Integrated electronic data investigation record generation method based on structured analysis

CN122797508APending Publication Date: 2026-09-22吉林警察学院
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610940894.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-27
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0003]由于上述过程涉及数据种类多、信息量大、步骤繁杂且格式要求严格,现有人工处理方式普遍存在以下问题:一是报告字段提取依赖人工浏览与复制,工作量大且容易漏填、误填;二是图像材料整理、筛选、插图及排版依赖人工逐项处理,效率低且易出错;三是截图、录屏、压缩、校验等证据固定环节相互分离,难以与文书导出形成统一闭环;四是不同案件之间的文书格式、字段内容和材料组织方式缺乏统一约束,导致结果规范性不足、可追溯性较弱

Benefits of technology

本发明通过构建一个从取证报告解析到文书与证据同步输出的全流程自动化闭环系统,从根本上改变了传统电子数据勘验笔录依赖大量人工、操作分散、易出错的制作模式。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122797508A_ABST
    Figure CN122797508A_ABST
Patent Text Reader

Abstract

The application discloses an integrated electronic data investigation record generation method based on structured analysis, comprising the following steps: S1, starting to leave traces and acquiring input data; S2, analyzing a report and extracting key field information; S3, structurally organizing and state marking the key field information; S4, performing manual checking and supplementing record processing; S5, identifying a case material directory and establishing a graphic-text mapping relationship; S6, performing packaging and encapsulation and integrity checking on the case material; S7, generating an investigation record document; and S8, associated output. In addition, the application also discloses a system for implementing the above method, comprising the following modules: a process trace leaving module, a report analysis module, a field management module, a man-machine checking module, a material identification and mapping module, an encapsulation and checking module, a record generation module and an associated output module. The application improves the completeness, traceability and legal validity of case handling results, and realizes the standardization, integration and closed-loop management of electronic data investigation work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information technology, specifically relating to electronic data processing, automatic document generation and electronic evidence preservation technology, and particularly to an integrated electronic data inspection record generation method based on structured analysis. Background Technology

[0002] In the electronic data forensics work of public security organs, especially cybersecurity departments, the technical evidence collection process has gradually become automated, but the preparation of forensic records still generally relies on manual work. After extracting electronic data, investigators usually need to manually search, extract, verify, and enter key information such as device information, account information, and data statistics in the evidence collection report. They also need to supplement case-specific information such as case number, investigating unit, investigator's name, inspection time, and inspection requirements based on the actual circumstances of the case. At the same time, they also need to classify, organize, insert, compress, and generate verification values ​​for image materials such as packaged photos, pre-inspection photos, extracted data screenshots, and operation screenshots.

[0003] Because the above process involves many types of data, a large amount of information, complex steps, and strict format requirements, the existing manual processing methods generally have the following problems: First, the extraction of report fields depends on manual browsing and copying, which is labor-intensive and prone to omissions and errors; second, the organization, screening, illustration, and layout of image materials depend on manual processing item by item, which is inefficient and prone to errors; third, the evidence fixation links such as screenshotting, screen recording, compression, and verification are separated from each other, making it difficult to form a unified closed loop with document export; fourth, there is a lack of unified constraints on document formats, field content, and material organization methods among different cases, resulting in insufficient standardization and weak traceability of the results.

[0004] In existing technologies, related auxiliary tools typically only support filling in a few basic fields such as case number and time. They lack the ability to automatically extract key fields from evidence reports, the ability to automatically identify and integrate text and images from case material catalogs, and mechanisms for material compression, integrity verification, and associated output linked to the document generation process. Existing technologies are insufficient to meet the actual needs of electronic data forensics work for high efficiency, standardization, integration, and traceability.

[0005] Therefore, overcoming the problems of low automation, cumbersome and error-prone manual operation, low efficiency of graphic and text integration, disconnect between document generation and evidence fixation processes, and insufficient standardization and completeness of output results in existing electronic data inspection record production methods is an urgent problem to be solved in this field. Summary of the Invention

[0006] This invention aims to provide an integrated electronic data inspection record generation method based on structured parsing. By integrating evidence report parsing, field structured organization, manual verification and supplementation, case material catalog recognition, image and text template mapping, automatic document generation, material compression and packaging, and verification and correlation output into a unified processing flow, the invention achieves automation, standardization, and integration of inspection record production.

[0007] Specifically, by establishing an automatic extraction and management mechanism for key fields, a human-machine collaborative mechanism combining automatic extraction and manual verification, an automatic identification and text-image mapping insertion mechanism for image materials, and a linkage mechanism for document generation and evidence fixation, the integrity, traceability, and closed-loop nature of the process are comprehensively improved.

[0008] Specifically, the technical solution of the present invention includes the following innovative points: 1. Full-process closed-loop integration: Integrate evidence report analysis, manual review, screenshot recording, evidence image arrangement, data compression, MD5 verification and Word record generation into the same desktop workflow, forming an automated link that runs through the entire process of creating inspection records; 2. Adaptive parsing of multi-source reports: Supports parsing of both HTML and JSON forensic report formats, and has automatic recognition and fallback switching capabilities, reducing users' dependence on report formats; 3. Field mapping and template decoupling: The internal fields are decoupled from Word template placeholders through MAPPING_RULES, thereby achieving standardization and maintainability of template replacement; 4. Maintaining consistency between image numbering and text citation: Image numbers are generated based on global consecutive numbering and category ranges to solve the problem of incorrect image numbers and inconsistent citations after manual illustration; 5. Automatic integrity verification written to documents: Automatically generates compressed package name, path and MD5 value and associates them with document context, reducing errors caused by manually filling in fixed information in electronic data; 6. Embedded process material fixation capability: The screenshot and screen recording functions are embedded into the transcript generation process, so that the operation process fixation and document production can be completed in the same system.

