A full-cycle safety processing method and system for railway industry drawing documents
By adopting a transparent encryption/decryption engine, dynamic watermarking, and hierarchical key management in the railway industry's drawing and document management, a full lifecycle security management system was established, solving the problem of drawing and document security management and achieving closed-loop security management and efficient collaboration throughout the entire lifecycle.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA RAILWAY BAOJI BRIDGE GROUP CO LTD
- Filing Date
- 2026-03-20
- Publication Date
- 2026-07-31
AI Technical Summary
The management of drawings and documents in the railway industry suffers from problems such as scattered storage, lack of access control, high risk of leakage during transmission, inability to audit and trace usage behavior, and conflict between encryption and collaboration efficiency, making it difficult to balance information security and work efficiency.
A transparent encryption and decryption engine is used to encrypt all drawings and documents, embed dynamic watermarks, establish a hierarchical key management system, transmit drawings through a secure transmission channel, implement fine-grained access control and behavior auditing, and build a full lifecycle security management system.
It achieves closed-loop security management of drawings and documents throughout their entire lifecycle, from generation to destruction, enhances leakage prevention capabilities, balances information security and work efficiency, adapts to the multi-stage collaboration characteristics of the railway industry, and reduces implementation costs.
Smart Images

Figure CN122490568A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of industrial information security and railway engineering data management technology, and in particular to a method and system for full-lifecycle security processing of drawings and documents in the railway industry. Background Technology
[0002] As a vital national infrastructure sector, the railway industry generates a wealth of core engineering data and technical secrets in its digital drawings and documents throughout the entire process of design, manufacturing, and operation. These are core assets for railway engineering construction and equipment manufacturing, and thus have extremely high industry requirements for information security and confidentiality management. Therefore, the full-process security control of drawings and documents has become a key link in the digital development of the railway industry.
[0003] Currently, the railway industry still primarily manages digital drawings and documents using traditional methods, which have revealed numerous security management deficiencies in practical applications: Drawings and documents are scattered across various departments and terminal devices, lacking a unified encryption protection system and refined access control mechanisms, making them susceptible to illegal copying, tampering, and information leakage; existing management systems are functionally limited and lack deep integration with encryption systems, failing to achieve full-process confidentiality tracking of drawings from generation to destruction, resulting in significant security management gaps; data transmission to external collaborators such as outsourced suppliers, construction sites, and after-sales service providers lacks dedicated secure transmission channels and dynamic authorization mechanisms, making it difficult to guarantee data security in cross-enterprise and cross-process collaborations; furthermore, the use of drawings, such as opening, copying, printing, and distributing, lacks real-time auditing capabilities, making it difficult to quickly trace and locate the source of leaks; and existing encryption systems have poor compatibility with mainstream railway industry design software such as CAD and PLM, making the encryption process prone to affecting the normal operation of design software and the efficiency of cross-departmental collaboration.
[0004] The aforementioned problems make it difficult for the railway industry's security management level of drawings and documents to adapt to the industry's digital and intelligent development needs. The ability to protect core technical secrets is insufficient, which may not only lead to the loss of core technologies of enterprises, but also bring potential risks to the quality of railway engineering construction, equipment manufacturing safety and the overall development of the industry. Therefore, there is an urgent need for a technical solution that can realize the full life cycle security management of railway industry drawings and documents to solve the security loopholes and efficiency contradictions in the existing management model. Summary of the Invention
[0005] The purpose of this invention is to provide a method and system for full-lifecycle secure processing of railway drawings and documents, which solves the technical problems existing in the management of railway drawings and documents, such as scattered storage, lack of access control, high risk of leakage during transmission, inability to audit and trace usage behavior, and contradiction between encryption and collaboration efficiency. It realizes closed-loop secure management of railway drawings and documents throughout their entire lifecycle, from generation, storage, transmission, use to destruction, and is adapted to the multi-stage and cross-enterprise collaboration characteristics of the railway industry.
