced the production and management costs of QR codes, enabling business departments to quickly and conveniently acquire and use QR code capabilities.

[0022] (3) Enhanced data security: Through a full-chain security design from content, transmission, storage to access, a defense-in-depth system has been built, which effectively reduces the risk of data leakage and tampering and meets the high security requirements of enterprise-level applications.

[0023] (4) The value of data assets has been explored: Through a comprehensive code analysis system, scattered scanning data is transformed into valuable business insights, providing accurate data support for marketing decisions, process optimization and resource allocation, and realizing data feedback to business.

[0024] (5) It has good scalability and adaptability: The system adopts a microservice and front-end and back-end separation architecture, and integrates with various systems through API gateway, which can flexibly adapt to changes in business scenarios and future technological developments in different industries. Attached Figure Description

[0025] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0026] Figure 1 This is a flowchart of an embodiment of the enterprise-level QR code management, service, and security method of the present invention; Figure 2 This is a schematic diagram of the overall system architecture used in the enterprise-level QR code management, service and security method of the present invention (reflecting the 214N architecture: two pools, one base, four capabilities, and N applications). Figure 3 This is a schematic diagram of the functional architecture used in the enterprise-level QR code management, service and security method of the present invention; Figure 4 This is a flowchart of the code issuance data used in the enterprise-level QR code management, service and security method of the present invention; Figure 5 This is a data flow diagram of code usage used in the enterprise-level QR code management, service, and security method of the present invention; Figure 6 This is a schematic diagram illustrating the application of components used in the enterprise-level QR code management, service, and security method of the present invention. Figure 7 This is a schematic diagram of the QR code integration architecture used in the enterprise-level QR code management, service and security method of the present invention; Figure 8 This is a schematic diagram of the city-level deployment architecture for applying the enterprise-level QR code management, service, and security method of this invention; Figure 9 This is a schematic diagram of a structure of an embodiment of the enterprise-level QR code management, service and security device of the present invention; Figure 10This is a schematic diagram of the structure of an embodiment of the computer device of the present invention.

[0027] Figure reference numerals: 60-Enterprise-level QR code management, service and security device, 61-Building module, 62-Management module, 63-Configuration module, 64-Analysis module, 65-Security module, 7-Computer equipment, 71-Memory, 72-Processor, 73-Network interface. Detailed Implementation

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.

[0029] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0030] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.

[0031] It should be noted that the enterprise-level QR code management, service and security method provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the enterprise-level QR code management, service and security device is generally set in the server / terminal device.

[0032] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.

[0033] Example 1 Please refer to Figure 1 The diagram illustrates a flowchart of an embodiment of the enterprise-level QR code management, service, and security method of the present invention. The enterprise-level QR code management, service, and security method includes the following steps: Step S1: Construct a unified QR code management platform. Use a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category, and QR code generation code. Combined with a labeling mechanism, QR code attributes are defined in multiple dimensions.

[0034] In this embodiment, the electronic device (e.g., a server / terminal device) on which the enterprise-level QR code management, service, and security method runs can receive enterprise-level QR code management, service, and security requests via wired or wireless connections. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAXX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future-developed wireless connection methods.

[0035] In this embodiment, the tree topology and five-level hierarchical mechanism are as follows: The organizational relationships are presented in a tree structure. The QR code is positioned based on a three-level standard structure of affiliated organization, affiliated platform, and affiliated unit. Then, it is further subdivided into scenarios through affiliation classification, and finally a unique QR code is generated. The tagging mechanism is used to define the technical type, scope of use, and content format attributes of QR codes.

[0036] Tree-like topology refers to the hierarchical relationship of an organization that is visually represented by a tree-like topology (such as province-city-county).

[0037] The organization to which it belongs is such as the Tobacco Bureau of XX City; the platform to which it belongs is such as the business platform of marketing, monopoly, logistics, etc.; the unit to which it belongs is such as the specific department or functional module under the platform; the category to which it belongs is such as a more granular scenario category defined by the user department, such as "equipment inspection" or "material requisition"; and the QR code generated is a unique code generated by the system.

[0038] Tags refer to adding multi-dimensional attribute labels to QR codes, such as "static code / live code / dynamic code", "internal use / external use", "internal form / external link", etc., to achieve flexible classification, filtering and statistics.