[0009] Furthermore, in one aspect, the present invention provides an integrated electronic data inspection record generation method based on structured analysis, comprising the following steps: Step S1, Start recording and acquire input data: Start the screen recording function to record the subsequent operation process; and acquire the target evidence report exported by the evidence collection tool, as well as the case material catalog corresponding to the target case; the case material catalog contains at least one image material among operation screenshots, encapsulated photos, extracted data and pre-examination photos; Step S2, parsing the report and extracting fields: Parse the target evidence collection report and extract the key field information required to generate the inspection record according to preset rules to obtain the initial field dataset; Step S3, Structured Organization and Marking: The key field information is structured and the fields with abnormal states are marked to form a set of fields to be processed; Step S4, manual verification and supplementation: Receive user input for verification and supplementation of the field set to be processed, and generate a confirmed field dataset; Step S5, Identify materials and establish mapping: Identify the image materials in the case material catalog and establish the image-text mapping relationship between the image materials and the inspection record template; Step S6, Packaging and Verification: Based on the case material catalog, compress and package the case materials to generate a case material compressed package, and generate the verification value corresponding to the case material compressed package and the trace file; Step S7, Generate Inspection Record Document: Based on the confirmed field dataset, the image-text mapping relationship, and the encapsulation result of the case material compressed package, call the standardized template to generate an electronic data inspection record document; Step S8, Associated Output: Associate the output of the electronic data inspection record document, the case material compressed package, the trace file and its corresponding verification value.

[0010] Optionally, in step S2, the preset rule is a keyword positioning rule; the parsing and extraction of specific fields includes: reading the target forensic report in HTML format, performing field retrieval based on preset keywords, and extracting device identification information, account statistics information, and data entry information from the retrieval results.

[0011] Optionally, step S4 further includes: saving the frequently confirmed fields by the user as historical records; when processing a new case, calling the historical records to generate a list of candidate fields for the user to select; The high-frequency fields include the name of the case handler and the case-handling unit.

[0012] Optionally, in step S5, the case material catalog includes: scanning and identifying preset subdirectories of operation screenshots, encapsulated photos, extracted data, and pre-inspection photos under the case parent directory; The establishment of the image-text mapping relationship includes: determining the insertion position of the image material in the standardized template according to the category of the image material.

[0013] Optionally, step S6 includes: compressing and packaging the target file based on the case material catalog to obtain a case material compressed package and its storage path; generating a first verification value for the case material compressed package; and generating a second verification value for the process screen recording file in the trace file. The trace files include screen recording files of the process, and may also include screenshot files generated during the inspection process.

[0014] Optionally, in step S7, the step of calling the standardized template to generate the electronic data investigation record document includes: writing the confirmed field dataset into the text variable position of the template; inserting the corresponding image materials into the image placeholder position of the template according to the image-text mapping relationship; and filling the document with the storage path and verification value of the case material compressed package as attachment information.

[0015] Optionally, step S8 includes: storing and packaging the electronic data inspection record document, the case material compressed package, the first verification value, the trace file, and the second verification value together with the same case identifier.

[0016] In another aspect, the present invention provides a system for implementing the above method, the system comprising: The process recording module is used to start and control screen recording to generate process screen recording files; The report parsing module is used to acquire and parse the target forensic report to extract key field information; The field management module is used to structure and mark the status of the key field information; The human-machine verification module is used to receive user input for field verification and supplementation, and generate a dataset of confirmed fields. The material recognition and mapping module is used to recognize image materials in the case material catalog and establish a text-image mapping relationship between the image materials and the document template; The encapsulation and verification module is used to compress and encapsulate the case material catalog to generate a case material compressed package, and generate verification values ​​corresponding to the case material compressed package and the trace file. The record generation module is used to generate electronic data inspection record documents based on the confirmed field dataset, the image-text mapping relationship, and the encapsulation result of the case material compressed package; The associated output module is used to associate and output the electronic data inspection record document, the case material compressed package, the trace file and its corresponding verification value.

[0017] Optionally, the encapsulation and verification module is further configured to: generate a first verification value for the case material compressed package, and generate a second verification value for the process screen recording file in the trace file.

[0018] Optionally, the first check value and the second check value are MD5 check values.

[0019] The technical solutions provided by the embodiments of the present invention have the following beneficial effects: This invention fundamentally changes the traditional electronic data investigation record production model, which relies heavily on manual labor, is fragmented, and prone to errors, by constructing a fully automated closed-loop system that integrates evidence report analysis with the synchronous output of documents and evidence.

[0020] Specifically, this invention significantly reduces the basic workload of case handlers in repeatedly searching, extracting, and entering data by automatically parsing evidence reports and extracting key fields, greatly improving the efficiency and accuracy of data acquisition. By structuring and marking the extracted fields, it provides a standardized and manageable data foundation for subsequent processing. Its innovative human-machine collaboration mechanism organically combines automatic extraction with manual verification and supplementation, enabling the system to flexibly adapt to the actual needs of complex cases where fields are missing or require case-specific corrections, ensuring the completeness and accuracy of the document content.

[0021] Simultaneously, the system automatically identifies image materials in the case material catalog and establishes an image-text mapping relationship, realizing the automatic insertion and unified layout of image and text materials in the inspection record, which greatly improves the efficiency of image and text integration and the consistency of document format. More importantly, this invention deeply links the document generation process with the evidence fixation operation, so that the compression and packaging of case materials, the generation of integrity verification values, and the output of process trace files can be completed synchronously and output in conjunction with the final inspection record document, thereby constructing a complete and tamper-proof evidence chain, comprehensively improving the integrity, traceability, and legal effect of the case results, and realizing the standardized, integrated, and closed-loop management of electronic data inspection work.