[0006] To achieve the above objectives, the present invention provides the following technical solution: According to one aspect of the present invention, a method for full-lifecycle security processing of drawings and documents in the railway industry is provided, comprising the following steps: S1. In the drawing generation stage, a transparent encryption and decryption engine is integrated into the design software to automatically encrypt the generated railway drawing documents. At the same time, a dynamic watermark containing user, time, and equipment information is embedded and bound to the initial permission policy. S2. In the drawing storage stage, the encrypted drawing documents are uploaded to a centralized encrypted repository to complete version archiving and identification. Fine-grained access permissions are configured based on roles, projects, and departments, and a hierarchical key management system of enterprise master key, department key, and file session key is established. S3. In the drawing transfer stage, the internal and external transfer of drawing documents is realized through a secure transmission channel based on national cryptographic algorithms. Internally, decryption keys are automatically issued according to permissions. Externally, dynamic authorization is implemented for outsourced / purchased units and construction sites, with time, frequency, and equipment restrictions, and controlled documents are generated for external distribution. S4. During the drawing usage phase, compliant viewing of encrypted drawings is achieved on authorized terminals. Screen capture prevention, printing with designated printers, and watermarking of the operator on printed copies are enforced. Unencrypted use is only permitted after fulfilling confidentiality responsibilities and going through the decryption process. S5. Full-cycle auditing and anomaly handling: The behavior auditing engine records the entire process operation log of drawings and documents, provides real-time alarms for abnormal behaviors such as copying, sending out, and tampering, and automatically blocks data outflow. The log enables full-process traceability, and the drawing destruction stage performs key cancellation and complete file deletion operations.
[0007] According to an embodiment of the present invention, in step S1, the transparent encryption and decryption engine is compatible with mainstream design software in the railway industry such as CAD and PLM, and the dynamic watermark is an invisible watermark that is only triggered and displayed when the file is copied, printed, or sent out.
[0008] According to an embodiment of the present invention, in step S2, the fine-grained access permissions include read-only, edit, download, and print permissions; the centralized encrypted repository supports rapid retrieval of drawing versions, version comparison, and historical version backtracking; and the hierarchical key management system enables independent generation, updating, and cancellation of keys.
[0009] According to an embodiment of the present invention, in step S3, the dynamic authorization is implemented through a lightweight client. The outsourcing / purchase unit can only open the encrypted drawings through a designated viewer. The outsourced controlled files are bound to the recipient's device identifier and cannot be decrypted on unauthorized devices.
[0010] According to one embodiment of the present invention, in step S4, the manufacturing site terminal is a lightweight and secure terminal that supports barcode scanning and printing management, retains complete records of printing operations, and requires multi-level electronic signature approval for decryption processes used without encryption.
[0011] According to an embodiment of the present invention, in step S5, the operation log includes the operator, operation time, operation equipment, operation behavior, and drawing / document identification information. The log is stored using a blockchain notarization method to ensure that the log is tamper-proof. Abnormal handling includes blocking operation, deregistering authorization, and locking terminal.
[0012] According to one embodiment of the present invention, the method further includes a periodic security inspection step: periodically checking the key status, permission configuration, device authorization, and audit logs of the entire security process, updating the encryption algorithm and permission policy in a timely manner, and fixing security vulnerabilities.
[0013] According to one embodiment of the present invention, the railway drawing documents include research and development design drawings, production and manufacturing drawings, operation and maintenance drawings, as well as supporting technical documents and process documents.
[0014] According to one embodiment of the present invention, the entire process of steps S1 to S5 is an electronic workflow collaboration, including electronic signatures and process log records for approval, issuance, and modification.
[0015] On the other hand, the present invention also provides a full-lifecycle security processing system for drawings and documents in the railway industry. The system includes: a data encryption and leakage prevention module, a centralized drawing management module, a secure transmission and authorization module, a behavior audit and traceability module, and an anomaly handling module. The modules work together to achieve secure processing of drawings and documents throughout their entire lifecycle. The data encryption and anti-leakage module includes a transparent encryption and decryption engine, a dynamic watermark and traceability unit, and a hierarchical key management unit, which are used to realize automatic encryption, watermark embedding and key system management during the drawing generation stage. The centralized drawing management module includes an encrypted repository, a permission management unit, a version management unit, and a workflow collaboration unit, which are used to achieve centralized encrypted storage, fine-grained permission configuration, version management, and electronic workflow collaboration during the drawing storage phase. The secure transmission and authorization module includes a national cryptographic algorithm secure transmission channel, an internal authorization unit, an external dynamic authorization unit, and an external file management unit, which are used to realize encrypted transmission and refined internal and external authorization during the drawing transfer stage. The behavior audit and traceability module includes a behavior audit engine, an operation log storage unit, and a traceability analysis unit, which are used to record the entire process of drawing operation behavior and realize log storage and full-process traceability. The anomaly handling module includes an anomaly behavior monitoring unit, a real-time alarm unit, an operation blocking unit, and a key cancellation unit. It is used to monitor, alarm, and handle anomalies in real time, and to cancel keys and clear files during the drawing destruction stage.