[0039] In this embodiment, the QR code service includes: Single code creation and batch code generation services, where batch code generation is achieved by importing data from an Excel template; QR code beautification service, supporting template selection, text editing, image upload, and background setting; The QR code template service supports the creation, saving, and reuse of QR code styles and content templates for different scenarios; The QR code printing service supports arranging QR code labels on A4 paper or using compatible label printers. A unified API interface service provides various RESTful interfaces, including code management, data query, and form operations.

[0040] Single code creation offers a visual interface or API, combined with templates and beautification features to quickly generate a single QR code.

[0041] Batch QR code generation can be achieved by downloading an Excel template, filling in the data, and generating a large number of QR codes with the same structure but different content, greatly improving efficiency.

[0042] The QR code beautification and template service offers a rich template library and visual editing tools, supporting customization of text, colors, fonts, and backgrounds to ensure a consistent corporate image and enhance the recognizability and aesthetics of QR codes.

[0043] API interface services can provide a complete set of RESTful APIs through API gateways, including but not limited to code-related interfaces, data-related interfaces, and form-related interfaces.

[0044] QR code related interfaces include CRUD operations for code hierarchy / category / tags, and creating / downloading / activating / deactivating QR codes.

[0045] Data-related interfaces include QR code statistics, personnel information query, and organization query.

[0046] Form-related interfaces include those for form creation, querying, and permission settings. This allows third-party business systems to seamlessly integrate QR code capabilities while ensuring that all QR codes remain under the unified management of the central platform.

[0047] Step S2 involves managing the entire lifecycle of the QR code, from application, approval, registration, issuance, update, deactivation to cancellation.

[0048] In this embodiment, during the full lifecycle management: The application is initiated through the management interface or API interface, and the QR code is inactive after the application is submitted. Approval is the process of authorizing the official use of QR codes. Registration involves formally entering the approved QR code information into the system, assigning it to a specified level, unit, and label, and configuring its initial state. It supports downloading QR code images individually or in batches and is compatible with various printing methods; An update modifies the associated form content or permissions without altering the issued QR code pattern.

[0049] In the full lifecycle management, application refers to users submitting applications through the platform interface or API, linking specific forms or links; approval refers to establishing an electronic approval process to ensure the compliance of QR code usage; registration refers to the system officially registering the QR code information into the database after approval, assigning it to a preset level, category, and tag; distribution supports downloading QR code images individually or in batches, providing multiple printing options such as A4 printing and die-cut adhesive labels; updates allow administrators to modify the content of the forms or access permissions associated with the QR code without changing the QR code image, achieving "code unchanged, content changed"; deactivation and cancellation can provide two status management options: temporary closure and permanent invalidation, meeting the needs of different business scenarios.

[0050] Step S3: Configure the QR code generation, beautification, template customization, printing, and the interface for providing services to the outside world through the API interface.

[0051] The generation process employs dynamic encryption algorithms (such as AES-256) combined with unique identifiers (UUIDs) to generate tamper-proof QR codes, achieving high-fault-tolerance encoding through QR code standard libraries (such as ZXing). The beautification stage utilizes an SVG vector graphics engine for visual optimization, supporting corporate logo embedding, gradient color schemes, and dynamic watermarking technology to ensure brand consistency. Template customization is achieved through a low-code platform, defining configurable fields based on JSON Schema and enabling visual drag-and-drop editing using the React / Vue front-end framework. The printing process integrates a PDF generation library (iText) and the ZPL instruction set, adapting to industrial-grade label printers and supporting batch printing and consumable management. External services utilize a RESTful API architecture, built on a microservice cluster using Spring Cloud, implementing access control through OAuth2.0+JWT, and combining with an API gateway (Kong) for traffic limiting and log auditing. An SDK package is also provided to support multi-language integration, forming a secure and controllable QR code management system from generation to distribution.

[0052] Step S4: Establish a code analysis system to collect, statistically analyze, and visualize QR code usage data, enabling data overview, multi-dimensional early warning, in-depth data analysis, and report generation.