[0022] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of the overall process of the integrated electronic data inspection record generation method of the present invention; Figure 2 Yes Figure 1 A detailed schematic diagram illustrating the overall process of the method shown; Figure 3 This is a flowchart of the system module operation provided in the embodiments of the present invention; Figure 4 This is a schematic diagram of an application scenario provided by an embodiment of the present invention. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of protection of this invention.

[0025] This invention is mainly proposed for scenarios such as network security and law enforcement, electronic data forensics, criminal technology support, and assistance in law enforcement and case handling. It focuses on solving practical problems in the process of electronic data examination, such as "dispersed data sources, duplicate field entry, chaotic image numbering, easy to fill in compressed packages and hash values ​​incorrectly, and document format relying on manual adjustment".

[0026] In existing technologies, the creation of electronic data inspection records relies on manual searching of information from HTML / JSON reports and manual input into the document. This process suffers from problems such as inconsistent image numbering and error-prone hash values, resulting in low efficiency and poor standardization. To address this, the present invention constructs a desktop tool that integrates "report parsing - field backfilling - evidence material collection - data compression and fixation - MD5 verification - Word record rendering." This transforms the manual compilation of electronic data inspection records into a configurable, traceable, and verifiable automated process, effectively solving the problems of low efficiency, error-proneness, and incomplete evidence chains inherent in the traditional manual method.

[0027] like Figure 1 and Figure 2 As shown, on the one hand, the present invention provides an integrated electronic data inspection record generation method based on structured analysis, comprising the following steps: Step S1: Activate the record keeping function and obtain case-related input data. Start the screen recording function to record all subsequent operations in their entirety and generate a screen recording file; obtain the target evidence report exported by the evidence collection tool, as well as the case material directory corresponding to the target case; wherein, the case material directory includes at least one of operation screenshots, encapsulated photos, extracted data, and pre-examination photos; at the same time, receive basic case information obtained by user input or by calling historical records.

[0028] Specifically, screen recording is performed: when the user clicks the "Screen Recording" button in the software, the system begins recording the screen operation in the background and saves the recorded content as a process screen recording file. This serves as a crucial trace file to ensure the traceability of the evidence operation process and to preserve the record. Simultaneously, the hash value of the screen recording file is calculated. Specifically, this process screen recording file will be used in a subsequent step (S6) to calculate the verification value (second verification value).

[0029] The operation screenshots in the case materials catalog can be obtained in the following ways: receiving screenshot commands triggered by the user, including but not limited to shortcut keys, recording the selection range of the user on the display interface, capturing the target area image from the current screen image according to the range, and automatically saving it to the "Operation Screenshots" subdirectory of the case materials catalog.

[0030] Step S2: Parse the target forensic report and extract key field information Based on the file format characteristics of the target evidence collection report, the report content is read and parsed. According to preset field identifiers, keyword positioning rules, or field mapping relationships, the key field information required for generating the inspection record is extracted from the target evidence collection report to obtain an initial field dataset. The key field information includes equipment information, account information, data entry number information, and other structured data that can be used to generate the inspection record.

[0031] In some implementations, step S2 may further include an adaptive parsing mechanism for multi-format forensic reports, as detailed below: Step S201: Access the source code of the forensic report; For Honglian HTML reports: a recursive search method is used to locate the page1.html file in the report directory, and utf-8, gbk, and gb2312 encoding are tried in turn. After cleaning up HTML tags and irrelevant script styles, basic fields are extracted from plain text and table structure. For Amazon JSON reports: First, remove JavaScript variable prefixes (such as ;static.mypico.json.data_xxx=) from the file, then convert it to a standard JSON structure that is compatible with multiple versions of field names such as id / orderIndex, c1 / Col1, and c2 / Col2. Step S202: Locate the target field based on preset keywords; Step S203: Extract the field values ​​corresponding to the target field and write them into the structured field data. The extracted field values ​​correspond one-to-one with the internal fields of data_dict in step S3 (such as basic_data_num corresponding to the number of basic data entries), providing a foundation for subsequent structured storage.

[0032] Optionally, the system is configured with adaptive switching logic: if the key fields in the Honglian parsing result are empty, "none", "0" or do not exist, the Meiya parser will be automatically called to process them, reducing the user's cost of judging the report vendor's format; the parsing process includes an exception capture mechanism to avoid process interruption due to missing fields or structural abnormalities.

[0033] Step S3: Organize and status-mark key field information in a structured manner. The extracted key field information is structured and stored according to the correspondence between field name and field value to form a set of fields to be processed; fields that are missing, abnormal, pending confirmation, or require manual supplementation are marked with a status for subsequent verification and processing.

[0034] Specifically, this step uses a dual-dictionary core data structure to manage fields, establishes a mapping relationship between field identifiers and document template variables, and adds specific status markers to fields such as missing and abnormal fields. For example, missing fields are marked as "to be supplemented" and abnormal fields are marked as "to be confirmed", and these are displayed prominently in the user interface.

[0035] The dual dictionaries include: data_dict: carrying text-based fields, including report parsing fields (such as basic_data_num, IMEI1), case procedure fields (such as case_number, check_time), personnel information fields (such as check_name1), and fixed electronic data fields (such as zip_name, zip_md5); photo_dict: carrying image path fields, organized according to the categories jcms / jbxx / wxsj / jcfz.

[0036] The system maintains the mapping relationship between field identifiers and template placeholders (such as jcbh-case_number, imei1-IMEI1) uniformly through MAPPING_RULES, thereby achieving standardization and maintainability of template replacement.