[0016] The present invention provides a method and system for full-cycle security processing of railway industry drawings and documents. Compared with the prior art, the beneficial effects of the present invention are as follows: (1) It realizes closed-loop security management of railway drawings and documents from generation, storage, transmission, use to destruction, fills the gap of security breakpoints in traditional management, greatly improves the leakage prevention capability of core drawings and documents, and effectively protects the technical secrets of the railway industry; (2) The encryption system is deeply integrated with the drawing management system. The transparent encryption and decryption engine is compatible with mainstream design software. The encryption process does not affect the design and collaboration efficiency, taking into account both information security and work efficiency, and solving the compatibility contradiction between the existing encryption system and the business system. (3) A refined internal and external authorization mechanism has been constructed to support fine-grained permission control by role / project / department internally and dynamic authorization by time, frequency and equipment externally, adapting to the design, manufacturing and operation and maintenance of the railway industry and the collaborative characteristics of cross-enterprise and cross-department; (4) A sound audit and traceability system has been established, and the operation logs are stored using blockchain evidence storage, so as to realize real-time auditing of operation behavior, abnormal alarm and full-process traceability. The responsible party can be quickly located in the event of leakage, and the legal evidence collection capability is improved at the same time. (5) The system adopts a lightweight design. The manufacturing site and external cooperative units are equipped with lightweight security terminals / viewers, which are easy to deploy and operate. It is also compatible with the existing software and hardware systems in the railway industry. There is no need to make large-scale modifications to existing equipment, which reduces the implementation cost and has good promotion and application value. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a flowchart of a full-cycle safety processing method for railway industry drawings and documents according to an embodiment of the present invention; Figure 2 This is a schematic diagram of a full-cycle safety processing system for railway industry drawings and documents according to an embodiment of the present invention; Figure 3 This is a schematic diagram illustrating the practical application of the full-lifecycle security processing of railway industry drawings and documents in an embodiment of the present invention. Detailed Implementation
[0018] To facilitate a clear description of the technical solutions in the embodiments of the present invention, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. For example, the first threshold and the second threshold are merely used to distinguish different thresholds and do not limit their order. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that the terms "first" and "second" are not necessarily different.
[0019] It should be noted that in this invention, the terms "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in this invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0020] In this invention, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one" or similar expressions refer to any combination of these items, including any combination of singular or plural items. For example, "at least one of a, b, or c" can represent: a, b, c, a combination of a and b, a combination of a and c, a combination of b and c, or a, b, and c, where a, b, and c can be single or multiple.
[0021] like Figure 1 As shown, a flowchart of a full-lifecycle safety processing method for railway industry drawings and documents is presented. This method includes the following steps: S101. Security procedures during the drawing generation stage: Transparent encryption and decryption engines are integrated into mainstream railway design software such as CAD and PLM. When designers generate and edit railway drawing documents in the software, the engine automatically encrypts the entire file without affecting the normal operation and collaboration efficiency of the software. At the same time, a dynamic, invisible watermark containing the operator, operation time, and unique identifier of the operating equipment is embedded in the encrypted file. The watermark is only triggered and displayed when the file is copied, printed, or sent out. An initial permission policy is also bound to the encrypted file to clarify the basic access and usage permissions of the file.
[0022] S102. Security procedures during the drawing storage phase: Designers upload encrypted drawing documents to the system's centralized encrypted repository. The repository automatically archives drawing versions and generates unique identifiers, supporting rapid version retrieval, comparison, and historical version lookup. Fine-grained access permissions are configured for different users based on roles, projects, and departments, with permission types including read-only, edit, download, and print, achieving "least privilege" control. A hierarchical key management system is also established, comprising an enterprise master key, department keys, and file session keys. Keys at each level are generated, updated, and revoked independently, ensuring the security of the key system.
