A blockchain-based electronic archive full-life-cycle security management system and method

By constructing a distributed storage system and hierarchical access control model using blockchain technology, and combining smart contracts and encryption algorithms, the problems of data tampering, difficulty in tracing, coarse permissions, and insufficient security in electronic records management are solved, achieving secure management and efficient compliance verification throughout the entire lifecycle.

CN122365577APending Publication Date: 2026-07-10FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID
Filing Date
2026-04-16
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Traditional electronic records management suffers from problems such as easy data tampering, difficulty in tracing operations, coarse access control, insufficient data transmission and storage security, lack of automated compliance verification mechanisms, and low management efficiency.

Method used

A distributed storage system is built using blockchain technology to generate a unique blockchain identifier, establish a hierarchical permission management model, and combine smart contracts to achieve automated verification and traceability of operational behaviors. Data security is ensured through consensus mechanisms and encryption algorithms.

Benefits of technology

It achieves tamper-proof, traceable, and fine-grained access control throughout the entire lifecycle of electronic records, improving the security, compliance, and efficiency of management, and solving the technical drawbacks of traditional management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122365577A_ABST
    Figure CN122365577A_ABST
Patent Text Reader

Abstract

This invention provides a blockchain-based electronic archives lifecycle security management system and method. It collects business and operational data from each stage of the electronic archives' lifecycle, extracting archive characteristic information and operational behavior characteristics; generates unique blockchain identifiers for electronic archives and completes on-chain notarization, constructing a blockchain distributed storage system; establishes a hierarchical permission management model based on blockchain node attributes to achieve on-chain permission control for each participant; records and traces operational behaviors throughout the electronic archives' lifecycle in real time, and uses smart contracts to automate the verification and compliance determination of operational behaviors; ensures the immutability of archive data and operation records through a blockchain consensus mechanism, and achieves secure transmission and storage of archive data through encryption algorithms. Using the solution of this application, secure, traceable, and immutable management of electronic archives throughout their lifecycle can be achieved, effectively improving the security, compliance, and reliability of electronic archives management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of blockchain technology and electronic records management technology, specifically to a blockchain-based electronic records full lifecycle security management system and method. Background Technology

[0002] As an important carrier of information storage in the digital age, the secure management of electronic records throughout their entire lifecycle is a core requirement in the field of archival management. With the deepening of digital transformation, the number of electronic records has exploded, and their management stages cover multiple links such as acquisition, filing, storage, borrowing, modification, and destruction. The requirements for security control and data traceability at each link are constantly increasing.

[0003] Traditional electronic record management often employs a centralized storage and management architecture, which has several technical drawbacks: First, under a centralized storage model, electronic record data and operation records are easily tampered with or deleted, and there are no effective means of data recovery after loss, making it difficult to guarantee the integrity and authenticity of the records. Second, traditional access control often uses a single account password model, with coarse-grained access control, which easily leads to problems such as unauthorized operations and abuse of permissions, and cannot achieve fine-grained access control based on the record's security classification. Third, operation records of electronic records are mostly stored on centralized servers, making traceability difficult, and it is difficult to identify the responsible party when problems such as record leaks or violations occur. Fourth, existing security protections mostly use a single encryption method, and the transmission and storage of record data are at risk of leakage, and there is a lack of automated operation compliance verification mechanisms, requiring manual intervention for review, resulting in low management efficiency.

[0004] Blockchain technology, with its characteristics of immutability, distributed storage, traceability, and automated smart contract execution, offers a novel technological approach to the secure management of electronic records. By deeply integrating blockchain technology with the entire lifecycle management of electronic records, many drawbacks of traditional centralized management can be addressed, enabling secure storage of archival data, full traceability of operational activities, and fine-grained control over permissions. Therefore, how to build a complete secure management system for the entire lifecycle of electronic records based on blockchain technology has become a pressing technical challenge for the industry. Summary of the Invention

[0005] This invention provides a blockchain-based electronic archives full lifecycle security management system and method, which can realize the immutability, traceability, and fine-grained access control of electronic archives throughout their entire lifecycle, thereby improving the security, compliance, and management efficiency of electronic archives management.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solution:

[0007] Firstly, this application provides a blockchain-based method for the secure management of the entire lifecycle of electronic records, used to securely manage the entire lifecycle of electronic records, including the following steps:

[0008] Collect business and operational data at each stage of the entire lifecycle of electronic records, and extract archival characteristic information and operational behavior characteristics of electronic records;

[0009] Generate a unique blockchain identifier for electronic records and complete on-chain evidence storage to build a distributed storage system for electronic records based on blockchain.

[0010] A hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic records management.

[0011] Real-time on-chain recording and traceability of all operations throughout the lifecycle of electronic records; combined with smart contracts to achieve automated verification and compliance determination of operations.

[0012] By leveraging the blockchain consensus mechanism to ensure the immutability of electronic archive data and operation records, and combining this with encryption algorithms to achieve secure transmission and storage of electronic archive data, the secure management of electronic archives throughout their entire lifecycle is achieved.

[0013] Preferably, collecting business and operational data from all stages of the electronic archive's lifecycle, and extracting archival characteristic information and operational behavior characteristics of the electronic archive, specifically includes:

[0014] The business data consists of the content and metadata of electronic records at each stage of collection, filing, storage, borrowing, modification and destruction, as well as the operation data consisting of the operator, operation time, operation type and operation terminal.

[0015] The document extracts archival subject, format, security classification, and characteristics of the unit that created the document from business data, and determines the archival characteristic information of the electronic archives through each characteristic dimension.

[0016] The operation data is filtered to identify operation frequency, operation permission matching degree, and operation duration as key features. These features are then used to determine the operational behavior characteristics of electronic records.

[0017] Preferably, generating a unique blockchain identifier for electronic records and completing on-chain notarization to construct a blockchain-based distributed storage system for electronic records specifically includes:

[0018] A hash encryption algorithm is used to perform hash operations on the archival feature information of electronic archives, and combined with timestamps and archive security levels to generate a unique blockchain identifier for electronic archives;

[0019] The blockchain identifier and archive metadata are uploaded to the blockchain for evidence storage. The original business data of the electronic archives are processed into blocks and then stored in the distributed storage nodes of the blockchain.