[0037] Step S4: Perform manual verification and supplementary data entry. The set of fields to be processed is displayed as data items that can be verified, modified, and supplemented. It receives user additions, corrections, and confirmations for case number, case-handling unit, case-handling personnel name, inspection time, inspection requirements, and other individual case fields. Based on historical records, it performs candidate backfilling or reuse processing on high-frequency fields to obtain a confirmed field dataset.

[0038] In some implementations, step S4 may further include: Step S401: Mark the fields to be confirmed as fields to be manually entered; Step S402: Retrieve historical field records to generate candidate values; Step S403: Overwrite the automatically extracted results with the manually confirmed results to form the final field data.

[0039] Optionally, during this process, the system will display the fields as editable items, and when the automatically extracted results conflict with the manual input, the manual confirmation result shall prevail.

[0040] Furthermore, the system can save frequently accessed fields, after user confirmation, as historical records. When processing new cases, the system automatically retrieves these historical records to generate a list of candidate values ​​for the user to choose from, thus enabling field reuse. These frequently accessed fields include, but are not limited to, the investigating unit and the name of the investigating personnel.

[0041] Furthermore, the system provides a configurable manual filling interface, allowing users to dynamically add fields required for the inspection record according to the needs of each case, and to make adaptive adjustments to the standardized template, thereby improving the system's ability to handle complex and ever-changing cases.

[0042] Step S5: Identify the case materials catalog and establish a mapping relationship between text and images. The case materials catalog is scanned to identify the image materials and their path information in each sub-catalog. Based on preset template rules, illustration placeholders, or the correspondence between image categories and document positions, a text-image mapping relationship is established between the case materials and the inspection record template.

[0043] In some implementations, step S5 may further include an automatic image layout and image number consistency maintenance mechanism, as detailed below: Step S501: Identify the operation screenshots, encapsulated photos, extracted data, and pre-inspection photo subdirectories under the parent directory of the case; JCMS (Sample Description): Includes photos of the sample's appearance and delivery status, mostly taken at the scene; jbxx (Basic Information): Includes basic phone information and IMEI screenshot; wxsj (WeChat data): Includes WeChat account and chat data screenshots; jcfz (Exhibit Packaging): Includes photos of the sealed specimens.

[0044] Step S502: Read the image file paths in each subdirectory and write them into photo_dict according to the above categories; if there are no image files in a certain category of subdirectory, skip writing the path of the image in that category to avoid errors in document generation caused by empty paths; Step S503: Determine the insertion position and layout of the image in the document template according to the image category.

[0045] The JCMS and JCFZ classes use a dual-image layout (two images per page); The jbxx and wxsj classes use single-image layout (one image per page).

[0046] Optionally, the system generates map numbers for all images in this survey record using a uniform and consecutive numbering rule (e.g., " Figure 1 , Figure 2 ..."), and automatically generate text citation ranges by category using preset functions: for example, jcms corresponds to " Figure 1 "To Figure X1", jbxx corresponds to "Figure X1+1 to Figure X1+X2", ensuring that the text description, image position, and figure number are completely consistent, thus solving the problem of incorrect figure numbers and inconsistent citations after manual illustration.

[0047] Optionally, this includes: reading the parent directory path of the case; automatically identifying subdirectories with preset names such as operation screenshots, encapsulated photos, extracted data, and pre-examination photos; and reading the image file paths in each subdirectory to form a collection of image materials organized by category.

[0048] Step S6: Package and verify the integrity of the case materials. Based on the case material catalog, the target files are compressed and packaged to obtain a case material compressed package and its storage path; a first verification value is generated for the case material compressed package; a second verification value is generated for the process screen recording file generated in step S1. The process screen recording file is a core component of the trace file; the trace file includes the process screen recording file, and may also include screenshot files or other process record files triggered by the system during the investigation.

[0049] In some implementations, step S6 may further include technical details of electronic data fixation and integrity verification, as follows: Step S601: Start screen recording or screenshot control to record key operation processes; Step S602: Compress the case directory to generate a compressed file; Compression tool: Compression is achieved by calling the built-in 7-Zip. It first checks whether 7z.exe exists in the system plugin directory. If it does not exist, it prompts the user and pauses the process. Naming rules: Generate compressed package names according to the rule of "examinement number parent directory subdirectory_examinement directory" (e.g., 2024001_mobile phone examinee_WeChat data.zip) to avoid confusion from manual naming; Progress feedback: The compression process is executed in a sub-thread, parsing the percentage output by 7-Zip in real time and sending it back to the main interface to avoid the interface becoming unresponsive.

[0050] Step S603: Generate and save the verification values ​​corresponding to the compressed package and the trace file.

[0051] MD5 Calculation: After compression, the compressed file is read in binary blocks (8192 bytes per block), and a 32-bit MD5 value is calculated as the first checksum. Simultaneously, the MD5 value of the screen recording file generated in step S1 is calculated as the second checksum. Reading in blocks avoids memory overflow caused by reading large files all at once. Associated storage: The compressed package name, path, first verification value, and the path and second verification value of the process screen recording file are associated and stored, for example, written to the corresponding fields of data_dict (in the implementation, the compressed package name, path, and first verification value can be stored in the zip_name, zip_path, and zip_md5 fields respectively). This information will be directly associated with the subsequent generation of document context; wherein, the zip_name, zip_path, and zip_md5 fields are directly used to fill in the attachment column of the inspection record document in step S7.

[0052] Optionally, the compression and verification process includes a fault tolerance mechanism: before compression, check whether the necessary subdirectories and materials in the case material catalog exist. If they are missing, prompt the user and pause the subsequent process; at the same time, verify whether the 7-Zip plugin exists and whether the path is valid to avoid process interruption due to environmental issues.