[0023] S103. Security procedures during the drawing transfer stage: The internal and external transmission of drawings and documents are all achieved through a secure transmission channel built on national cryptographic algorithms, ensuring that data is not stolen or tampered with during transmission. For internal transmission, the system automatically issues corresponding decryption keys based on the user's configured permissions, enabling compliant access within authorized limits. For external transmission to outsourced units, construction sites, after-sales service, and other external entities, a dynamic authorization mechanism with time, frequency, and device restrictions is implemented. Controlled files are generated through an external dynamic authorization unit and bound to the recipient's device identifier. The recipient can only open encrypted drawings through a designated viewer and cannot decrypt them on unauthorized devices.
[0024] S104. Safety procedures during the drawing usage phase: Internal users can compliantly view encrypted drawings on authorized terminals and lightweight secure terminals in the manufacturing area. The system enforces screen capture prevention and designated printer printing control policies. Printed documents are automatically watermarked with the operator's name, and all printing operations are fully logged. If unencrypted use of drawings is required for work purposes, confidentiality obligations must be fulfilled and a multi-level electronic signature approval process must be completed before decryption can proceed. External partners can only view encrypted drawings on authorized devices and at authorized times using designated viewers; they do not have download, copy, or modification permissions.
[0025] S105. Full-cycle auditing and anomaly handling: The system uses a behavior auditing engine to record real-time operation logs for the entire process of drawing and document documentation. These logs include information such as the operator, operation time, operating equipment, operation behavior, and the unique identifier of the drawing / document. The logs are stored using blockchain technology to ensure their immutability. The system monitors for abnormal behaviors such as copying, unauthorized distribution, alteration, and unauthorized printing in real time. Upon triggering an anomaly, real-time alarms are immediately issued through the system backend and administrator terminals, and automatic measures such as operation blocking and terminal locking are implemented to prevent data leakage. When a drawing / document reaches its expiration date or needs to be destroyed, key deregistration and complete file deletion are performed to ensure that the drawing cannot be recovered or decrypted.
[0026] Furthermore, the method of the present invention also includes a periodic security inspection step: regularly checking the key status, permission configuration, device authorization, and audit logs throughout the entire security processing process, updating encryption algorithms and permission policies in a timely manner, fixing system security vulnerabilities, and ensuring the continuous effectiveness of the security processing system.
[0027] Furthermore, in the method of the present invention, the railway drawing documents include R&D design drawings, production and manufacturing drawings, operation and maintenance drawings, as well as supporting technical documents, process documents, and all other core digital documents of the railway industry.
[0028] Furthermore, the entire process from steps S101 to S105 is conducted electronically, including electronic signatures and process logs for drawing approval, distribution, and modification, thereby digitally replacing paper-based processes and improving management efficiency.
[0029] like Figure 2 The diagram shows a schematic of a full-lifecycle security processing system for railway industry drawings and documents. This system is used to implement the above method. The system includes a data encryption and leakage prevention module, a centralized drawing management module, a secure transmission and authorization module, a behavior audit and traceability module, and an anomaly handling module. The modules are interconnected through a network and work together to achieve full lifecycle security processing of drawings and documents from generation to destruction. The data encryption and anti-leakage module includes a transparent encryption and decryption engine, a dynamic watermarking and traceability unit, and a hierarchical key management unit.
[0030] The transparent encryption and decryption engine is compatible with mainstream railway industry design software such as CAD and PLM, enabling automatic full-disk encryption during the drawing generation stage; the dynamic watermarking and traceability unit enables watermark embedding and traceability identification of user, time, and equipment information; and the hierarchical key management unit enables the generation, updating, cancellation, and management of enterprise master keys, department keys, and file session keys.
[0031] The centralized drawing management module includes an encrypted repository, an access control unit, a version control unit, and a workflow collaboration unit.
[0032] The encrypted repository enables centralized encrypted storage of drawings and documents; the access control unit configures fine-grained access permissions based on roles, projects, and departments; the version control unit enables the retrieval, comparison, retrospection, and archiving of drawing versions; and the workflow collaboration unit enables electronic processes and electronic signatures for drawing approval, distribution, and changes.