[0053] In this embodiment, the code analysis system includes: a one-stop overview dashboard that centrally displays indicators such as the number of codes issued, scanning status, call status, and activity status; an early warning module that includes access threshold warnings, redirect address validity warnings, illegal access warnings, and illegal content warnings; a data analysis module that performs statistical analysis on the number of codes issued, scanned, expired codes, and QR code activity by region, time, type, and tag statistical criteria; and a data reporting module that provides code address data reports and dynamic data summary reports, and supports data export to Excel and PDF formats.

[0054] The One-Code Overview Dashboard presents key metrics such as total number of codes issued, total number of codes scanned, real-time activity, and API call activity in a visual data dashboard format.

[0055] In the early warning mechanism, the access volume warning sets an access volume threshold for QR codes of important marketing activities or key processes, and automatically issues an early warning when the access volume is too high or too low; the validity warning can periodically check the validity of the QR code jump address and issue an early warning for invalid links; the illegal access and content warning is based on security policies and content review rules, and provides real-time warnings for abnormal access and illegal content.

[0056] Data analytics can provide multi-dimensional (time, region, type, tag) data analysis functions, including but not limited to code issuance statistics, code scanning statistics, expired code statistics, and activity statistics.

[0057] QR code distribution statistics provide insights into the distribution of QR code resources across various business lines. Scanning statistics allow for analysis of user scanning behavior and evaluation of campaign effectiveness. Expired code statistics enable the periodic cleanup of invalid resources and optimized management. Activity statistics identify frequently used QR codes and scenarios. Data reports generate lists of QR code addresses, dynamic data summaries, and other reports, with support for exporting to Excel / PDF for easy archiving and in-depth analysis.

[0058] Step S5: Build a QR code security system. Through automatic content review, localized deployment, encryption algorithms, API security reinforcement, and access control strategies, ensure that QR code data is secure and controllable throughout the entire process from generation to destruction.

[0059] Automated content moderation includes the review of content accessed via QR codes, specifically covering: Image content moderation, identifying advertisements and inappropriate content; Text content moderation, identifying advertisements, text, and their variations; Document content review: analyze and review any prohibited content within the document. Video content review uses a combination of image, text, and voice technologies to filter out illegal content in videos; The review process supports custom blacklists, whitelists, and review policy configurations.

[0060] The automatic content moderation feature integrates an intelligent content moderation engine to automatically scan and filter the content (images, text, documents, videos) of the target page linked by the QR code, blocking illegal or harmful information such as advertisements.

[0061] Localized deployment refers to the system being deployed within the organization's internal network (such as the tobacco intranet), where all data parsing and redirection are completed internally, ensuring that core data "does not leave the domain." Redirection to external addresses is securely proxied through a gateway.

[0062] The encryption algorithm includes at least one of the following: Binary image chaotic encryption: encryption is achieved by generating a chaotic sequence and performing an XOR operation with the pixel value of the QR code; Multi-level fusion encryption: the QR code information is encrypted multiple times at different levels and decoded using different keys; Dual encryption based on Rindael and XOR operation: high-strength encryption is achieved by combining the Rindael algorithm and XOR operation.

[0063] Binary image chaotic encryption refers to performing chaotic encryption at the pixel level to enhance the security of the QR code image itself.

[0064] Multi-level fusion encryption encrypts the encoded information multiple times using multiple keys, increasing the difficulty of cracking it.

[0065] Based on dual encryption using Rindael and XOR, and employing a combination of high-strength encryption algorithms, the confidentiality of data is ensured during transmission and storage.

[0066] API security hardening includes: prohibiting the display of insecure resources, limiting page size and API call frequency; enforcing API authentication to prevent unauthorized access; implementing authorization mechanisms to ensure that authenticated users can only access data within their authorized scope; and server security hardening, mandating the use of HTTPS protocol and deploying load balancing equipment.

[0067] API security hardening implements identity authentication (such as API Key, Auth) and authorization mechanisms, which can limit the frequency of calls, prevent malicious crawling, use HTTPS transmission, and strengthen security on the server side.

[0068] Access control policies are based on at least one of the following rules: IP address range rules; IP blacklist / whitelist rules; access frequency limit rules; application type rules; and timestamp verification rules.