[0020] Establish a mapping relationship between blockchain identifiers and distributed storage node addresses, and store this mapping relationship on the blockchain to form a blockchain distributed storage system for electronic archives.

[0021] Preferably, a hierarchical permission management model is built based on the attribute types of blockchain nodes, which assigns corresponding on-chain operation permissions to each participant in electronic record management, specifically including:

[0022] Blockchain nodes are divided into four attribute types: management nodes, operation nodes, audit nodes, and query nodes, which correspond to file management administrators, file operation specialists, file auditors, and file query personnel, respectively.

[0023] Configure basic operation permissions for blockchain nodes of various attribute types, and build a fine-grained hierarchical permission management model based on the confidentiality level of electronic archives;

[0024] A unique on-chain digital certificate is generated for each participant in electronic records management. The digital certificate is used to bind the participant to the blockchain node, enabling the allocation, issuance and revocation of on-chain operation permissions.

[0025] Preferably, real-time on-chain recording and traceability of all operations performed on electronic records throughout their entire lifecycle, combined with smart contracts to automate the verification and compliance assessment of these operations, specifically includes:

[0026] Real-time collection of operational data on electronic record operations, generation of standardized operation records and uploading to the blockchain for evidence storage, forming a traceable on-chain ledger of operational behavior;

[0027] Deploy smart contracts with pre-defined operational compliance rules in the blockchain and input operational behavior characteristics into the smart contracts;

[0028] The smart contract automatically verifies the operation behavior to determine whether it complies with the preset compliance rules. If it complies with the rules, the operation is allowed to be executed. If it does not comply with the rules, the smart contract's warning and operation interception mechanism is triggered.

[0029] Preferably, the immutability of electronic archive data and operation records is ensured through a blockchain consensus mechanism, and the secure transmission and storage of electronic archive data is achieved by combining encryption algorithms, specifically including:

[0030] The blockchain identifier, mapping relationship, and operation record of electronic archives are synchronized to each node of the blockchain. The blockchain consensus mechanism is used to achieve consistent synchronization of data among nodes and ensure that the data cannot be tampered with.

[0031] Asymmetric encryption algorithm is used to encrypt the transmission process of electronic archive data, and hash encryption algorithm is used to encrypt the stored electronic archive data using fingerprint encryption.

[0032] The core sensitive data of electronic archives are fragmented and encrypted before being stored on blockchain distributed storage nodes. The fragmented data can be spliced ​​and read only through authorized blockchain identifiers.

[0033] Preferably, the blockchain consensus mechanism is a practical Byzantine fault-tolerant consensus mechanism, the asymmetric encryption algorithm is the RSA algorithm, and the hash encryption algorithm is the SHA-256 algorithm.

[0034] Secondly, this application provides a blockchain-based electronic archives lifecycle security management system, which includes an archives security management unit, the archives security management unit comprising:

[0035] The data acquisition and extraction module is used to collect business data and operational data at each stage of the entire lifecycle of electronic archives, and to extract the archive feature information and operational behavior features of electronic archives.

[0036] The on-chain storage module is used to generate a unique blockchain identifier for electronic archives and complete on-chain evidence storage, thereby building a distributed storage system for electronic archives based on blockchain.

[0037] The permission management module is used to build a hierarchical permission management model based on the attribute types of blockchain nodes, and to assign corresponding on-chain operation permissions to each participant in electronic record management.

[0038] The traceability and verification module is used to record and trace the operation behavior of electronic archives in real time on the blockchain, and combine smart contracts to realize the automated verification and compliance judgment of the operation behavior.

[0039] The encrypted consensus module is used to ensure the immutability of electronic archive data and operation records through the blockchain consensus mechanism, and to achieve secure transmission and storage of electronic archive data by combining encryption algorithms.

[0040] Thirdly, this application provides a computer device, which includes a memory and a processor. The memory stores code, and the processor is configured to acquire the code and execute the above-described blockchain-based electronic record full lifecycle security management method.

[0041] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned blockchain-based electronic archive lifecycle security management method.

[0042] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:

[0043] In this embodiment, feature information is extracted by collecting business and operational data from each stage of the electronic archive's lifecycle. A unique blockchain identifier is generated for the electronic archive, and a distributed storage system is constructed. A hierarchical permission management model is built based on blockchain nodes. Smart contracts are used to achieve automated verification and traceability of operational behaviors. The blockchain consensus mechanism and encryption algorithm ensure the immutability and secure transmission and storage of data, thus completing the secure management of the entire lifecycle of electronic archives.

[0044] Therefore, the proposed solution possesses multiple technical advantages: First, it deeply integrates blockchain technology with the full lifecycle management of electronic archives, leveraging the distributed storage characteristics of blockchain to solve the problems of data loss and tampering in traditional centralized storage, and achieving unique identification and precise location of electronic archives across the entire domain through a unique blockchain identifier; Second, a hierarchical permission management model built based on blockchain node attributes, combined with the archive's security level, achieves fine-grained permission control, and completes full lifecycle management of permissions through on-chain digital certificates, effectively preventing unauthorized operations and permission abuse; Third, it achieves automated verification and compliance judgment of operational behaviors through smart contracts, replacing the traditional manual review mode, significantly improving the management efficiency of electronic archives, while the full on-chain evidence storage of operational behaviors enables traceability and accountability; Finally, it adopts a two-layer security protection system of "consensus mechanism + multiple encryption algorithms" to ensure the security of electronic archive data during transmission and storage, and the fragmented encryption of core sensitive data further enhances the data's anti-leakage capability.