[0033] The secure transmission and authorization module includes a national cryptographic algorithm secure transmission channel, an internal authorization unit, an external dynamic authorization unit, and an outgoing file management unit.
[0034] The national cryptographic algorithm secure transmission channel enables encrypted transmission of drawings; the internal authorization unit enables automatic distribution of decryption keys to internal entities according to their permissions; the external dynamic authorization unit enables time-limited, frequency-limited, and equipment-limited dynamic authorization for external cooperation / construction sites; and the external document management unit enables the generation and management of externally issued controlled documents.
[0035] The behavior auditing and tracing module includes a behavior auditing engine, an operation log storage unit, and a tracing analysis unit.
[0036] The behavior audit engine collects the entire process of drawing operations in real time; the operation log storage unit uses blockchain notarization to store operation logs; and the traceability analysis unit uses logs to achieve traceability and responsibility positioning of the entire drawing document process.
[0037] The anomaly handling module includes an abnormal behavior monitoring unit, a real-time alarm unit, an operation blocking unit, and a key deregistration unit.
[0038] The abnormal behavior monitoring unit identifies abnormal operations such as copying and unauthorized external distribution in real time; the real-time alarm unit pushes abnormal alarm information to the administrator; the operation blocking unit automatically blocks abnormal operations and locks unauthorized terminals; and the key cancellation unit realizes key cancellation and complete file deletion during the drawing destruction stage.
[0039] Figure 3 This is a schematic diagram illustrating the practical business application scenario of secure processing of drawings and documents throughout the entire lifecycle in the railway industry. Taking core business departments such as R&D, production, and materials management in the railway industry as the main body, it intuitively shows the secure processing logic of the entire process of drawings from creation, storage, internal collaborative sharing to external distribution. It clearly presents the core security measures such as encryption control, access constraints, and process standardization at each stage. It is a concrete manifestation of the method and system described in this invention in a real business scenario. The overall process revolves around three core principles: encrypted transfer, access control, and full traceability.
[0040] Figure 3 The document clarifies the core business departments / collaborating entities for the circulation of drawings in the railway industry, including three core internal departments: R&D, production, and materials, as well as two types of external collaborating entities: subsidiaries and external units. It also covers non-production use scenarios such as office settings, fully adapting to the business characteristics of internal and external collaboration in the railway industry.
[0041] (I) Drawing Creation Stage: The R&D department is the primary source for generating railway drawing documents. This stage implements a comprehensive encryption core security measure: After designers complete the drawing design in the R&D department, the system automatically encrypts the entire drawing, generating encrypted drawing files. This ensures encryption protection of the drawings from the source, guaranteeing that the drawings are under secure control from the moment they are generated, with no risk of plaintext leakage.
[0042] (II) Drawing Storage. All generated / received drawing documents are uploaded and stored in encrypted form: encrypted drawings from various departments such as R&D, production, and materials are uniformly uploaded to the system's centralized encrypted storage repository, realizing centralized and encrypted storage of drawings, eliminating the security risks caused by decentralized storage, and providing a foundation for subsequent retrieval, sharing, and version management.
[0043] (III) Internal Collaborative Sharing of Drawings (Internal Circulation within R&D / Production Departments). This stage involves the collaborative use of drawings between the R&D and production departments within railway enterprises. The core implementation measures include encrypted viewing and access control: the R&D department distributes encrypted drawings to the production department, achieving internal / collaborative sharing of drawings; after receiving the drawings, the production department can only view them in real-time through the system with encrypted access, with no plaintext access permissions throughout the process, ensuring that the encrypted state of the drawings is not lost during internal collaboration; the entire internal sharing process strictly follows fine-grained permission configuration based on roles / departments, with the production department only obtaining viewing / usage permissions matching its work, and no possibility of exceeding permissions.