[0069] Access control policies are based on a variety of rules, including IP address ranges, IP blacklists and whitelists, access frequency, application type, and timestamps, to build a sophisticated access control system.

[0070] Figure 2 This is a schematic diagram of the overall system architecture used in the enterprise-level QR code management, service, and security method of this invention (representing a 214N architecture: two pools, one foundation, four capabilities, and N applications). Figure 2As shown, the two pools refer to the code address management pool (which stores metadata information for all QR codes) and the data resource pool (which stores scanning records, form data, etc.). The one base refers to the QR code management center base, providing basic computing, storage, network resources, and the core engine. The four capabilities are the four core modules of this invention: code management, code service, code analysis, and code security. The N applications refer to various business applications built based on this embodiment, such as "code-based marketing," "code-based supervision," and "Fragrant Red Station," etc.

[0071] The system is recommended to be deployed in the organization's internal data center, based on an x86 server cluster, using the Spring Clud microservice framework, with front-end and back-end separation. Databases will use MySQL (relational) and SS / NAS (unstructured data). Redis will be used as a cache, message queues (such as Kafka / RcketMQ) for asynchronous decoupling, and an API gateway (such as Spring Clud Gateway) to centrally manage all API interfaces. The deployment architecture is as follows: Figure 7 As shown, this ensures isolation between internal and external networks and controllable data flow.

[0072] Figure 3 This is a schematic diagram of the functional architecture used in the enterprise-level QR code management, service, and security method of this invention. (See diagram below.) Figure 3 As shown, the main function of the QR code center is to manage the entire lifecycle of QR codes used in business application scenarios, such as the application, creation, tracking, and cancellation of QR codes across various business lines within the tobacco industry.

[0073] During use, in response to the actual needs of various business lines for QR codes, a unified QR code issuance and management system was implemented, an effective permission management mechanism was established, and unified parsing and redirection were performed. This broke down the application barriers caused by the original application's own code creation and achieved comprehensive management of QR codes.

[0074] Based on the existing x86 server, the resource layer allows third-party applications to access the QR code center open platform via the network. The submitted data is then uniformly accessed and stored, enabling services such as creating, managing, canceling, and securely authenticating the required QR codes.

[0075] At the service layer, city-level data services and invocation services are built for the QR code center. The data services cover the entire lifecycle of QR code management business. Combined with the invocation services, API call control, call permission authentication, and call security control are implemented to provide strong support for the QR code center.

[0076] The application layer includes four major modules: code management, code service, code analysis, and code security. It involves 12 major functional points, basically covering every aspect of QR code management applications at the prefecture-level city level, laying a solid foundation for the digital transformation of QR code management at the prefecture-level city level.

[0077] On the presentation layer, the QR code center supports use and display on PC (H5 page), mobile devices, and other terminals. For external retailers and consumers, it supports parsing and redirecting QR code scanning requests; internally, it enables all employees to redirect business requests via the platform.

[0078] At the level of standards and specifications, the system construction follows and is designed and built based on the technical specifications of the tobacco industry's basic digital technology platform, including: information classification and coding specifications, application system data standard specifications, application system interface and portal integration specifications, application system technical development specifications, application system application security management specifications, and application system operating environment specifications.

[0079] At the technical system level, the selection of the system construction technology system follows the technical specifications of the tobacco industry's basic digital technology platform, including the selection of front-end development languages, frameworks, operating environments, component libraries, packaging tools, etc.; the selection of back-end development languages, technical frameworks, microservice frameworks, etc.; and the selection of middleware, databases and storage, and data development tools.

[0080] At the application security level, system construction adheres to application system security management standards, encompassing both application system security and data security. Application system security includes: identity authentication, session security, access control, logging, exception handling, configuration security, and component security. Data security includes: security related to data acquisition, data transmission and storage, data usage, and data sharing.

[0081] Figure 4 This is a flowchart of the code issuance data used in the enterprise-level QR code management, service, and security method of this invention. (Example) Figure 4 As shown, QR code issuance reflects the unified management of QR codes by the QR code center. The specific process begins with a QR code issuance application from a user department. This involves determining the code's level, category, and label. After approval, the corresponding permissions for code issuance are confirmed (the permissions are specific to a single application scenario). Subsequently, QR codes can be created and distributed through the QR code center's page or API interface.