[0045] In summary, the solution proposed in this application achieves immutability, traceability, fine-grained access control, and automated compliance verification throughout the entire lifecycle of electronic records. It effectively solves the technical shortcomings of traditional electronic record management, improves the security, compliance, and management efficiency of electronic record management, and can be widely applied to various electronic record management scenarios such as government affairs, finance, and enterprises. Attached Figure Description

[0046] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0047] Figure 1 This is an exemplary flowchart illustrating a blockchain-based electronic record lifecycle security management method according to some embodiments of this application;

[0048] Figure 2 This is a schematic diagram of the structure of a blockchain-based electronic archives lifecycle security management system according to some embodiments of this application;

[0049] Figure 3This is a schematic diagram of the structure of a computer device for implementing the method of this application, according to some embodiments of this application. Detailed Implementation

[0050] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0051] The present invention will be further described in detail below with reference to the accompanying drawings.

[0052] Reference Figure 1 Firstly, this application provides a blockchain-based method for secure management of the entire lifecycle of electronic records, used to manage the security of electronic records throughout their entire lifecycle, including the following steps:

[0053] Collect business and operational data at each stage of the entire lifecycle of electronic records, and extract archival characteristic information and operational behavior characteristics of electronic records;

[0054] Generate a unique blockchain identifier for electronic records and complete on-chain evidence storage to build a distributed storage system for electronic records based on blockchain.

[0055] A hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic records management.

[0056] Real-time on-chain recording and traceability of all operations throughout the lifecycle of electronic records; combined with smart contracts to achieve automated verification and compliance determination of operations.

[0057] By leveraging the blockchain consensus mechanism to ensure the immutability of electronic archive data and operation records, and combining this with encryption algorithms to achieve secure transmission and storage of electronic archive data, the secure management of electronic archives throughout their entire lifecycle is achieved.

[0058] In practice, the process begins by collecting business and operational data from each stage of the electronic archive's lifecycle—collection, filing, storage, borrowing, modification, and destruction—to extract archival characteristics and operational behavior features. Next, a unique blockchain identifier is generated for each electronic archive and uploaded to the blockchain for evidence storage. Simultaneously, a distributed storage system for electronic archives based on blockchain is constructed. Then, a hierarchical permission management model is built based on the attribute types of blockchain nodes, assigning corresponding on-chain operation permissions to each participant in electronic archive management. Subsequently, real-time on-chain recording and traceability of operational behaviors throughout the entire electronic archive lifecycle are performed, and smart contracts are used to automatically verify and determine compliance. Finally, the blockchain consensus mechanism ensures the immutability of electronic archive data and operation records, and encryption algorithms enable secure transmission and storage of electronic archive data, thereby completing the secure management of the entire electronic archive lifecycle.

[0059] This invention constructs a blockchain-based full lifecycle security management system for electronic records from a holistic perspective. It solves the technical drawbacks of traditional centralized electronic record management, such as easy data tampering, difficulty in tracing operations, coarse access control, and security risks in data transmission and storage. It realizes integrated security management of electronic records throughout their entire lifecycle, comprehensively improves the security, compliance, and traceability of electronic record management, and provides a complete technical solution for various electronic record management scenarios.

[0060] In some embodiments, collecting business data and operational data at each stage of the electronic archive's entire lifecycle, and extracting archival characteristic information and operational behavior characteristics of the electronic archive, specifically includes:

[0061] The business data consists of the content and metadata of electronic records at each stage of collection, filing, storage, borrowing, modification and destruction, as well as the operation data consisting of the operator, operation time, operation type and operation terminal.

[0062] The document extracts archival subject, format, security classification, and characteristics of the unit that created the document from business data, and determines the archival characteristic information of the electronic archives through each characteristic dimension.

[0063] The operation data is filtered to identify operation frequency, operation permission matching degree, and operation duration as key features. These features are then used to determine the operational behavior characteristics of electronic records.

[0064] In practice, the process involves first acquiring business data consisting of archive content and metadata at each stage of the electronic archive's lifecycle, as well as operational data consisting of the operator, operation time, operation type, and operation terminal. Then, four characteristic dimensions—archive theme, archive format, archive security classification, and archive generating unit—are selected from the business data to determine the archive characteristic information of the electronic archive. Finally, three characteristic dimensions—operation frequency, operation permission matching degree, and operation duration—are selected from the operational data to determine the operational behavior characteristics of the electronic archive.

[0065] This invention enables accurate and comprehensive data collection throughout the entire lifecycle of electronic archives. By defining specific feature dimensions, it achieves targeted extraction of archival feature information and operational behavior characteristics, effectively eliminating invalid data interference. This provides a real, reliable, and effective data foundation for subsequent steps such as blockchain identifier generation and smart contract compliance verification, ensuring the smooth implementation of subsequent technical steps.

[0066] In some embodiments, generating a unique blockchain identifier for electronic records and completing on-chain notarization to construct a blockchain-based distributed storage system for electronic records specifically includes:

[0067] A hash encryption algorithm is used to perform hash operations on the archival feature information of electronic archives, and combined with timestamps and archive security levels to generate a unique blockchain identifier for electronic archives;

[0068] The blockchain identifier and archive metadata are uploaded to the blockchain for evidence storage. The original business data of the electronic archives are processed into blocks and then stored in the distributed storage nodes of the blockchain.

[0069] Establish a mapping relationship between blockchain identifiers and distributed storage node addresses, and store this mapping relationship on the blockchain to form a blockchain distributed storage system for electronic archives.

[0070] In practice, a hash encryption algorithm is first used to perform hash operations on the archival feature information of the electronic archives, and combined with the timestamp and the archive's security classification, a unique blockchain identifier for the electronic archives is generated. Then, the blockchain identifier and the archive metadata are uploaded to the blockchain for evidence storage. At the same time, the original business data of the electronic archives are processed into blocks and stored in the distributed storage nodes of the blockchain. Finally, a mapping relationship between the blockchain identifier and the address of the distributed storage node is established, and this mapping relationship is stored on the blockchain, forming a blockchain distributed storage system for electronic archives.