[0053] Optionally, before compression and packaging, an integrity check can be performed on the case material catalog to determine whether the necessary subdirectories and materials exist. If any are missing, the user will be prompted and the subsequent process will be paused.

[0054] Optionally, specifically, the directory is compressed to generate a ZIP archive, and its MD5 checksum is calculated. This checksum can be saved as a separate file or written to the associated information.

[0055] Step S7: Generate the inspection record document based on the confirmed field dataset, image-text mapping relationship, and encapsulation results. Call the preset standardized inspection record template, write the confirmed field dataset into the corresponding position of the template, insert the identified image materials into the target position according to the image-text mapping relationship, and fill the document with the path of the case material compressed package obtained in step S6 and the first verification value corresponding to the compressed package as attachment information, complete the text content filling, image content integration and document format output, and generate the target electronic data inspection record document.

[0056] Optionally, specifically, the system uses the docxtpl template rendering engine to generate documents, and ensures automation and standardization through a three-layer mechanism: Field mapping decoupling: The mapping relationship between template placeholders and fields inside data_dict is maintained uniformly through MAPPING_RULES (such as in the template). Corresponding case_number, (For zip_md5), template adjustments only require modifying the mapping table; no changes to the rendering logic are needed. Dynamic adaptation capability: The template is pre-set with Jinja2 loop statements (such as {% for img in jcms_images%}), which automatically adapt to case situations where the number of images and the content of fields are not fixed; Layout preservation mechanism: When inserting images, preset sizes (such as 16cm width for a single image and 7.5cm width for two images) and placeholders are used to reduce the probability of layout errors during template rendering.

[0057] For example: Inserting JCMS-based images into a template The placeholder image is inserted into the jcfz class. Placeholders are used; at the same time, the compressed package name and MD5 value in data_dict are automatically filled into the document attachment field, realizing a seamless connection between "extraction-generation-verification".

[0058] Step S8: Perform verification and correlation output The target electronic data inspection record document, the case material compressed package, the first verification value, the trace file (including at least the process screen recording file) and the second verification value are associated and stored with the same case identifier (such as the case number) and exported synchronously, thereby forming a closed loop of the whole process of "input (step S1) - processing (step S2-step S7) output (step S8)" to avoid the evidence chain break caused by the disconnection of each link in the manual mode.

[0059] Optionally, the output results include documents, compressed packages, checksum files, etc., which are stored together with the same case identifier to achieve synchronous output and binding of document generation and evidence fixation. Specifically, the case identifier is used to achieve a strong binding between document generation and evidence fixation: for example, the compressed package name includes the case number (such as "2024001_Mobile Phone Sample.zip"), and the checksum file corresponds one-to-one with the compressed package to ensure that the output of any stage can be traced back to the original case.

[0060] Optionally, screen recording can be started automatically or manually at the beginning of the process to record key operations (such as report import, field verification, and document generation). The recording is stopped and saved after the process ends. A second verification value can also be generated for this screen recording file and saved together with other outputs (documents, compressed files, and verification values) as tamper-proof evidence of the legality of the process, linked by case identifiers.

[0061] Example 1: Automatic generation of inspection record from standard mobile phone forensic report In this embodiment, the object to be processed is the standardized evidence collection report and its case material directory corresponding to a certain mobile phone sample. The evidence collection report is a report file exported by the evidence collection tool, and the case material directory is the parent directory corresponding to the mobile phone sample. The parent directory includes at least one or more subdirectories of operation screenshots, encapsulated photos, extracted data, and pre-examination photos.

[0062] (1) Input data Input data includes: target evidence collection report, case material catalog, and manually entered information.

[0063] The target evidence collection report is used to reflect the device information, account information, and electronic data statistics in the mobile phone evidence; the case material catalog is used to provide image materials such as packaging photos, pre-inspection photos, extracted data, and operation screenshots; the manually supplemented information includes the case number, the case-handling unit, the name of the case-handling personnel, the inspection time, and the inspection requirements.

[0064] (2) Implementation steps The system first imports the target evidence collection report and case material directory, and saves the corresponding path information; then it parses the target evidence collection report and extracts key fields such as IMEI, number of accounts, data volume and target account identifier; then it organizes the extracted results in a structured manner and adds status markers when necessary.

[0065] Based on this, the system receives confirmation from the user of the automatically extracted results and adds case number, name, unit, time, inspection requirements, and other case-specific fields to form a confirmed field dataset. Subsequently, the system scans the parent directory of case materials, identifies image materials in each subdirectory, and establishes an image-text mapping relationship.

[0066] The system calls a preset standardized inspection record template, writes the confirmed field dataset into the corresponding text positions in the template, and inserts the identified image materials into the target positions to generate an electronic data inspection record document. After the document is generated, the system compresses and packages the case materials to create a case material compressed package, and generates a verification value for this compressed package, i.e., the first verification value. It also generates a corresponding verification value for the process screen recording file in the trace file, i.e., the second verification value. Finally, the inspection record document, the case material compressed package, the verification value file, and the process trace file are uniformly exported and associated for storage according to the same case identifier.

[0067] (3) Output results Through the above steps, this embodiment can output: an electronic data inspection record document automatically generated based on the target evidence collection report and manually supplemented information; a case material compressed package containing image materials of the target case; a first verification value file corresponding to the case material compressed package, a process screen recording file in the trace file and its corresponding second verification value file; and other trace files (such as screenshot files) saved in association with the case identifier.