[0082] Figure 5 This is a data flow diagram of code usage used in the enterprise-level QR code management, service, and security method of this invention. (Example) Figure 5As shown, after an application creates and distributes a QR code through the QR code center, when an end user scans the QR code using a mobile phone or other browser, the QR code center will identify, parse, and redirect the user according to the platform's identification and control logic. First, the QR code is scanned to determine if it exists. If it does, the scanner's information is verified; otherwise, an error message is displayed. After verifying the scanner's information, it is checked. If the scanner has permission, the access information is recorded; otherwise, an error message is displayed. After recording the access information, the access address is converted, and it is then determined whether it is a single code with multiple addresses. If it is a single code with multiple addresses, the target form is selected; otherwise, address pre-access is performed. After selecting the target form, the address pre-access process also begins. After address pre-access, the URL is verified. If correct, the user is redirected to the desired URL, the form is displayed, and the process ends. After an error message is displayed, the form display process begins, and then the process ends.

[0083] Figure 6 This is a schematic diagram illustrating the components used in the enterprise-level QR code management, service, and security method of this invention. For example... Figure 6 As shown, by integrating mature modular components, it provides second-level business monitoring and response capabilities for application front-ends and back-ends. It offers data access, data computation, data storage information querying, and API gateway integration monitoring functions.

[0084] The log service provides log collection components for system log data scenarios, enabling quick log data collection, consumption, query and analysis without development, thereby improving system operation and maintenance efficiency.

[0085] The message queue provides asynchronous decoupling and peak-shaving capabilities for the parsing and forwarding of QR codes. Based on highly available distributed cluster technology, it offers a range of messaging services, including message subscription and publishing, message querying, scheduled (delayed) messaging, and resource statistics.

[0086] The system utilizes Redis caching to provide a high-performance, highly reliable, and smoothly scalable key-value in-memory database service. It supports various data types, including strings, lists, sets, sorted sets, and hash tables.

[0087] It supports simultaneous linear expansion of read / write concurrency and storage capacity. It also supports automatic load balancing and high-concurrency read / write operations.

[0088] Relational databases provide MySQL databases or future cloud-based RDS databases, supporting advanced features such as read / write separation, data compression, and intelligent optimization.

[0089] OSS (Object Storage Service) is a distributed object storage system that provides massive, secure, low-cost, and highly reliable cloud storage services. It supports the system to store and access various unstructured data files, including text, images, audio, and video, anytime and anywhere over the network.

[0090] File Storage NAS is a distributed file storage system that offers shared access, elastic scalability, high reliability, and high performance. It supports access control for file system files and directories, and log auditing of file system operations.

[0091] The QR code center is developed based on native technology systems, including front-end interface, back-end services, API gateway, etc. The system adopts front-end and back-end separation and is designed and developed based on the Spring framework.

[0092] API gateways provide users with complete API hosting services, assisting them in exposing their capabilities, services, and data to various systems in the form of APIs. They can also publish APIs to an API marketplace for wider use by developers. Multiple measures are provided to ensure API security and reduce the risks associated with API sharing, including attack prevention, replay protection, request encryption, authentication, access control, traffic control, and monitoring alerts.

[0093] The system uses a front-end / back-end separation model, requiring separate deployment of the web application. The front-end and back-end use HTTP or other protocols to interact and make requests. PC front-end applications are developed using frameworks such as HTML5, CSS3, ES6, Vue, and Ant Design. Mobile application front-ends are developed using frameworks such as HTML5, CSS3, and Vue.

[0094] Figure 7 This is a schematic diagram of the QR code integration architecture used in the enterprise-level QR code management, service, and security method of this invention. (See diagram below.) Figure 7 As shown, all internal and external systems are connected using HTTPS and HTTP interface protocols. For internal system integration, a user access control interface is provided, along with a standard interface for managing daily operations of the QR code center. Integration with other systems is achieved through developed interface services. External systems are integrated with external network systems via an external API gateway using HTTPS, and also with the mobile work platform through integration interfaces.