[0071] This invention generates a blockchain identifier through hash encryption combined with timestamps and document security levels, ensuring global uniqueness and providing a unique identity for electronic documents, preventing duplicate or forged identifiers. Storing the identifier and metadata on the blockchain ensures the immutability of core information, while storing the original data in blocks on distributed nodes solves the problems of data loss and single points of failure in traditional centralized storage. The mapping relationship on the blockchain enables precise association between the blockchain identifier and the original data, ensuring rapid location and efficient retrieval of electronic documents.

[0072] In some embodiments, a hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic record management. Specifically, this includes:

[0073] Blockchain nodes are divided into four attribute types: management nodes, operation nodes, audit nodes, and query nodes, which correspond to file management administrators, file operation specialists, file auditors, and file query personnel, respectively.

[0074] Configure basic operation permissions for blockchain nodes of various attribute types, and build a fine-grained hierarchical permission management model based on the confidentiality level of electronic archives;

[0075] A unique on-chain digital certificate is generated for each participant in electronic records management. The digital certificate is used to bind the participant to the blockchain node, enabling the allocation, issuance and revocation of on-chain operation permissions.

[0076] In practice, blockchain nodes are first divided into four attribute types: management nodes, operation nodes, audit nodes, and query nodes, corresponding to four types of participants: file management administrators, file operation specialists, file auditors, and file query personnel, respectively. Then, basic operation permissions are configured for each attribute type of blockchain node. At the same time, a fine-grained hierarchical permission management model is built based on the file security level of electronic files. Finally, a unique on-chain digital certificate is generated for each participant in electronic file management. The digital certificate is used to bind the participant to the blockchain node, realizing the allocation, issuance, and revocation of on-chain operation permissions.

[0077] This invention establishes a two-tiered hierarchical permission management model based on blockchain node attributes and file security levels. This model enables fine-grained permission control for electronic file management and adapts to the permission management needs of files with different security levels. The unique on-chain digital certificate enables precise binding between participants and nodes, ensuring the uniqueness and validity of permission allocation and avoiding problems such as unauthorized operations and permission abuse. At the same time, it enables traceable management of the entire lifecycle of permissions, facilitating the auditing and adjustment of permission control.

[0078] In some embodiments, real-time on-chain recording and traceability of operational activities throughout the entire lifecycle of electronic records, combined with smart contracts to automate the verification and compliance determination of operational activities, specifically includes:

[0079] Real-time collection of operational data on electronic record operations, generation of standardized operation records and uploading to the blockchain for evidence storage, forming a traceable on-chain ledger of operational behavior;

[0080] Deploy smart contracts with pre-defined operational compliance rules in the blockchain and input operational behavior characteristics into the smart contracts;

[0081] The smart contract automatically verifies the operation behavior to determine whether it complies with the preset compliance rules. If it complies with the rules, the operation is allowed to be executed. If it does not comply with the rules, the smart contract's warning and operation interception mechanism is triggered.

[0082] In practice, the operation data of electronic file operation behavior is first collected in real time, standardized operation records are generated and uploaded to the blockchain for evidence storage, forming a traceable on-chain ledger of operation behavior; then, smart contracts with preset operation compliance rules are deployed in the blockchain, and the operation behavior characteristics are input into the smart contracts; finally, the operation behavior is automatically verified by the smart contracts to determine whether the operation behavior complies with the preset compliance rules. If it complies with the rules, the operation is allowed to be executed; if it does not comply with the rules, the smart contract's warning and operation interception mechanism is triggered.

[0083] The real-time on-chain storage of operation records enables full traceability of electronic file operation behavior, facilitating subsequent responsibility positioning and audit verification; the automated compliance verification of smart contracts replaces the traditional manual review mode, significantly improving the review efficiency of electronic file operation and reducing manual management costs; the real-time early warning and operation interception mechanism can promptly control illegal operations, ensuring the compliance of electronic file management from the operation stage and avoiding risks such as file data leakage and tampering caused by illegal operations.

[0084] In some embodiments, the immutability of electronic archive data and operation records is ensured through a blockchain consensus mechanism, and the secure transmission and storage of electronic archive data is achieved by combining encryption algorithms, specifically including:

[0085] The blockchain identifier, mapping relationship, and operation record of electronic archives are synchronized to each node of the blockchain. The blockchain consensus mechanism is used to achieve consistent synchronization of data among nodes and ensure that the data cannot be tampered with.

[0086] Asymmetric encryption algorithm is used to encrypt the transmission process of electronic archive data, and hash encryption algorithm is used to encrypt the stored electronic archive data using fingerprint encryption.

[0087] The core sensitive data of electronic archives are fragmented and encrypted before being stored on blockchain distributed storage nodes. The fragmented data can be spliced ​​and read only through authorized blockchain identifiers.

[0088] In practice, the blockchain identifier, mapping relationship, and operation records of the electronic archives are first synchronized to each node of the blockchain. The blockchain consensus mechanism is used to achieve data consistency and synchronization among nodes, ensuring that the data is tamper-proof. Then, an asymmetric encryption algorithm is used to encrypt the transmission process of the electronic archive data, and a hash encryption algorithm is used to perform fingerprint encryption on the stored electronic archive data. Finally, the core sensitive data of the electronic archives is fragmented, encrypted, and stored in the distributed storage nodes of the blockchain. The fragmented data can be spliced ​​and read only through the authorized blockchain identifier.

[0089] The blockchain consensus mechanism ensures the immutability of electronic archive data and operation records from the ground up through data consistency synchronization among nodes, thereby enhancing the authenticity and integrity of the data. The combined application of asymmetric encryption and hash encryption provides dual security protection for the transmission and storage of electronic archive data, effectively reducing the risk of data leakage. The fragmented encrypted storage of core sensitive data further enhances the data protection level. Even if some fragmented data is obtained, it is impossible to complete the splicing and reading of the complete data, ensuring the security of core sensitive data.

[0090] In some embodiments, the blockchain consensus mechanism is a practical Byzantine fault-tolerant consensus mechanism, the asymmetric encryption algorithm is the RSA algorithm, and the hash encryption algorithm is the SHA-256 algorithm.