[0068] (4) Implementation effect The method provided in this embodiment automates the entire process of creating an inspection record for a standard mobile phone evidence report, from report import, field extraction, manual confirmation, and image / text integration to document export, material compression, and verification output. Compared to the traditional manual process of searching, copying, entering, inserting images, and verifying each item, this embodiment reduces the workload of repetitive searching and extracting by investigators, improves the efficiency of image / text integration and document standardization, and enhances the completeness and traceability of the results.

[0069] Example 2: Scenario for supplementing and generating data for complex cases with missing fields In this embodiment, the object to be processed is still the evidence collection report and case material catalog corresponding to a certain mobile phone sample. However, the evidence collection report is not a standardized and complete report. Instead, it may have at least one of the following situations: some fields are missing, the position of the target field has changed, some fields cannot be directly identified by the preset parsing rules due to format differences, or some information required by the investigation record is not included in the evidence collection report and needs to be supplemented by the case handlers based on the facts of the case.

[0070] (1) Input data Input data includes: incomplete target evidence reports, case material catalogs, historical field records, and manually entered information.

[0071] (2) Implementation steps The system first imports incomplete target evidence reports and case material directories, and saves the report path and directory path information. Then, the system performs initial automatic parsing on the target evidence reports. For fields that can be identified by rules, they are directly extracted and written into the initial field dataset; for fields that are missing, unidentifiable, or whose extraction fails due to structural changes, valid field values ​​are not written for them, but are retained as abnormal fields or empty fields.

[0072] The system performs structured organization and status marking on the fields, dividing them into automatically identified fields, missing fields, fields awaiting manual confirmation, and fields awaiting supplementation. For fields awaiting supplementation or manual confirmation, the system preferentially extracts candidate values ​​from historical field records and generates a candidate field list. Users then manually verify and supplement the field set to be processed, either by directly selecting candidate values ​​or manually entering new values. When the automatically extracted results differ from the manual confirmation results, the manual confirmation results are taken as the final results and written into the confirmed field dataset.

[0073] After forming a complete and confirmed field dataset, the system continues to identify the case material catalog and establish a text-image mapping relationship. It then calls the standardized inspection record template to generate the target electronic data inspection record document. Subsequently, it performs material packaging, generates a case material compressed package and calculates its verification value, i.e., the first verification value. It also generates a verification value for the process screen recording file generated in the trace file, i.e., the second verification value. Finally, it performs correlation output.

[0074] (3) Output results Through the above steps, this embodiment can output: an electronic data inspection record document generated after manual supplementation and confirmation under the condition of incomplete automatic extraction; a material compressed package corresponding to the current case; the compressed package and its corresponding first verification value file, the process screen recording file in the trace file and its corresponding second verification value file; and the historical field update results associated with the case identifier.

[0075] (4) Implementation effect Compared to processing methods that rely solely on automatic extraction or manual input, this embodiment can improve the adaptability to complex cases, enabling the system to still generate standardized documents even when the target evidence report has missing fields, changed field positions, or abnormal formats. At the same time, through field status marking and historical field reuse mechanisms, it can enhance human-machine collaboration efficiency and reduce the repetitive input of high-frequency information. Furthermore, through material compression, verification value generation, and associated export, it can maintain the integrity and traceability of output results in complex cases.

[0076] Effectiveness Verification Case: Comparison of Efficiency, Standardization, and Completeness between Manual and Systematic Approaches To verify the technical effectiveness of the automatic generation and verification method for electronic data inspection records provided by this invention in practical application scenarios, several mobile phone electronic data inspection tasks were selected as test objects, and the same batch of case materials were processed by manual methods and the method of this invention, respectively.

[0077] In a manual process, investigators must manually review evidence reports, search for key fields item by item, manually fill in templates, organize image materials, insert and format images one by one, and finally compress materials and generate verification values. Because this process relies on manual completion of field searches, copying and entering data, organizing materials, inserting images, and adjusting formats, there are many steps involved, and the lack of unified coordination between different steps makes it easy for repetitive work and human errors to occur.

[0078] Under the method of this invention, the system first automatically imports the target evidence collection report and extracts key fields, and then organizes the extracted results in a structured manner; for missing fields or case information, the case handlers verify and supplement them in the interface; then the system automatically identifies the image materials in the parent directory of the case and establishes the image-text mapping relationship according to the template rules, thereby automatically generating the inspection record document; after the document is generated, the system further compresses the case material directory and generates a verification value, and at the same time outputs the inspection record, compressed package and verification result corresponding to the case.

[0079] Comparative results show that the method of the present invention is superior to manual processing in terms of generation efficiency, field filling accuracy, integrity of image and text integration, standardization of document format, and traceability of results. In particular, by automatically generating and associating the verification values ​​of the case material compressed package and the process screen recording file, it achieves dual integrity assurance for the inspection results and operation process, which can significantly improve the automation and standardization level of electronic data inspection record production.

[0080] like Figure 2 As shown, on the other hand, the present invention also provides a system for generating integrated electronic data inspection records based on structured parsing. The system is preferably designed using a hierarchical architecture combined with functional modules, so that user interaction, business processing, and document resource management are both independent and collaborative. Specifically, it may include: The user interaction layer is used to provide a graphical user interface, receive user input, display processing status, trigger functional processes, and provide feedback on processing results. The business logic layer is used to perform tasks such as parsing evidence reports, extracting fields, manually verifying data, identifying materials, mapping images and text, generating templates, recording processes, verifying material packaging, and outputting related data. The document processing layer is used for unified management of evidence collection reports, case directory files, image materials, compressed files, exported documents, and intermediate data.