[0095] Figure 8 This is a schematic diagram of a city-level deployment architecture for applying the enterprise-level QR code management, service, and security method of this invention. (See diagram below.) Figure 8As shown, the QR code center is deployed at the city level, fully considering application scenarios such as existing tobacco security equipment and facilities resources. It embodies the design concept of system and server resource integration and sharing, and is designed with a unified provincial architecture for easy promotion. The city-level deployment opens external network links according to the actual application needs.

[0096] QR code analysis is a data display and statistical analysis of the usage, early warning, and management of QR codes, including four parts: overview, early warning, data analysis, and data reports.

[0097] Taking equipment inspection as an example, let's illustrate a specific QR code application process: (1) Application: Employees of the equipment management department log in to the platform, select the "Equipment Management" template, select "Inspection Record" under "Classification", fill in the equipment list (which can be imported in batches via Excel), and submit the code generation application.

[0098] (2) Approval: The department head receives the approval task in the pending items and approves it.

[0099] (3) Registration and Issuance: The system automatically generates a batch of dynamic codes based on the template and data, and registers them under the category of "Equipment Department - Integrated Management Platform - Equipment Management Unit - Inspection Records" with the tags "Dynamic Code, Internal Use, Internal Form". Employees then download these QR codes in batches, print them out, and paste them onto the corresponding equipment.

[0100] (4) Usage and Data Analysis: Inspection personnel can fill out the inspection form online by scanning the QR code on the device. The data is transmitted back to the platform in real time.

[0101] (5) Analysis: Administrators can see the scanning and inspection status of all devices in the "One-Code Overview" dashboard. Through "Scanning Statistics", the inspection frequency and anomaly rate of each device can be analyzed. The system can issue "Validity Warning" for devices that have not been scanned (not inspected) for a long time.

[0102] (6) Security and maintenance: All QR code data is processed on the intranet. When a device is scrapped, the administrator will execute the "deactivation" operation on the QR code of the device on the platform. After that, anyone who scans the code will be shown "The device is invalid".

[0103] For example, a specific implementation of a security control is as follows: (1) Content review: When a new marketing campaign QR code points to an external H5 page, the system's content review engine will automatically crawl the text and images of the page and compare them with the preset word library and image model. If illegal content is found, the QR code will be blocked from being accessed and an "illegal content warning" will be issued to the administrator.

[0104] (2) API Security: When a third-party system calls the "Batch Code Generation" interface, it must include a valid API Key and digital signature in the request header. The API gateway will verify its identity and permissions and check whether the number of calls it made in the past minute exceeds the threshold (e.g., 100 times). If it does, the service will be rejected.

[0105] Compared with the prior art, the present invention has the following main advantages: (1) Centralized and standardized management of QR codes has been achieved: Through the “one tree + five layers + label” model and full life cycle management, the problem of scattered QR code applications and chaotic management has been completely solved, and a unified QR code asset library for enterprises has been formed.

[0106] (2) Improved operational efficiency and service capabilities: Features such as batch code generation, templated design, and API integration significantly reduced the production and management costs of QR codes, enabling business departments to quickly and conveniently acquire and use QR code capabilities.

[0107] (3) Enhanced data security: Through a full-chain security design from content, transmission, storage to access, a defense-in-depth system has been built, which effectively reduces the risk of data leakage and tampering and meets the high security requirements of enterprise-level applications.

[0108] (4) The value of data assets has been explored: Through a comprehensive code analysis system, scattered scanning data is transformed into valuable business insights, providing accurate data support for marketing decisions, process optimization and resource allocation, and realizing data feedback to business.

[0109] (5) It has good scalability and adaptability: The system adopts a microservice and front-end and back-end separation architecture, and integrates with various systems through API gateway, which can flexibly adapt to changes in business scenarios and future technological developments in different industries.

[0110] This invention can be used in a wide range of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0111] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).

[0112] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0113] Example 2 Further reference Figure 9 As a response to the above Figure 1 The implementation of the method shown in this invention provides an embodiment of an enterprise-level QR code management, service, and security device. This device embodiment is similar to... Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.