[0091] It should be noted that applying the Practical Byzantine Fault-Tolerant Consensus Mechanism to the data consistency synchronization stage of blockchain nodes, the RSA algorithm to the transmission encryption stage of electronic archive data, and the SHA-256 algorithm to the storage fingerprint encryption stage of electronic archive data, ensures the overall technical solution has clear feasibility and avoids implementation difficulties caused by ambiguity in algorithms and mechanisms. The Practical Byzantine Fault-Tolerant Consensus Mechanism is suitable for multi-node collaborative management scenarios in consortium blockchains, featuring high fault tolerance and fast consensus speed, thus improving node data synchronization efficiency. Both the RSA and SHA-256 algorithms are mature encryption algorithms that can ensure encryption security while also considering the efficiency of data encryption and decryption, achieving a balance between security and efficiency.

[0092] Reference Figure 2 Secondly, this application provides a blockchain-based electronic archives lifecycle security management system, which includes an archives security management unit, the archives security management unit comprising:

[0093] The data acquisition and extraction module is used to collect business data and operational data at each stage of the entire lifecycle of electronic archives, and to extract the archive feature information and operational behavior features of electronic archives.

[0094] The on-chain storage module is used to generate a unique blockchain identifier for electronic archives and complete on-chain evidence storage, thereby building a distributed storage system for electronic archives based on blockchain.

[0095] The permission management module is used to build a hierarchical permission management model based on the attribute types of blockchain nodes, and to assign corresponding on-chain operation permissions to each participant in electronic record management.

[0096] The traceability and verification module is used to record and trace the operation behavior of electronic archives in real time on the blockchain, and combine smart contracts to realize the automated verification and compliance judgment of the operation behavior.

[0097] The encrypted consensus module is used to ensure the immutability of electronic archive data and operation records through the blockchain consensus mechanism, and to achieve secure transmission and storage of electronic archive data by combining encryption algorithms.

[0098] It should be noted that the document security management unit is constructed, which includes a data collection and extraction module, an on-chain storage module, an access control module, a traceability and verification module, and an encryption consensus module. These modules work together. The data collection and extraction module completes the full lifecycle data collection and feature extraction. The on-chain storage module completes the generation of blockchain identifiers and the construction of a distributed storage system. The access control module completes the construction of a hierarchical access control model and the allocation of on-chain permissions. The traceability and verification module completes the on-chain traceability of operational behavior and the automated verification of smart contracts. The encryption consensus module completes the implementation of the blockchain consensus mechanism and the application of encryption algorithms. Through the functional connection and data interaction between the modules, the full lifecycle security management of electronic documents at the system level is achieved.

[0099] This invention modularizes and implements the aforementioned method and solution, with clear functional boundaries and responsibilities for each module. It also achieves efficient collaboration and data interoperability between modules, improving the feasibility and maintainability of the technical solution. The modular system architecture can adapt to the personalized needs of different electronic record management scenarios, and modules can be flexibly adjusted and expanded according to actual needs, facilitating system upgrades and iterations. At the same time, it provides a clear architectural reference for the development of actual electronic record management systems.

[0100] Reference Figure 3Thirdly, this application provides a computer device including a memory and a processor. The memory stores code, and the processor is configured to acquire the code and execute the aforementioned blockchain-based electronic archive lifecycle security management method. The computer device provides the hardware execution platform for the aforementioned blockchain-based electronic archive lifecycle security management method. Utilizing the high-speed computing, large-capacity storage, and network communication capabilities of the computer device, it ensures that the management method can efficiently process large-scale electronic archive data, adapting to the management needs of massive electronic archives in practical applications. Simultaneously, relying on a general computer device architecture, the technical solution can be quickly implemented on existing hardware, reducing the implementation cost.

[0101] In some embodiments, the blockchain-based electronic record full lifecycle security management method described above can be implemented by a computer device, which includes at least one processor, a communication bus, a memory, and at least one communication interface.

[0102] A processor can be a general-purpose central processing unit (CPU) or an application-specific integrated circuit (ASIC).

[0103] A communication bus can be used to transmit information between the aforementioned components.

[0104] The memory can be read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, universal optical discs, Blu-ray discs, etc.), magnetic disks or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited to these. The memory can exist independently and be connected to the processor via a communication bus. The memory can also be integrated with the processor.

[0105] The memory stores the program code that executes the solution of this application, and its execution is controlled by the processor. The processor executes the program code stored in the memory. The program code may include one or more software modules. The blockchain-based electronic archive full lifecycle security management method in the above embodiments can be implemented by the processor and one or more software modules in the program code in the memory.

[0106] A communication interface is a device that uses any transceiver or similar device to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.

[0107] In a specific implementation, as one example, a computer device may include multiple processors, each of which may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).

[0108] The aforementioned computer device can be a general-purpose computer device or a special-purpose computer device. In specific implementations, the computer device can be a desktop computer, a portable computer, a network server, a handheld digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, a communication device, or an embedded device. This application does not limit the type of computer device.

[0109] Fourthly, this application provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the aforementioned blockchain-based electronic record lifecycle security management method. The computer-readable storage medium provides a portable and reusable program storage carrier for the aforementioned management method, realizing the programmatic encapsulation of the management method and enabling it to be stored and transmitted independently of specific computer devices. Based on this storage medium, the management method can be quickly deployed to different computer devices, improving the scalability and applicability of the technical solution and facilitating its rapid implementation on various electronic record management hardware platforms.

[0110] To better understand the technical solution of this application, the technical solution of this application will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0111] refer to Figure 1The figure is an exemplary flowchart of a blockchain-based electronic archives lifecycle security management method according to some embodiments of this application. The method mainly includes the following steps:

[0112] In step 101, business data and operational data of each stage of the electronic archive's entire lifecycle are collected, and archival characteristic information and operational behavior characteristics of the electronic archive are extracted.