[0081] For example, the user interaction layer may include: The login unit is used to manage user identity entry and allow users to enter the system homepage after identity verification is successful. The homepage navigation unit is used to display function entry points and supports switching between pages such as the automatic import interface, manual fill interface, and function operation interface; Automatic import interactive unit, used to display the field results after automatic recognition of the evidence report; The manual entry interaction unit is used to receive user input, corrections and confirmations for case number, name, unit, inspection requirements, time and other case fields; The functional operation interaction unit is used to respond to user operations such as screen recording, screenshotting, importing case paths, compression calculation, and exporting reports, and output corresponding status prompts.

[0082] The above-mentioned interaction layer design enables investigators to complete the task of creating investigation records in the order of "login-import-verify-operate-export", which meets the requirements of actual usage process and low-threshold interaction.

[0083] For example, the business logic layer, as the core processing layer of the system, includes at least the following modules: The process recording module is used to initiate and control screen recording to generate a process screen recording file; specifically, it is used to perform screen recording control, screenshot control, and related status management during the preparation of the inspection record. In an optional embodiment, the module initiates screen recording to generate a screen recording file when it receives a start recording command, and captures an image of the target area and saves it to a specified directory when it receives a screenshot trigger command.

[0084] The report parsing module is used to read the target evidence collection report and, based on preset field identifiers, keyword positioning rules, or field correspondences, parse the content of the target evidence collection report to extract the key fields required for the electronic data inspection record; the key fields include at least one of device identification information, account statistics information, and data entry information.

[0085] The field management module is used to organize the extracted key fields in a structured manner according to the correspondence between field names and field values, and to mark the status of missing fields, abnormal fields, fields to be confirmed, or fields to be manually added; in an optional implementation, this module is also used to establish a mapping relationship between field identifiers and variables in the inspection record template.

[0086] The human-machine verification module is used to receive user input for verification, modification and supplementation of automatically extracted fields, and when there is a conflict between the automatic extraction results and the manual confirmation results, it generates a final confirmed field dataset according to a preset priority rule; in an optional embodiment, the module also includes a historical field reuse unit, which is used to save the high-frequency fields input by the user and provide candidate values ​​in subsequent processing to improve information entry efficiency.

[0087] The material recognition and mapping module, including the material recognition module and the image-text mapping module, is used to recognize image materials in the case material catalog and establish their image-text mapping relationship with the document template; Specifically, the material identification module is used to identify target materials in the parent directory of the case and its subordinate subdirectories, and to classify, read, obtain paths, and organize image materials such as encapsulated photos, pre-inspection photos, extracted data, and operation screenshots; this module preferably supports automatic identification based on a preset directory structure.

[0088] Specifically, the image-text mapping module is used to establish an image-text position mapping relationship between case materials and standardized inspection record templates based on the image material category, placeholders in the template, or preset illustration rules.

[0089] The record generation module is used to call a preset standardized inspection record template, write the confirmed field data into the corresponding text variable position in the template, and insert the image material into the corresponding target position in the template according to the image-text mapping relationship, thereby generating a standardized electronic data inspection record document.

[0090] The encapsulation and verification module is used to fix and verify the integrity of case materials and process trace files. Specifically, the encapsulation and verification module is used to compress and encapsulate the case material directory to generate a compressed case material package, and generate verification values ​​for the compressed case material package and the process screen recording file or other process trace files generated by the process trace module. Specifically, the case material directory is compressed and encapsulated to generate a compressed case material package, and a first verification value is generated for the compressed case material package; and a second verification value is generated for the process screen recording file generated by the process trace module, thereby achieving full-chain evidence integrity protection from result to process. In an optional embodiment, the generated first and second verification values ​​are MD5 values.

[0091] The associated output module is used to associate, store, and package the electronic data inspection record document, the case material compressed package, the first verification value, the trace file (including at least the process screen recording file), and the second verification value according to the same case identifier.

[0092] The connections between the modules in the business logic layer are not a simple linear sequence, but a parallel and convergent collaborative workflow that can achieve a closed loop from raw data to standardized and verifiable inspection records.

[0093] For example, the file processing layer may include: The report file management unit is used to read and cache source files of forensic reports; The directory resource management unit is used to scan the parent and subdirectories of cases and maintain the path information of image materials, screen recording files and other attachment resources; Intermediate data storage unit is used to store extracted fields, manual data entry results, image and text mapping results, historical field records, and other intermediate state data; The export file management unit is used to generate and save inspection record documents, compressed packages, check value files and their associated information.

[0094] By adopting the above file processing layer design, the system's resource access efficiency and result consistency in local operation scenarios can be improved by standardizing and constraining file paths and directory structures.

[0095] like Figure 3 As illustrated, the integrated electronic data inspection record generation method based on structured analysis described in this invention can be implemented using an electronic device. This electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the method as described in the foregoing embodiments. This electronic device can be a server, workstation, personal computer, or other terminal device with computing capabilities.

[0096] By way of example, the present invention also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the method embodiments described above. The computer-readable storage medium includes, but is not limited to, various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), solid-state drives (SSDs), magnetic disks, or optical disks.

[0097] The basic working principle of this invention is as follows: This invention adopts an integrated technical approach of "evidence report rule parsing - field structure organization - manual verification and supplementation - case material catalog recognition - image and text template mapping generation - verification and correlation output" to reconstruct the entire process of electronic data inspection record production.

[0098] First, for the target evidence collection report exported by the evidence collection tool, based on preset field identifiers, keyword positioning rules or field mapping relationships, the system automatically reads and extracts device information, account information, data entry information and other key fields required for the inspection record, and organizes the extraction results into a structured field data set.