[0114] like Figure 9 As shown, the enterprise-level QR code management, service, and security device 60 in this embodiment includes: a construction module 61, a management module 62, a configuration module 63, an analysis module 64, and a security module 65. Wherein: Module 61 is used to build a unified QR code management platform. It adopts a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category and QR code generation code, and combine a tag mechanism to define QR code attributes in multiple dimensions. Management module 62 is used to manage the entire lifecycle of QR codes, from application, approval, registration, issuance, update, deactivation to cancellation; Configuration module 63 is used to configure the generation, beautification, template customization, printing of QR codes, and the interface for providing services to the outside world through the API interface; Analysis module 64 is used to establish a code analysis system to collect, statistically analyze, and visualize QR code usage data, and realize data overview, multi-dimensional early warning, in-depth data analysis, and report generation. Security Module 65 is used to build a QR code security system. Through automatic content review, localized deployment, encryption algorithms, API security reinforcement and access control policies, it ensures that QR code data is secure and controllable throughout the entire process from generation to destruction.

[0115] The beneficial effects of implementing this embodiment are: it achieves centralized and standardized management of QR codes, improves operational efficiency and service capabilities, strengthens data security, taps into the value of data assets, and has good scalability and adaptability.

[0116] Example 3 To address the aforementioned technical problems, embodiments of the present invention also provide a computer device. Please refer to [link / reference needed]. Figure 10 , Figure 10 This is a basic structural block diagram of the computer device in this embodiment.

[0117] The aforementioned computer device 7 includes a memory 71, a processor 72, and a network interface 73 that are interconnected via a system bus. It should be noted that the figure only shows a computer device 7 with components 71, 72, and 73; however, it should be understood that it is not required to implement all the shown components, and more or fewer components may be implemented instead. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0118] The aforementioned computer devices can be desktop computers, laptops, handheld computers, and cloud servers, among other computing devices. These devices can facilitate human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0119] The aforementioned memory 71 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 71 may be an internal storage unit of the aforementioned computer device 7, such as the hard disk or memory of the computer device 7. In other embodiments, the aforementioned memory 71 may also be an external storage device of the aforementioned computer device 7, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 7. Of course, the aforementioned memory 71 may also include both the internal storage unit and the external storage device of the aforementioned computer device 7. In this embodiment, the aforementioned memory 71 is typically used to store the operating system and various application software installed on the aforementioned computer device 7, such as computer-readable instructions for enterprise-level QR code management, service and security methods, etc. In addition, the aforementioned memory 71 can also be used to temporarily store various types of data that have been output or will be output.

[0120] In some embodiments, the processor 72 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 72 is typically used to control the overall operation of the computer device 7. In this embodiment, the processor 72 is used to execute computer-readable instructions stored in the memory 71 or to process data, such as executing the computer-readable instructions for the enterprise-level QR code management, service, and security methods described above.

[0121] The aforementioned network interface 73 may include a wireless network interface or a wired network interface, which is typically used to establish a communication connection between the aforementioned computer device 7 and other electronic devices.

[0122] The beneficial effects of implementing this embodiment are: it achieves centralized and standardized management of QR codes, improves operational efficiency and service capabilities, strengthens data security, taps into the value of data assets, and has good scalability and adaptability.

[0123] Example 4 The present invention also provides another embodiment, namely, a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the enterprise-level QR code management, service and security method described above.

[0124] The beneficial effects of implementing this embodiment are: it achieves centralized and standardized management of QR codes, improves operational efficiency and service capabilities, strengthens data security, taps into the value of data assets, and has good scalability and adaptability.

[0125] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0126] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.

Claims

1. A unified management, service, and security method for QR codes at the enterprise level, characterized in that, Includes the following steps: A unified QR code management platform is constructed, which adopts a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category and QR code generation code, and combine a tag mechanism to define QR code attributes in multiple dimensions. The QR code is managed throughout its entire lifecycle, from application, approval, registration, issuance, update, deactivation to cancellation. Configure the interfaces for generating, beautifying, customizing templates, printing, and providing services to the outside world through API interfaces for the QR codes; Establish a code analysis system to collect, statistically analyze, and visualize the usage data of the QR codes, and realize data overview, multi-dimensional early warning, in-depth data analysis, and report generation; We build a QR code security system to ensure the security and controllability of QR code data from generation to destruction through automatic content review, localized deployment, encryption algorithms, API security reinforcement, and access control policies.