[0113] It should be noted that the reference Figure 2 As shown in the figure, this diagram is a flowchart of the full lifecycle management of electronic records in some embodiments of this application. The full lifecycle of electronic records covers six core stages: collection stage, filing stage, storage stage, borrowing stage, modification stage, and destruction stage. Each stage forms a closed-loop management. The method of this application collects business and operational data from all dimensions of the six stages to achieve seamless security control of each stage.

[0114] The business data in this application refers to the data related to the electronic archives themselves generated at each stage of the entire lifecycle, including the original content of the archives and archive metadata (such as archive name, creation time, creating unit, security classification, etc.); the operational data refers to the behavioral data generated when operators perform operations on the electronic archives at each stage, including operator identity information, operation time, operation type (such as upload, borrow, modify, delete), operation terminal MAC address, IP address, etc.; the archive feature information refers to the set of features that can characterize the core attributes of the electronic archives and is the core basis for generating a unique blockchain identifier; the operational behavior features refer to the set of features that can characterize the operational behavior patterns of operators and are an important indicator for smart contracts to verify operational compliance.

[0115] In practice, data acquisition is achieved through data acquisition terminals deployed in the archive management system. Real-time acquisition can be adopted, and business and operational data at each stage of the entire lifecycle can be obtained through interfaces connecting to the business modules and operation log modules of the archive management system. During feature extraction, four core feature dimensions are selected from the business data: archive theme, archive format, archive security level, and archive generating unit. Each dimension is quantified and encoded and combined into a feature vector, which serves as the archive feature information. Three core feature dimensions are selected from the operational data: operation frequency, operation permission matching degree, and operation duration. These are also quantified and encoded and combined into a feature vector, which serves as the operation behavior features.

[0116] In step 102, a unique blockchain identifier is generated for the electronic archive and the evidence is stored on the blockchain, thus constructing a distributed storage system for electronic archives based on blockchain.

[0117] This application adopts a consortium blockchain architecture as the blockchain infrastructure for electronic record management. The consortium blockchain nodes include management nodes, operation nodes, audit nodes, query nodes, and storage nodes. Each node performs its own function to achieve distributed storage and collaborative management of data. The unique blockchain identifier is a globally unique identity identifier for electronic records within the consortium blockchain, possessing the characteristics of being uncopyable and tamper-proof.

[0118] In practice, the SHA-256 hash encryption algorithm is first used to hash the archive feature information extracted in step 101 to obtain a fixed-length hash value. This hash value is then concatenated with the current timestamp and the archive security classification code to generate a unique blockchain identifier for the electronic archive. Subsequently, the blockchain identifier and archive metadata are uploaded to each node of the consortium blockchain for on-chain storage to ensure that the identifier and metadata are immutable. For the original business data of the electronic archive, due to the large amount of data, block processing technology is used to divide it into several data fragments and store them in the distributed storage nodes of the consortium blockchain. Finally, a mapping relationship between the blockchain identifier and the storage address of each data fragment in the distributed storage nodes is established, and this mapping relationship is stored on the blockchain to form a distributed blockchain storage system. Subsequently, the original data of the electronic archive can be quickly located and read through the blockchain identifier.

[0119] In step 103, a hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic record management.

[0120] In practical implementation, the consortium blockchain nodes are first divided into four attribute types: management nodes, operation nodes, audit nodes, and query nodes, corresponding to the four types of participants in electronic record management: record administrators, record operation specialists, record auditors, and record query personnel. Basic operation permissions are configured for each attribute type of node. For example, management nodes have full access to records, permission allocation, and node management permissions; operation nodes have permissions for record creation, modification, and borrowing approval; audit nodes have permissions for querying and auditing all operation records; and query nodes only have authorized record query permissions within their scope. Secondly, based on electronic records... A classification permission sub-model is built based on the classification level (e.g., public, internal, secret, confidential, top secret). Different operation permissions are set for electronic files of different classification levels. For example, top secret files can only be operated by the management node, and confidential files can only be operated by the management node and the operation node. Finally, a unique on-chain digital certificate is generated for each participant. The certificate contains the participant's identity information, the type of blockchain node bound to it, the scope of permissions, the certificate validity period, and other information. The binding of participants to blockchain nodes is completed through digital certificates, realizing the allocation, issuance, and revocation of on-chain operation permissions. The invalidation and renewal of digital certificates must be recorded on the chain to ensure the traceability of permission management.

[0121] In step 104, the operational behavior of the electronic archive throughout its entire lifecycle is recorded on the blockchain in real time and traced back to its source. Combined with smart contracts, the operational behavior is automatically verified and its compliance is determined.

[0122] The smart contract in this application is a programmable automated contract deployed in a consortium blockchain. It pre-sets compliance rules for electronic file operations, such as "top secret files are prohibited from being accessed by external terminals", "file borrowing requires approval from the operation node", and "file modifications require the retention of modification records and version comparisons". The smart contract has the characteristics of automated execution and immutability, and can complete the compliance verification of operation behavior without human intervention.

[0123] In practice, the process begins with the following steps: First, data acquisition terminals collect operational data from each stage of the electronic record-keeping process in real time. Standardized operation records are generated according to a preset format, including information such as the operator, operation time, operation type, operation object, and operation result. These records are then uploaded to the consortium blockchain for on-chain evidence storage, forming an on-chain ledger of operational behavior. This ledger supports precise traceability by operator, operation time, and operation object. Second, a smart contract with preset operational compliance rules is deployed on the consortium blockchain, and the operational behavior features extracted in step 101 are input into the smart contract. Finally, the smart contract automatically verifies the operational behavior according to the preset rules. If the operational behavior complies with the compliance rules, it is automatically allowed to execute, and the execution result is recorded on the blockchain. If the operational behavior does not comply with the compliance rules, the smart contract's warning and operation interception mechanism is immediately triggered to intercept the current operation. At the same time, a warning message is sent to the management node, and details of the violation are recorded, enabling real-time control of violations.

[0124] In step 105, the blockchain consensus mechanism ensures the immutability of electronic archive data and operation records, and the encryption algorithm enables the secure transmission and storage of electronic archive data, thus completing the secure management of the entire lifecycle of electronic archives.

