WO2017063465A1 - Innovation and creativity data processing method, device and system and certificate storage device - Google Patents

Innovation and creativity data processing method, device and system and certificate storage device Download PDF

Info

Publication number
WO2017063465A1
WO2017063465A1 PCT/CN2016/098152 CN2016098152W WO2017063465A1 WO 2017063465 A1 WO2017063465 A1 WO 2017063465A1 CN 2016098152 W CN2016098152 W CN 2016098152W WO 2017063465 A1 WO2017063465 A1 WO 2017063465A1
Authority
WO
WIPO (PCT)
Prior art keywords
certificate
data string
data
time
information
Prior art date
Application number
PCT/CN2016/098152
Other languages
French (fr)
Chinese (zh)
Inventor
鹿毅忠
Original Assignee
北京源创云网络科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京源创云网络科技有限公司 filed Critical 北京源创云网络科技有限公司
Publication of WO2017063465A1 publication Critical patent/WO2017063465A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • G06F21/645Protecting data integrity, e.g. using checksums, certificates or signatures using a third party

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Bioethics (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Databases & Information Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Storage Device Security (AREA)

Abstract

An innovation and creativity data processing method, device and system and a certificate storage device. An enterprise client generates a unique corresponding first data string according to innovation and creativity data; and sends the first data string to the certificate storage device for certificate storage; the certificate storage device returns return receipts such as certificate storage time and credible timestamp. The certificate storage time is credible time issued by a credible time issuing device, and the credible timestamp is obtained in a manner in which the certificate storage device performs, by using a private key, digital signing on a second data string that is generated according to the first data string and the certificate storage time, thereby ensuring the authenticity and the credibility of the certificate storage device. The certificate storage time of innovation and creativity data is cured by means of the credible time issued by the credible time issuing device; the certificate storage process is based on the first data string rather than innovation and creativity data content, thereby effectively ensuring the confidentiality of data content of the enterprise client; meanwhile, the certificate storage process is implemented by a third party that does not have a benefit relationship with a user, thereby improving the credibility of original creativity authentication of innovation and creativity data of the enterprise.

Description

创新创意数据处理方法、装置、系统及存证设备Innovative creative data processing method, device, system and depositing device 技术领域Technical field
本发明涉及数据信息存储及处理技术领域,涉及企业创新创意数据第三方存证验证领域,尤其涉及一种创新创意数据处理方法、装置、系统及存证设备。The invention relates to the technical field of data information storage and processing, and relates to the field of third-party deposit verification of enterprise creative creative data, in particular to an innovative creative data processing method, device, system and depositing device.
背景技术Background technique
随着互联网技术的普及,网络已经慢慢成为了数据传递、传播的重要途径。With the popularity of Internet technology, the network has gradually become an important way of data transmission and dissemination.
电子数据尤其对于创新/创意的电子数据,例如:技术文档、软件代码、设计素材、音视频作品等,其发明创造的构思一般都以电子形式记录,随之而来的问题是,若这些创新/创意电子数据不能被具有法律效力地存储下来,一旦泄露,随着网络的传播速度快、范围广,则很难证明其原创的历史、原创的成果。Electronic data, especially for innovative/creative electronic data, such as technical documents, software code, design materials, audio and video works, etc., the concept of invention and creation is generally recorded in electronic form, and the problem is that if these innovations / Creative electronic data can not be stored legally. Once leaked, as the network spreads quickly and has a wide range, it is difficult to prove its original history and original results.