[0099] Secondly, the automatically extracted results undergo status marking and manual verification. For missing, abnormal, pending, or case-by-case fields, the system displays them as verifiable, modifiable, and supplementable data items, and receives case information such as case number, name, unit, and inspection requirements from the user to form a confirmed field dataset.

[0100] Furthermore, for image materials such as encapsulated photos, pre-inspection photos, extracted data, and operation screenshots in the case material catalog, the system automatically performs catalog scanning, material identification, and path acquisition, and establishes image-text mapping relationships based on preset template rules or the correspondence of illustration positions.

[0101] Then, the standardized inspection record template is invoked, the confirmed field data is written into the target text position in the template, and the image material is inserted into the target illustration position in the template to generate an integrated electronic data inspection record document.

[0102] Finally, the case materials are compressed and packaged to generate a compressed case material package, and a first verification value is generated for the compressed package; a second verification value is generated for the screen recording file in the trace file. The electronic data inspection record document, the compressed case material package, the first verification value, the trace file, and the second verification value are associated and output according to the same case identifier, thereby forming a closed-loop processing mechanism of "automatic extraction - manual verification - document generation - evidence consolidation".

[0103] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A method for generating integrated electronic data inspection records based on structured analysis, characterized in that, Includes the following steps: Step S1, Start recording and acquire input data: Start the screen recording function to record the subsequent operation process; It also obtains the target evidence collection report exported by the evidence collection tool, as well as the case material catalog corresponding to the target case; the case material catalog includes at least one image material among operation screenshots, encapsulated photos, extracted data, and pre-examination photos; Step S2, parsing the report and extracting fields: Parse the target evidence collection report and extract the key field information required to generate the inspection record according to preset rules to obtain the initial field dataset; Step S3, Structured Organization and Marking: The key field information is structured and the fields with abnormal states are marked to form a set of fields to be processed; Step S4, manual verification and supplementation: Receive user input for verification and supplementation of the field set to be processed, and generate a confirmed field dataset; Step S5, Identify materials and establish mapping: Identify the image materials in the case material catalog and establish the image-text mapping relationship between the image materials and the inspection record template; Step S6, Packaging and Verification: Based on the case material catalog, compress and package the case materials to generate a case material compressed package, and generate the verification value corresponding to the case material compressed package and the trace file; Step S7, Generate Inspection Record Document: Based on the confirmed field dataset, the image-text mapping relationship, and the encapsulation result of the case material compressed package, call the standardized template to generate an electronic data inspection record document; Step S8, Associated Output: Associate the output of the electronic data inspection record document, the case material compressed package, the trace file and its corresponding verification value.

2. The integrated electronic data inspection record generation method based on structured analysis according to claim 1, characterized in that, In step S2, the preset rule is a keyword positioning rule; the parsing and extraction of specific fields includes: reading the target forensic report in HTML format, performing field retrieval based on preset keywords, and extracting device identification information, account statistics information, and data entry information from the retrieval results.

3. The integrated electronic data inspection record generation method based on structured analysis according to claim 1, characterized in that, Step S4 further includes: saving the frequently confirmed fields by the user as historical records; when processing a new case, calling the historical records to generate a list of candidate fields for the user to choose from; The high-frequency fields include the name of the case handler and the case-handling unit.

4. The integrated electronic data inspection record generation method based on structured analysis according to claim 1, characterized in that, In step S5, the case material catalog includes: scanning and identifying the preset operation screenshots, encapsulated photos, extracted data and pre-inspection photo subdirectories under the case parent directory; The establishment of the image-text mapping relationship includes: determining the insertion position of the image material in the standardized template according to the category of the image material.

5. The integrated electronic data inspection record generation method based on structured analysis according to claim 1, characterized in that, Step S6 includes: compressing and packaging the target file based on the case material catalog to obtain a case material compressed package and its storage path; generating a first verification value for the case material compressed package; and generating a second verification value for the screen recording file in the trace file. The trace files include screen recording files of the process, and may also include screenshot files generated during the inspection process.

6. The integrated electronic data inspection record generation method based on structured analysis according to claim 1, characterized in that, In step S7, the step of calling the standardized template to generate the electronic data inspection record document includes: writing the confirmed field dataset into the text variable position of the template; inserting the corresponding image materials into the image placeholder position of the template according to the image-text mapping relationship; and filling the document with the storage path and verification value of the case material compressed package as attachment information.

7. The integrated electronic data inspection record generation method based on structured analysis according to claim 5, characterized in that, Step S8 includes: storing and packaging the electronic data inspection record document, the case material compressed package, the first verification value, the trace file, and the second verification value together with the same case identifier.

8. A system for implementing the method as described in any one of claims 1-7, characterized in that, The system includes: The process recording module is used to start and control screen recording to generate process screen recording files; The report parsing module is used to acquire and parse the target forensic report to extract key field information; The field management module is used to structure and mark the status of the key field information; The human-machine verification module is used to receive user input for field verification and supplementation, and generate a dataset of confirmed fields. The material recognition and mapping module is used to recognize image materials in the case material catalog and establish a text-image mapping relationship between the image materials and the document template; The encapsulation and verification module is used to compress and encapsulate the case material directory to generate a case material compressed package, and generate verification values ​​corresponding to the case material compressed package and the trace file. The record generation module is used to generate electronic data inspection record documents based on the confirmed field dataset, the image-text mapping relationship, and the encapsulation result of the case material compressed package; The associated output module is used to associate and output the electronic data inspection record document, the case material compressed package, the trace file and its corresponding verification value.

9. The system according to claim 8, characterized in that, The encapsulation and verification module is also used to: generate a first verification value for the case material compressed package, and generate a second verification value for the process screen recording file in the trace file.

10. The system according to claim 9, characterized in that, The first check value and the second check value are MD5 check values.