[0125] This application adopts the Practical Byzantine Fault Tolerance (PBFT) consensus mechanism as the consensus mechanism of the consortium blockchain. This mechanism has the characteristics of high fault tolerance and fast consensus speed, and is suitable for multi-node collaborative management scenarios in consortium blockchains. It adopts a multi-encryption method combining the RSA asymmetric encryption algorithm and the SHA-256 hash encryption algorithm to achieve secure transmission and storage of electronic archive data.

[0126] In practice, the core data of the electronic archives, including blockchain identifiers, mapping relationships, operation records, and permission configurations, are first synchronized to all nodes of the consortium blockchain. The PBFT consensus mechanism is used to verify the consistency of data across nodes. Data is only written to the blockchain when more than two-thirds of the nodes confirm data consistency, ensuring the immutability of electronic archive data and operation records. Secondly, during data transmission, the RSA asymmetric encryption algorithm is used to generate public and private keys. The public key is used to encrypt the transmitted electronic archive data, while the private key, held only by authorized nodes, is used to decrypt the encrypted data, ensuring security during data transmission. During data storage, the SHA-256 hash encryption algorithm is used to perform fingerprint encryption on the stored electronic archive data, generating a data fingerprint. If the data is tampered with, the data fingerprint will change, allowing for rapid detection of data tampering. For core and sensitive electronic archive data, a fragmentation encryption technology is used to divide it into several fragments. Each fragment is independently encrypted and stored on different distributed storage nodes. The data from each fragment can be concatenated and read using only an authorized blockchain identifier, further enhancing data leakage prevention capabilities.

[0127] Through steps 101 to 105 above, secure management of electronic records throughout their entire lifecycle, from collection to destruction, is achieved, ensuring the integrity, authenticity, and security of electronic record data, enabling full traceability and accountability of operational actions, and improving the compliance and efficiency of electronic record management.

[0128] refer to Figure 2 The figure is a schematic diagram of the structure of an archive security management unit according to some embodiments of this application. The archive security management unit includes an acquisition and extraction module, an on-chain storage module, an access control module, a traceability and verification module, and an encryption consensus module. The functions of each module are as follows:

[0129] Data Acquisition and Extraction Module: The core functions are data acquisition and feature extraction. It connects to the document management system through an interface to collect business data and operational data from all stages of the electronic document lifecycle in real time, and completes the extraction and quantification encoding of document feature information and operational behavior features.

[0130] On-chain storage module: Its core functions are blockchain identifier generation, on-chain evidence storage and distributed storage system construction. It is responsible for generating a unique blockchain identifier for electronic archives, storing the identifier and metadata on the chain, storing the original data in blocks to distributed nodes, and establishing mapping relationships on the chain.

[0131] The permission management module's core functions are building a hierarchical permission management model and allocating on-chain permissions. It is responsible for classifying blockchain node attribute types, configuring basic operation permissions and security level permissions, generating on-chain digital certificates for participants, and realizing the allocation, issuance, revocation, and verification of permissions.

[0132] Source tracing and verification module: Its core functions are on-chain source tracing of operational behavior and automated verification of smart contracts. It is responsible for collecting operational behavior data and generating on-chain ledgers, deploying smart contracts and completing compliance verification of operational behavior, and triggering early warning and interception mechanisms.

[0133] Encryption Consensus Module: Its core function is to implement data encryption and consensus mechanisms. It is responsible for ensuring data consistency and immutability through the PBFT consensus mechanism, and using RSA and SHA-256 algorithms to encrypt data transmission and storage, and to complete the fragmented encrypted storage of core sensitive data.

[0134] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:

[0135] In this embodiment, feature information is extracted by collecting business and operational data from each stage of the electronic archive's lifecycle. A unique blockchain identifier is generated for the electronic archive, and a distributed storage system is constructed. A hierarchical permission management model is built based on blockchain nodes. Smart contracts are used to achieve automated verification and traceability of operational behaviors. The blockchain consensus mechanism and encryption algorithm ensure the immutability and secure transmission and storage of data, thus completing the secure management of the entire lifecycle of electronic archives.

[0136] Therefore, the proposed solution possesses multiple technical advantages: First, it deeply integrates blockchain technology with the full lifecycle management of electronic archives, leveraging the distributed storage characteristics of blockchain to solve the problems of data loss and tampering in traditional centralized storage, and achieving unique identification and precise location of electronic archives across the entire domain through a unique blockchain identifier; Second, a hierarchical permission management model built based on blockchain node attributes, combined with the archive's security level, achieves fine-grained permission control, and completes full lifecycle management of permissions through on-chain digital certificates, effectively preventing unauthorized operations and permission abuse; Third, it achieves automated verification and compliance judgment of operational behaviors through smart contracts, replacing the traditional manual review mode, significantly improving the management efficiency of electronic archives, while the full on-chain evidence storage of operational behaviors enables traceability and accountability; Finally, it adopts a two-layer security protection system of "consensus mechanism + multiple encryption algorithms" to ensure the security of electronic archive data during transmission and storage, and the fragmented encryption of core sensitive data further enhances the data's anti-leakage capability.

[0137] In summary, the solution proposed in this application achieves immutability, traceability, fine-grained access control, and automated compliance verification throughout the entire lifecycle of electronic records. It effectively solves the technical shortcomings of traditional electronic record management, improves the security, compliance, and management efficiency of electronic record management, and can be widely applied to various electronic record management scenarios such as government affairs, finance, and enterprises.