目前对于创新/创意电子数据的保护基本都是通过给电子作品加密或打上水印的方式,但这种方式仅能对作品本身进行一定程度的防篡改保护,很难证明其原创的时间性及归属性,维权艰难。我国相关法律对电子数据的原件形式有如下规定:能够可靠地保证自最终形成时起,内容保持完整、未被更改。通常一般情况下,由中立的第三方云端保存的电子数据,其证明力大于当事人保存的电子数据。但是,现有的计算机系统安全漏洞层出不穷,第三方云端也经常会被恶意攻击者攻击。例如,2013年大量腾讯QQ的用户数据被泄露;2014年800万小米用户数据泄露等等。另一方面,第三方云端本身也可能会误用或者滥用用户的电子数据对用户造成威胁,例如商户将自己数据库内的用户信息卖给其他行业的销售人员的违法行为。综合上面的因素,用户对于将自己的电子数据尤其是发明创造成果的创新/创意电子数据存储于第三方云端存在必然的担心,很多企业就是基于这点而不敢将企业的核心数据以及技术秘密等资料的保密完全依赖于第三方的云存储系统;然而企业自行保存或备份的技术成果/技术秘密一旦 泄露,其自证该技术成果/技术秘密的归属性、原创性很难。因此对于企业来说,既希望技术成果/技术秘密的内容可以保留在企业内部,又希望通过可信第三方为其创新创意技术成果进行原创时间的固化以及原创性鉴证。因此,亟需一种平台可以使创新创意数据保存在企业本地数据库的情况下还能够同时获得可信第三方的原创性鉴证保护,以证明其创新创意数据的历史性和成果性。At present, the protection of innovative/creative electronic data is basically by encrypting or watermarking electronic works, but this method can only protect the work itself to a certain degree of tamper protection, and it is difficult to prove its original timeliness and attribution. Sex, rights protection is difficult. The relevant laws of China have the following provisions on the original form of electronic data: it can reliably guarantee that the content remains intact and has not been changed since the final formation. Generally, electronic data stored by a neutral third-party cloud is more powerful than the electronic data saved by the parties. However, existing computer system security vulnerabilities are endless, and third-party clouds are often attacked by malicious attackers. For example, in 2013, a large number of user data of Tencent QQ were leaked; in 2014, 8 million cubic meters of user data leaked and so on. On the other hand, the third-party cloud itself may misuse or misuse the user's electronic data to pose a threat to the user, such as the illegal behavior of the merchant to sell the user information in the database to the sales personnel in other industries. Based on the above factors, users are inevitably worried about storing their own electronic data, especially the innovative/creative electronic data of invention and creation, in the third-party cloud. Many companies are based on this and do not dare to put the core data and technical secrets of the enterprise. The confidentiality of the data is completely dependent on the third-party cloud storage system; however, the technical results/technical secrets that the enterprise saves or backs up once Leakage, it is difficult to prove the attribution and originality of the technical achievements/technical secrets. Therefore, for the enterprise, it is hoped that the content of the technical achievement/technical secret can be retained inside the enterprise, and it is hoped that the original time can be solidified and the originality is verified by the trusted third party for its innovative creative technology achievements. Therefore, there is a need for a platform that enables innovative creative data to be stored in an enterprise's local database and simultaneously obtain the original forensic protection of trusted third parties to prove the historical and fruitful nature of their innovative creative data.
发明内容Summary of the invention
本发明提供一种创新创意数据处理方法、装置、系统及存证设备,为企业创新创意数据提供原创时间点的存证固化保护,以有效保证创新创意数据的历史性和成果性;同时该存证过程可以基于与企业创新创意数据唯一对应的数据串进行存证,保证了企业创新创意数据的保密性。The invention provides an innovative creative data processing method, device, system and depositing device, which provides the original time point of the certificate solidification protection for the enterprise creative creative data, so as to effectively ensure the historical and fruitfulness of the innovative creative data; The certificate process can be based on the data string uniquely corresponding to the enterprise's innovative creative data, ensuring the confidentiality of the company's innovative creative data.