[0044] (iv) External Distribution of Drawings (led by the Materials Department, targeting subsidiaries / external units). This stage involves cross-entity collaboration in the transfer of drawings from railway enterprises to subsidiaries and external units. The Materials Department leads the implementation of core security measures for controlled external distribution and exclusive viewing: As the external distribution management entity, the Materials Department professionally processes encrypted drawings to be distributed externally, creates controlled external distribution documents, and binds the documents to the recipient's equipment identification, usage period, operation permissions, and other control strategies; After receiving the controlled external distribution documents, subsidiaries and external units can only perform download and encrypted viewing operations, and must open them through the system's designated viewer. They have no permissions to copy, tamper with, or re-distribute the documents, and the entire viewing process is recorded; If the distributed drawings need to be printed, the printed copies will be generated as a watermarked PDF. The watermark contains traceability information such as the operator, time, and equipment, enabling full traceability of the distributed drawings.
[0045] (v) Special procedures are used for unencrypted applications. Figure 3 The document clarifies the sole compliant path for the unencrypted use of drawings, applicable to non-production scenarios such as office work where plaintext use of drawings is necessary. Its core implementation involves a dual control measure of fulfilling confidentiality responsibilities and following a decryption process: any department / personnel wishing to convert encrypted drawings to plaintext for unencrypted use must first fulfill the company's confidentiality responsibilities by signing a confidentiality agreement / making a confidentiality commitment; after fulfilling these responsibilities, they must go through the system's pre-set formal decryption process, undergoing multi-level electronic signature approval, before obtaining unencrypted access to the drawings, thus preventing non-compliant plaintext use.
[0046] (vi) Special control measures for drawing printing. This is specifically for the high-risk operation of drawing printing. Figure 3A comprehensive control system was designed, including designated printers, special printing processes, watermarking, and record retention. All drawing printing operations must be completed through the company's designated printers; unauthorized printers cannot print drawings. A special printing process is implemented, requiring authorization before printing commands are triggered, preventing unauthorized printing. Printed drawings bear a watermark containing unique traceability information such as the printer's name, printing time, and printing device, ensuring accountability for printed drawings. Complete records of all printing operations are retained, including the operator, time, device, and drawing information, enabling full auditability and traceability of the printing process.
[0047] Example 1: Full-cycle safety handling method; This embodiment provides a specific application scenario for a full-lifecycle security processing method for railway industry drawings and documents, applied to the drawing and document management of railway locomotive and rolling stock R&D and manufacturing enterprises. The specific steps are as follows: Drawing generation: R&D designers complete the drawing of railway locomotive bogie design drawings in CAD software. The transparent encryption and decryption engine integrated in the CAD software automatically encrypts the drawings in the whole disk, and embeds a dynamic invisible watermark containing the designer's name, operation time and design terminal device number, and binds the drawings to the initial permission policy of "R&D department can edit, production department can read and view only". Drawing storage: Designers upload encrypted drawings to the enterprise's centralized encrypted drawing repository. The repository automatically generates a drawing V1.0 version identifier. The permission management unit configures "read-only + print with designated printer" permissions for workshop directors in the production department and "online read-only view" permissions for production workers. The hierarchical key management unit generates a file session key for the drawing and associates it with the department key and the enterprise master key. Drawing transfer: The R&D department sends the drawings to the production and manufacturing department through the system's national cryptographic algorithm secure transmission channel. The system automatically issues the corresponding decryption key according to the permissions of the production department personnel. For the outsourced processing units that provide parts for the locomotive, the production department configures dynamic authorization for them through the external dynamic authorization unit with "7-day validity period, only one processing equipment can view, no printing / download permissions", generates outsourced controlled documents and sends them to the outsourced units through the secure transmission channel. Drawing usage: Production workshop workers can view encrypted drawings online through a lightweight and secure terminal on the manufacturing site. The terminal has its screen anti-screenshot function enabled, preventing copying and saving. If the workshop director needs to print drawings for production purposes, they can print them through a printer designated by the system. The printed copies are automatically watermarked with the workshop director's name and the printing time, and the system retains the printing record. External contractors can only open encrypted drawings on authorized processing equipment through a designated viewer and cannot decrypt or use them on other devices. Auditing and Handling: The behavior auditing engine records all personnel's operational behaviors in real time, including designers' editing, production workers' viewing, and workshop supervisors' printing. If a production worker attempts to illegally copy a drawing, the system's abnormal behavior monitoring unit immediately identifies the anomaly, the real-time alarm unit sends an alarm message to the enterprise security administrator, and the operation blocking unit automatically blocks the copying operation and temporarily locks the production worker's terminal. After the drawing is used in production, the security administrator cancels the drawing's file session key through the key cancellation unit of the anomaly handling module and completely deletes the drawing file from the repository, thus destroying the drawing.