[0138] The technical solutions provided by the embodiments of the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the embodiments of the present invention. The descriptions of the embodiments above are only for helping to understand the principles of the embodiments of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the embodiments of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A blockchain-based method for secure management of the entire lifecycle of electronic records, used to securely manage the entire lifecycle of electronic records, including acquisition, archiving, storage, borrowing, modification, and destruction, characterized in that... Includes the following steps: Collect business and operational data at each stage of the entire lifecycle of electronic records, and extract archival characteristic information and operational behavior characteristics of electronic records; Generate a unique blockchain identifier for electronic records and complete on-chain evidence storage to build a distributed storage system for electronic records based on blockchain. A hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic records management. Real-time on-chain recording and traceability of all operations throughout the lifecycle of electronic records; combined with smart contracts to achieve automated verification and compliance determination of operations. By leveraging the blockchain consensus mechanism to ensure the immutability of electronic archive data and operation records, and combining this with encryption algorithms to achieve secure transmission and storage of electronic archive data, the secure management of electronic archives throughout their entire lifecycle is achieved.

2. The blockchain-based electronic archives full lifecycle security management method as described in claim 1, characterized in that, Collecting business and operational data from all stages of the electronic archives' lifecycle, and extracting archival characteristic information and operational behavior characteristics of the electronic archives, specifically includes: The business data consists of the content and metadata of electronic records at each stage of collection, filing, storage, borrowing, modification and destruction, as well as the operation data consisting of the operator, operation time, operation type and operation terminal. The document extracts archival subject, format, security classification, and characteristics of the unit that created the document from business data, and determines the archival characteristic information of the electronic archives through each characteristic dimension. The operation data is filtered to identify operation frequency, operation permission matching degree, and operation duration as key features. These features are then used to determine the operational behavior characteristics of electronic records.

3. The blockchain-based electronic archives full lifecycle security management method as described in claim 1, characterized in that, Generating a unique blockchain identifier for electronic records and completing on-chain notarization, and constructing a blockchain-based distributed storage system for electronic records specifically includes: A hash encryption algorithm is used to perform hash operations on the archival feature information of electronic archives, and combined with timestamps and archive security levels to generate a unique blockchain identifier for electronic archives; The blockchain identifier and archive metadata are uploaded to the blockchain for evidence storage. The original business data of the electronic archives are processed into blocks and then stored in the distributed storage nodes of the blockchain. Establish a mapping relationship between blockchain identifiers and distributed storage node addresses, and store this mapping relationship on the blockchain to form a blockchain distributed storage system for electronic archives.

4. The blockchain-based electronic archives full lifecycle security management method as described in claim 1, characterized in that, A hierarchical permission management model is built based on the attribute types of blockchain nodes to assign corresponding on-chain operation permissions to each participant in electronic records management. Specifically, this includes: Blockchain nodes are divided into four attribute types: management nodes, operation nodes, audit nodes, and query nodes, which correspond to file management administrators, file operation specialists, file auditors, and file query personnel, respectively. Configure basic operation permissions for blockchain nodes of various attribute types, and build a fine-grained hierarchical permission management model based on the confidentiality level of electronic archives; A unique on-chain digital certificate is generated for each participant in electronic records management. The digital certificate is used to bind the participant to the blockchain node, enabling the allocation, issuance and revocation of on-chain operation permissions.

5. The blockchain-based electronic archives full lifecycle security management method as described in claim 1, characterized in that, Real-time on-chain recording and traceability of all operations related to electronic records throughout their lifecycle, combined with smart contracts to automate the verification and compliance assessment of these operations, specifically includes: Real-time collection of operational data on electronic record operations, generation of standardized operation records and uploading to the blockchain for evidence storage, forming a traceable on-chain ledger of operational behavior; Deploy smart contracts with pre-defined operational compliance rules in the blockchain and input operational behavior characteristics into the smart contracts; The smart contract automatically verifies the operation behavior to determine whether it complies with the preset compliance rules. If it complies with the rules, the operation is allowed to be executed. If it does not comply with the rules, the smart contract's warning and operation interception mechanism is triggered.

6. The blockchain-based electronic archives full lifecycle security management method as described in claim 1, characterized in that, Ensuring the immutability of electronic archive data and operation records through blockchain consensus mechanisms, and achieving secure transmission and storage of electronic archive data through encryption algorithms, specifically includes: The blockchain identifier, mapping relationship, and operation record of electronic archives are synchronized to each node of the blockchain. The blockchain consensus mechanism is used to achieve consistent synchronization of data among nodes and ensure that the data cannot be tampered with. Asymmetric encryption algorithm is used to encrypt the transmission process of electronic archive data, and hash encryption algorithm is used to encrypt the stored electronic archive data using fingerprint encryption. The core sensitive data of electronic archives are fragmented and encrypted before being stored on blockchain distributed storage nodes. The fragmented data can be spliced ​​and read only through authorized blockchain identifiers.

7. The blockchain-based electronic archives full lifecycle security management method as described in claim 6, characterized in that, The blockchain consensus mechanism is a practical Byzantine fault-tolerant consensus mechanism, the asymmetric encryption algorithm is the RSA algorithm, and the hash encryption algorithm is the SHA-256 algorithm.

8. A blockchain-based electronic archives lifecycle security management system, comprising an archives security management unit, characterized in that, The archive security management unit includes: The data acquisition and extraction module is used to collect business data and operational data at each stage of the entire lifecycle of electronic archives, and to extract the archive feature information and operational behavior features of electronic archives. The on-chain storage module is used to generate a unique blockchain identifier for electronic archives and complete on-chain evidence storage, thereby building a distributed storage system for electronic archives based on blockchain. The permission management module is used to build a hierarchical permission management model based on the attribute types of blockchain nodes, and to assign corresponding on-chain operation permissions to each participant in electronic record management. The traceability and verification module is used to record and trace the operation behavior of electronic archives in real time on the blockchain, and combine smart contracts to realize the automated verification and compliance judgment of the operation behavior. The encrypted consensus module is used to ensure the immutability of electronic archive data and operation records through the blockchain consensus mechanism, and to achieve secure transmission and storage of electronic archive data by combining encryption algorithms.

9. A computer device comprising a memory and a processor, the memory storing code, characterized in that, The processor is configured to acquire the code and execute the blockchain-based electronic record full lifecycle security management method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the blockchain-based electronic archive full lifecycle security management method as described in any one of claims 1 to 7.