本发明提供一种创新创意数据处理方法,包括:The invention provides an innovative creative data processing method, comprising:
企业客户端根据创新创意数据,生成第一数据串,所述第一数据串是与所述创新创意数据唯一对应的数据信息;The enterprise client generates a first data string according to the innovation creative data, where the first data string is data information uniquely corresponding to the innovation creative data;
向存证设备发送存证请求,所述存证请求包含:所述第一数据串;Sending a deposit request to the depositing device, the deposit request comprising: the first data string;
接收所述存证设备返回的存证回执,所述存证回执包含:所述第一数据串对应的存证时间;则所述企业客户端将所述存证时间与所述创新创意数据关联存储;Receiving a certificate receipt returned by the depositing device, where the certificate receipt includes: a deposit time corresponding to the first data string; and the enterprise client associates the deposit time with the innovation creative data storage;
或者所述存证回执包含:所述存证时间、可信时间戳;则所述企业客户端Or the deposit receipt includes: the deposit time, a trusted time stamp; and the enterprise client
将所述存证时间、所述创新创意数据、所述可信时间戳关联存储;And storing the deposit time, the innovation creative data, and the trusted time stamp;
所述存证时间是所述存证设备向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;所述可信时间戳是所述存证设备基于所述第一数据串、所述存证时间生成的唯一对应的第二数据串;且所述存证设备采用私钥对所述第二数据串进行数字签名后得到的。The depositing time is that the depositing device sends the first data string to the trusted time issuing device, so that the trusted time signing device is trusted according to the time when the first data string is received. The trusted timestamp is a unique second data string generated by the depositing device based on the first data string and the deposit time; and the depositing device uses the private key pair Two data strings are obtained after digital signature.
进一步地,所述企业客户端根据创新创意数据,生成第一数据串之前,还包括:Further, before the enterprise client generates the first data string according to the innovative creative data, the enterprise client further includes:
接收企业创新创意技术文档,所述技术文档包含:技术文档内容信息、多种属性信息; Receiving an enterprise creative creative technical document, the technical document comprising: technical document content information, and multiple attribute information;
根据至少一种所述属性信息对接收到的所述技术文档进行归类,形成归类后的技术文档数据包;Sorting the received technical documents according to at least one of the attribute information to form a classified technical document data package;
当所述技术文档数据包满足企业预设存证条件时,对所述技术文档数据包进行数据处理得到所述创新创意数据。When the technical document data package satisfies the enterprise preset depositing condition, data processing is performed on the technical document data packet to obtain the innovative creative data.
进一步地,所述属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息;Further, the attribute information includes one or more of the following items: a project ID, a technical document creator, a version number, a customer ID, a R&D department ID, and location information;
所述预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。The preset depositing conditions include: a preset depositing period, an item completion identifier, or a technical document security level.
进一步地,所述对所述技术文档数据包进行数据处理得到所述创新创意数据包括:Further, the data processing of the technical document data packet to obtain the innovative creative data includes:
根据预设数据格式和/或加密算法,对所述技术文档数据包进行数据处理;Performing data processing on the technical document data packet according to a preset data format and/or an encryption algorithm;
所述对所述技术文档数据包进行数据处理得到所述创新创意数据之后,还包括:After the data processing of the technical document data packet to obtain the innovative creative data, the method further includes:
将所述创新创意数据存储在所述企业客户端的本地数据库中。The innovative creative data is stored in a local database of the enterprise client.
进一步地,所述接收所述存证设备返回的存证回执之后,还包括:Further, after receiving the certificate receipt returned by the depositing device, the method further includes:
向所述存证设备发送出证请求,所述出证请求包含:所述存证回执的标识信息;Sending a certificate request to the depositing device, where the certificate request includes: identification information of the certificate receipt;
接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;Receiving a certificate of deposit of the innovation creative data returned by the depositing device according to the identification information of the certificate receipt; the certificate of deposit includes: a certificate number and a time of depositing a certificate;
相应的,所述接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书之后,还包括:Correspondingly, after receiving the certificate of deposit of the innovative creative data returned by the depositing device according to the identification information of the certificate receipt, the method further includes:
向所述存证设备发送第一验证请求,所述第一验证请求包含:所述证书编号,以使所述存证设备根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;Sending a first verification request to the certificate storage device, where the first verification request includes: the certificate number, so that the certificate storage device checks, according to the certificate number, whether a certificate corresponding to the certificate number has been stored certificate;
若存储,接收所述存证设备根据所述证书编号查验后返回的所述存证证书。And if stored, receiving the certificate of deposit returned by the depositing device after checking according to the certificate number.
进一步地,所述方法还包括:Further, the method further includes:
向所述存证设备发送所述创新创意数据的描述信息,以使所述存证设备将所述描述信息与所述第一数据串关联存储; Transmitting the description information of the innovation creative data to the certificate storage device, so that the certificate storage device stores the description information in association with the first data string;
相应的,所述第一验证请求还包含:验证密码;Correspondingly, the first verification request further includes: a verification password;
接收所述存证设备根据所述验证密码查验通过后,反馈的所述创新创意数据的所述描述信息。Receiving, by the verification device, the description information of the innovative creative data that is fed back after the verification password is passed.