2. The method according to claim 1, characterized in that, The tree topology and five-level hierarchical mechanism are specifically as follows: The organizational relationships are presented in a tree structure. The QR code is positioned based on a three-level standard structure of belonging organization, belonging platform, and belonging unit. Then, it is further subdivided into scenarios through belonging classification, and finally a unique QR code is generated. The labeling mechanism is used to define the technical type, scope of use, and content format attributes of the QR code.

3. The method according to claim 1, characterized in that, In the aforementioned full lifecycle management: The application is initiated through the management interface or API interface, and the QR code is in an inactive state after the application is submitted. The approval process refers to the authorization process for the official use of QR codes. The registration process involves formally entering the approved QR code information into the system, assigning it to a designated level, unit, and label, and configuring its initial state. The distribution supports downloading QR code images individually or in batches, and is compatible with various printing methods; The update refers to modifying the associated form content or permissions without changing the issued QR code pattern.

4. The method according to claim 1, characterized in that, The QR code service includes: Single code creation and batch code generation services, where batch code generation is achieved by importing data from an Excel template; QR code beautification service, supporting template selection, text editing, image upload, and background setting; The QR code template service supports the creation, saving, and reuse of QR code styles and content templates for different scenarios; The QR code printing service supports arranging QR code labels on A4 paper or using compatible label printers. A unified API interface service provides various RESTful interfaces, including code management, data query, and form operations.

5. The method according to claim 1, characterized in that, The code analysis system includes: The dashboard provides a comprehensive overview of metrics, including the number of codes issued, scanning activity, usage, and user activity. The early warning module includes access threshold warning, redirect address validity warning, illegal access warning, and illegal content warning; The data analysis module enables statistical analysis of code issuance volume, scan volume, number of expired codes, and QR code activity by region, time, type, and label statistical criteria. The data reporting module provides code address data reports and dynamic data summary reports, and supports data export to Excel and PDF formats.

6. The method according to claim 1, characterized in that, The automatic content review includes the review of the content accessed via QR code, specifically covering: Image content moderation, identifying advertisements and inappropriate content; Text content moderation, identifying advertisements, text, and their variations; Document content review: analyze and review any prohibited content within the document. Video content review uses a combination of image, text, and voice technologies to filter out illegal content in videos; The audit supports custom blacklists, whitelists, and audit strategy configurations.

7. The method according to claim 1, characterized in that, The encryption algorithm includes at least one of the following: Binary image chaotic encryption: Encryption is achieved by generating a chaotic sequence and performing an XOR operation with the pixel values ​​of the QR code; Multi-level encryption: The QR code information is encrypted multiple times at different levels and decoded using different keys; Double encryption based on Rindael and XOR operation: combining the Rindael algorithm and XOR operation for high-strength encryption.

8. The method according to claim 1, characterized in that, The API security hardening includes: Prohibit the display of insecure resources, and limit page size and API call frequency; Enforce API authentication to prevent unauthorized access; Implement an authorization mechanism to ensure that authenticated users can only access data within their authorized scope; Strengthen server security by enforcing the use of HTTPS and deploying load balancing equipment.

9. The method according to claim 1, characterized in that, The access control policy is based on at least one of the following rules: IP address range rules; IP blacklist / whitelist rules; Access frequency limit rules; Application type rules; Timestamp verification rules.

10. A QR code management, service, and security device for enterprise use, characterized in that, include: The module is used to build a unified QR code management platform. It adopts a tree topology structure and a five-layer hierarchical mechanism to uniformly encode and manage QR codes. The five layers include the affiliated organization, affiliated platform, affiliated unit, affiliated category and QR code generation code, and combine a tag mechanism to define QR code attributes in multiple dimensions. The management module is used to manage the QR code throughout its entire lifecycle, from application, approval, registration, issuance, update, deactivation to cancellation. The configuration module is used to configure the generation, beautification, template customization, printing, and API interfaces of the QR code. The analysis module is used to establish a code analysis system to collect, statistically analyze, and visualize the usage data of the QR codes, and realize data overview, multi-dimensional early warning, in-depth data analysis, and report generation. The security module is used to build a QR code security system. Through automatic content review, localized deployment, encryption algorithms, API security hardening, and access control policies, it ensures that QR code data is secure and controllable throughout the entire process from generation to destruction.