[0048] In this embodiment, all operation processes are electronically approved and electronically signed through the system's process collaboration unit. The operation logs are stored using blockchain evidence storage. Subsequently, the entire lifecycle of the drawing can be traced through the traceability analysis unit. If a leakage incident occurs, the responsible party can be quickly located.
[0049] Example 2: Deployment and operation of a full-cycle security processing system; This embodiment provides a deployment and operation method for a full-lifecycle secure processing system for railway industry drawings and documents. The system is deployed on the private cloud platform of a railway engineering construction enterprise and is compatible with the enterprise's entire process of drawing and document management, including R&D, construction, and operation and maintenance. The operational collaboration relationships of the various modules of the system are as follows: The transparent encryption and decryption engine of the data encryption and anti-leakage module is integrated into the PLM and CAD design software of the enterprise's R&D department to realize automatic encryption of drawing generation. The dynamic watermark and traceability unit embeds a unique traceability identifier for each drawing file. The hierarchical key management unit regularly updates the enterprise master key and department keys to ensure key security. The encrypted repository of the centralized drawing management module is deployed on a private cloud platform to realize the centralized storage of all railway engineering construction drawings of the enterprise. The permission management unit configures different permissions for the project department, construction team and supervision unit according to the construction project. The version management unit realizes the version update after the construction drawing is changed and the historical version back. The process collaboration unit realizes the electronic approval of the issuance of construction drawings. The secure transmission and authorization module equips the construction site with a lightweight secure terminal, enables the encrypted distribution of construction drawings through a secure transmission channel based on national cryptographic algorithms, and provides temporary dynamic authorization for temporary workers on the construction site, with authorization immediately revoked upon completion of the work. The behavior audit and traceability module collects operation logs from the private cloud platform and various terminals in real time and stores them in the blockchain evidence storage node. The enterprise security management department can query the entire process operation record of the drawing at any time through the traceability analysis unit. 7. Exception Handling Module The system monitors its operation status 24 / 7 and takes real-time action against abnormal behaviors such as unauthorized external transmission and access. At the same time, the system performs regular security inspections to check permission configurations and key status and promptly fix security vulnerabilities.
[0050] After the system was deployed, the company achieved full lifecycle security management of railway engineering construction drawings, with no data leakage incidents. At the same time, due to the application of transparent encryption and electronic processes, the collaboration efficiency between design and construction improved by more than 30%, and management costs were significantly reduced.
[0051] Although the invention has been described herein in conjunction with various embodiments, those skilled in the art will understand and implement other variations of the disclosed embodiments by reviewing the accompanying drawings, disclosure, and other materials. In this specification, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple components. A single processor or other unit can implement several functions listed in the specification. While certain measures are described in different embodiments, this does not mean that these measures cannot be combined to produce good results.
[0052] Although the invention has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made therein without departing from the spirit and scope of the invention. Accordingly, this specification and drawings are merely illustrative of the invention and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if such modifications and modifications fall within the scope of the invention and its equivalents, the invention is also intended to include such modifications and modifications.
Claims
1. A method for full-lifecycle security processing of drawings and documents in the railway industry, characterized in that, Includes the following steps: S1. In the drawing generation stage, a transparent encryption and decryption engine is integrated into the design software to automatically encrypt the generated railway drawing documents. At the same time, a dynamic watermark containing user, time, and equipment information is embedded and bound to the initial permission policy. S2. In the drawing storage stage, the encrypted drawing documents are uploaded to a centralized encrypted repository to complete version archiving and identification. Fine-grained access permissions are configured based on roles, projects, and departments, and a hierarchical key management system of enterprise master key, department key, and file session key is established. S3. In the drawing transfer stage, the internal and external transfer of drawing documents is realized through a secure transmission channel based on national cryptographic algorithms. Internally, decryption keys are automatically issued according to permissions. Externally, dynamic authorization is implemented for outsourced / purchased units and construction sites, with time, frequency, and equipment restrictions, and controlled documents are generated for external distribution. S4. During the drawing usage phase, compliant viewing of encrypted drawings is achieved on authorized terminals. Screen capture prevention, printing with designated printers, and watermarking of the operator on printed copies are enforced. Unencrypted use is only permitted after fulfilling confidentiality responsibilities and going through the decryption process. S5. Full-cycle auditing and anomaly handling: The behavior auditing engine records the entire process operation log of drawings and documents, provides real-time alarms for abnormal behaviors such as copying, sending out, and tampering, and automatically blocks data outflow. The log enables full-process traceability, and the drawing destruction stage performs key cancellation and complete file deletion operations.