进一步地,所述企业客户端根据创新创意数据,生成第一数据串之后,还包括:Further, after the enterprise client generates the first data string according to the innovative creative data, the method further includes:
向所述存证设备发送第二验证请求,所述第二验证请求包含:所述第一数据串;Sending a second verification request to the certificate storage device, where the second verification request includes: the first data string;
接收所述存证设备根据所述第一数据串进行查验后返回的第一验证回执。Receiving a first verification receipt returned by the depositing device after checking according to the first data string.
进一步地,所述接收所述存证设备根据所述第一数据进行查验后返回的第一验证回执,包括:Further, the receiving the first verification receipt returned by the depositing device after checking according to the first data comprises:
若所述存证设备中没有存储所述第一数据串,接收所述存证设备返回的未查到存证信息的响应消息;If the first data string is not stored in the certificate storage device, receiving a response message returned by the certificate storage device that does not find the deposit certificate information;
若所述存证设备中已存储所述第一数据串,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And if the first data string is already stored in the certificate storage device, receiving a response message for checking the certificate information returned by the certificate storage device and/or the certificate time information of the first data string.
进一步地,所述企业客户端根据创新创意数据,生成第一数据串之后,还包括:Further, after the enterprise client generates the first data string according to the innovative creative data, the method further includes:
向所述存证设备发送第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;Sending a third verification request to the certificate storage device, where the third verification request includes: the first data string, a trusted timestamp;
若所述存证数据库中已存储所述第一数据串,接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执。And if the first data string is stored in the certificate database, receiving a second verification receipt returned by the certificate device according to the first data string and the trusted timestamp.
进一步地,所述接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执,包括:Further, the receiving, by the checking device, the second verification receipt returned after the checking according to the first data string and the trusted timestamp, includes:
若所述存证设备基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第三数据串;并基于所述可信时间戳解密得到第四数据串;且所述第三数据串与所述第四数据串完全匹配,则接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And generating, by the certificate storage device, a unique third data string based on the first data string and the certificate time of the first data string; and decrypting the fourth data string based on the trusted time stamp; And the third data string and the fourth data string are completely matched, and the response message of the found evidence information returned by the certificate storage device and/or the certificate time information of the first data string is received.
进一步地,所述向存证设备发送存证请求,包括:Further, the sending the deposit request to the depositing device includes:
向存证设备发送带有第一CA认证信息的存证请求,所述第一CA认证信息包含:企业客户端的身份验证信息,以使所述存证设备根据所述第一CA 认证信息,对所述企业客户端的身份进行验证。Sending a certificate request with the first CA authentication information to the certificate storage device, where the first CA authentication information includes: identity verification information of the enterprise client, so that the certificate device is according to the first CA Authentication information, verifying the identity of the enterprise client.
进一步地,所述接收企业创新创意技术文档,包括:Further, the receiving enterprise innovation creative technical document includes:
接收带有第二CA认证信息的企业创新创意技术文档,所述第二CA认证信息包含:发送所述企业创新创意技术文档的发送方的身份验证信息以及所述发送方所归属的部门的身份验证信息;以使所述企业客户端根据所述第二CA认证信息,对所述企业创新创意技术文档的发送方的身份进行验证。Receiving an enterprise innovation creative technical document with a second CA authentication information, where the second CA authentication information includes: sending identity verification information of a sender of the enterprise innovation creative technical document and identity of a department to which the sender belongs Verifying information; such that the enterprise client verifies the identity of the sender of the enterprise innovation creative technical document according to the second CA authentication information.
进一步地,所述企业客户端根据创新创意数据,生成第一数据串之前,还包括:Further, before the enterprise client generates the first data string according to the innovative creative data, the enterprise client further includes:
向所述存证设备发送注册请求;Sending a registration request to the depositing device;
接收所述存证设备返回的算法生成器;所述算法生成器用于根据预设算法生成与所述创新创意数据唯一对应的所述第一数据串。Receiving an algorithm generator returned by the certificate storage device; the algorithm generator is configured to generate the first data string uniquely corresponding to the innovation creative data according to a preset algorithm.
本发明还提供一种创新创意数据处理方法,包括:The invention also provides an innovative creative data processing method, comprising:
存证设备接收企业客户端发送的存证请求,所述存证请求包含:第一数据串;所述第一数据串是所述企业客户端基于创新创意数据生成的唯一数据信息;The certificate storage device receives a certificate request sent by the enterprise client, where the certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data;
比对存证数据库中是否已存储有所述第一数据串,若没有,则向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备签发所述第一数据串的存证时间;所述存证时间为所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;Aligning whether the first data string is already stored in the certificate database, and if not, sending the first data string to the trusted time signing device, so that the trusted time signing device issues the first data The certificate time of the string; the certificate time is a trusted time issued by the trusted time signing device based on the time when the first data string is received;
基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第二数据串;Generating a unique corresponding second data string based on the first data string and the certificate time of the first data string;
采用私钥对所述第二数据串进行数字签名,得到与所述第一数据串对应的可信时间戳;Digitally signing the second data string with a private key to obtain a trusted timestamp corresponding to the first data string;
将所述第一数据串、所述第一数据串的存证时间、所述可信时间戳关联存储;And storing the first data string, the certificate time of the first data string, and the trusted timestamp;
向所述企业客户端返回存证回执;所述存证回执包含:所述第一数据串的存证时间,或者包含:所述第一数据串的存证时间和所述可信时间戳。Returning a deposit receipt to the enterprise client; the certificate receipt includes: a certificate time of the first data string, or a: a certificate time of the first data string and the trusted timestamp.
进一步地,所述方法还包括:Further, the method further includes:
接收所述企业客户端发送的出证请求,所述出证请求包含:所述存证回执的标识信息; Receiving a certificate request sent by the enterprise client, where the certificate request includes: identifier information of the certificate receipt;
根据所述存证回执的标识信息,向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;And returning, to the enterprise client, a certificate of deposit of the innovation creative data corresponding to the identifier information according to the identifier information of the certificate receipt receipt; the certificate of deposit includes: a certificate number and a certificate time;
相应的,所述向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书之后,还包括:Correspondingly, after the returning the certificate of the innovation creative data corresponding to the identifier information to the enterprise client, the method further includes:
接收所述企业客户端发送的第一验证请求,所述第一验证请求包含:所述证书编号;Receiving a first verification request sent by the enterprise client, where the first verification request includes: the certificate number;
根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;Checking, according to the certificate number, whether a certificate of deposit corresponding to the certificate number has been stored;
若存储,发送所述存证证书。If stored, the certificate of deposit is sent.
进一步地,其特征在于,所述方法还包括:Further, the method further includes:
接收所述企业客户端发送的所述创新创意数据的描述信息,将所述描述信息与所述第一数据串关联存储;Receiving description information of the innovation creative data sent by the enterprise client, and storing the description information in association with the first data string;
相应的,所述第一验证请求还包含:验证密码;Correspondingly, the first verification request further includes: a verification password;
根据所述验证密码查验所述验证密码是否正确,若正确,向所述企业客户端反馈所述存证证书对应的描述信息。And verifying, according to the verification password, whether the verification password is correct, and if yes, feeding back, to the enterprise client, description information corresponding to the certificate.
进一步地,所述描述信息包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息;所述接收所述企业客户端发送的所述创新创意数据的描述信息之后,还包括:Further, the description information includes: an item ID, a creator, a version number, a customer ID, a R&D department ID, or location information; and after receiving the description information of the innovation creative data sent by the enterprise client, the method further includes: :
根据至少一种所述描述信息对接收到的所述创新创意数据进行归类,形成所述创新创意数据的索引文档;以使所述企业客户端根据任一所述描述信息查找到对应的所述创新创意数据的归类信息。And classifying the received innovation creative data according to at least one of the description information to form an index document of the innovation creative data; so that the enterprise client finds a corresponding location according to any description information. A classification of innovative creative data.