2. The method according to claim 1, characterized in that, In step S1, the transparent encryption and decryption engine is compatible with mainstream design software in the railway industry such as CAD and PLM. The dynamic watermark is an invisible watermark that is only triggered and displayed when the file is copied, printed, or sent out.
3. The method according to claim 1, characterized in that, In step S2, the fine-grained access permissions include read-only, edit, download, and print permissions. The centralized encrypted repository supports quick retrieval of drawing versions, version comparison, and historical version backtracking. The hierarchical key management system enables independent generation, updating, and cancellation of keys.
4. The method according to claim 1, characterized in that, In step S3, the dynamic authorization is implemented through a lightweight client. Outsourcing / purchasing units can only open encrypted drawings through a designated viewer. Controlled files are bound to the recipient's device identifier and cannot be decrypted on unauthorized devices.
5. The method according to claim 1, characterized in that, In step S4, the manufacturing site terminal is a lightweight and secure terminal that supports barcode scanning and printing management. Printing operations are recorded in their entirety, and the decryption process for unencrypted applications requires multi-level electronic signature approval.
6. The method according to claim 1, characterized in that, In step S5, the operation log includes the operator, operation time, operation equipment, operation behavior, and drawing / document identification information. The log is stored using blockchain notarization to ensure that the log is tamper-proof. Abnormal handling includes blocking the operation, deregistering authorization, and locking the terminal.
7. The method according to claim 1, characterized in that, The method also includes a periodic security inspection step: regularly checking the key status, permission configuration, device authorization, and audit logs of the entire security process, updating encryption algorithms and permission policies in a timely manner, and fixing security vulnerabilities.
8. The method according to claim 1, characterized in that, The railway drawings and documents include research and development design drawings, production and manufacturing drawings, operation and maintenance drawings, as well as supporting technical documents and process documents.
9. The method according to claim 1, characterized in that, The entire process from steps S1 to S5 is an electronic workflow collaboration, including electronic signatures and workflow logs for approval, issuance, and changes.
10. A full-lifecycle security processing system for railway industry drawings and documents, used to implement the method described in any one of claims 1 to 9, characterized in that, The system includes: a data encryption and leakage prevention module, a centralized drawing management module, a secure transmission and authorization module, a behavior auditing and tracing module, and an anomaly handling module. These modules work together to achieve secure processing of drawing documents throughout their entire lifecycle. The data encryption and anti-leakage module includes a transparent encryption and decryption engine, a dynamic watermark and traceability unit, and a hierarchical key management unit, which are used to realize automatic encryption, watermark embedding and key system management during the drawing generation stage. The centralized drawing management module includes an encrypted repository, a permission management unit, a version management unit, and a workflow collaboration unit, which are used to achieve centralized encrypted storage, fine-grained permission configuration, version management, and electronic workflow collaboration during the drawing storage phase. The secure transmission and authorization module includes a national cryptographic algorithm secure transmission channel, an internal authorization unit, an external dynamic authorization unit, and an external file management unit, which are used to realize encrypted transmission and refined internal and external authorization during the drawing transfer stage. The behavior audit and traceability module includes a behavior audit engine, an operation log storage unit, and a traceability analysis unit, which are used to record the entire process of drawing operation behavior and realize log storage and full-process traceability. The anomaly handling module includes an anomaly behavior monitoring unit, a real-time alarm unit, an operation blocking unit, and a key cancellation unit. It is used to monitor, alarm, and handle anomalies in real time, and to cancel keys and clear files during the drawing destruction stage.