进一步地,所述方法还包括:Further, the method further includes:
接收所述企业客户端发送的第二验证请求,所述第二验证请求包含:所述第一数据串;Receiving a second verification request sent by the enterprise client, where the second verification request includes: the first data string;
在存证数据库中查验是否已存储所述第一数据串,根据查验结果返回第一验证回执。Checking whether the first data string has been stored in the certificate database, and returning the first verification receipt according to the verification result.
进一步地,所述根据查验结果返回第一验证回执,包括:Further, the returning the first verification receipt according to the verification result comprises:
若所述存证数据库中没有存储所述第一数据串,向所述企业客户端返回未查到存证信息的响应消息;If the first data string is not stored in the certificate database, returning a response message that the certificate information is not found to the enterprise client;
若所述存证数据库中已存储所述第一数据串,向所述企业客户端返回查 到存证信息的响应消息和/或所述第一数据串的存证时间信息。Returning to the enterprise client if the first data string has been stored in the certificate database a response message to the deposit information and/or a deposit time information of the first data string.
进一步地,所述方法还包括:Further, the method further includes:
接收所述企业客户端发送的第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;Receiving a third verification request sent by the enterprise client, where the third verification request includes: the first data string, a trusted timestamp;
若存证数据库中已存储所述第一数据串,根据所述第一数据串、所述可信时间戳进行验证,得到验证结果,并根据所述验证结果返回第二验证回执。If the first data string is stored in the certificate database, the verification is performed according to the first data string and the trusted timestamp, and the verification result is obtained, and the second verification receipt is returned according to the verification result.
进一步地,所述根据所述第一数据串、所述可信时间戳进行验证,得到验证结果,并根据所述验证结果返回第二验证回执,包括:Further, the verification is performed according to the first data string and the trusted timestamp, and the verification result is obtained, and the second verification receipt is returned according to the verification result, including:
查找与所述第一数据串对应的存证时间,并根据所述第一数据串和所述存证时间生成唯一对应的第三数据串;Searching for a certificate time corresponding to the first data string, and generating a unique third data string according to the first data string and the certificate time;
对所述可信时间戳进行解密,得到第四数据串;Decrypting the trusted timestamp to obtain a fourth data string;
若所述第三数据串与所述第四数据串完全匹配,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And if the third data string completely matches the fourth data string, returning, to the enterprise client, a response message for checking the deposit information and/or the certificate time information of the first data string.
进一步地,所述向所述企业客户端返回存证回执,包括:Further, the returning the deposit receipt to the enterprise client includes:
向所述企业客户端返回带有CA认证信息的存证回执,以向所述企业客户端提供所述存证设备的身份验证信息。Returning a certificate receipt with CA authentication information to the enterprise client to provide the enterprise client with the authentication information of the certificate device.
进一步地,所述方法还包括:Further, the method further includes:
接收所述企业客户端发送的注册请求;Receiving a registration request sent by the enterprise client;
返回用于生成所述第一数据串的算法生成器,以使所述企业客户端根据所述算法生成器提供的预设算法生成与所述创新创意数据唯一对应的所述第一数据串。Returning an algorithm generator for generating the first data string, so that the enterprise client generates the first data string uniquely corresponding to the innovation creative data according to a preset algorithm provided by the algorithm generator.
本发明还提供一种创新创意数据处理装置,包括:The invention also provides an innovative creative data processing device, comprising:
数据串生成模块,用于根据创新创意数据,生成第一数据串,所述第一数据串是与所述创新创意数据唯一对应的数据信息;a data string generating module, configured to generate, according to the innovative creative data, a first data string, where the first data string is data information uniquely corresponding to the innovative creative data;
发送模块,用于向存证设备发送存证请求,所述存证请求包含:所述第一数据串;a sending module, configured to send a deposit request to the depositing device, where the deposit request includes: the first data string;
第一接收模块,用于接收所述存证设备返回的存证回执;所述存证回执包含:所述第一数据串对应的存证时间;或者所述存证回执包含:所述存证时间、可信时间戳; a first receiving module, configured to receive a certificate receipt returned by the certificate storage device; the certificate receipt includes: a certificate time corresponding to the first data string; or the certificate receipt includes: the certificate Time, trusted timestamp;
存储模块,用于当所述存证回执包含所述存证时间时,将所述存证时间与所述创新创意数据关联存储;或者用于,当所述存证回执包含所述存证时间、所述可信时间戳时,将所述存证时间、所述创新创意数据、所述可信时间戳关联存储;a storage module, configured to associate the deposit time with the innovation creative data when the deposit receipt includes the deposit time; or for, when the deposit receipt includes the deposit time And storing the certificate time, the innovation creative data, and the trusted timestamp in association with the trusted timestamp;
所述存证时间是所述存证设备向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;所述可信时间戳是所述存证设备基于所述第一数据串、所述存证时间生成的唯一对应的第二数据串;且所述存证设备采用私钥对所述第二数据串进行数字签名后得到的。The depositing time is that the depositing device sends the first data string to the trusted time issuing device, so that the trusted time signing device is trusted according to the time when the first data string is received. The trusted timestamp is a unique second data string generated by the depositing device based on the first data string and the deposit time; and the depositing device uses the private key pair Two data strings are obtained after digital signature.
进一步地,还包括:Further, it also includes:
第二接收模块,用于接收企业创新创意技术文档;所述技术文档包含:技术文档内容信息、多种属性信息;a second receiving module, configured to receive an enterprise creative creative technical document; the technical document includes: technical document content information, and multiple attribute information;
归类模块,用于根据至少一种所述属性信息对接收到的所述技术文档进行归类,形成归类后的技术文档数据包;a categorization module, configured to classify the received technical documents according to the at least one attribute information, to form a classified technical document data package;
处理模块,用于当所述技术文档数据包满足企业预设存证条件时,对所述技术文档数据包进行数据处理得到所述创新创意数据。And a processing module, configured to perform data processing on the technical document data packet to obtain the innovative creative data when the technical document data package satisfies an enterprise preset depositing condition.
进一步地,所述属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息;Further, the attribute information includes one or more of the following items: a project ID, a technical document creator, a version number, a customer ID, a R&D department ID, and location information;
所述预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。The preset depositing conditions include: a preset depositing period, an item completion identifier, or a technical document security level.
进一步地,所述处理模块:具体用于根据预设数据格式和/或加密算法,对所述技术文档数据包进行数据处理得到创新创意数据;Further, the processing module is specifically configured to perform data processing on the technical document data packet according to a preset data format and/or an encryption algorithm to obtain innovative creative data;
所述存储模块,还用于将所述创新创意数据存储在所述企业客户端的本地数据库中。The storage module is further configured to store the innovative creative data in a local database of the enterprise client.
进一步地,所述发送模块,还用于向所述存证设备发送出证请求,所述出证请求包含:所述存证回执的标识信息;Further, the sending module is further configured to send a certificate issuing request to the certificate issuing device, where the certificate issuing request includes: identifier information of the certificate receipt receipt;
所述第一接收模块,还用于接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;The first receiving module is further configured to receive a certificate of deposit of the innovation creative data returned by the depositing device according to the identification information of the certificate receipt; the certificate of deposit includes: a certificate number, a certificate time ;
相应的, corresponding,
所述发送模块,还用于向所述存证设备发送第一验证请求,所述第一验证请求包含:所述证书编号,以使所述存证设备根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;The sending module is further configured to send a first verification request to the certificate storage device, where the first verification request includes: the certificate number, so that the certificate storage device checks whether the storage device has been stored according to the certificate number. a certificate of deposit corresponding to the certificate number;
所述第一接收模块,还用于接收所述存证设备根据所述证书编号查验后返回的所述存证证书。The first receiving module is further configured to receive the certificate of deposit returned by the depositing device after checking according to the certificate number.
进一步地,所述发送模块,还用于向所述存证设备发送所述创新创意数据的描述信息,以使所述存证设备将所述描述信息与所述第一数据串关联存储;Further, the sending module is further configured to send the description information of the innovation creative data to the certificate storage device, so that the certificate storage device associates the description information with the first data string;
相应的,所述发送模块发送的所述第一验证请求还包含:验证密码;Correspondingly, the first verification request sent by the sending module further includes: verifying a password;
所述第一接收模块,还用于接收所述存证设备根据所述验证密码查验通过后,反馈的所述创新创意数据的所述描述信息。The first receiving module is further configured to receive the description information of the innovative creative data that is sent back by the verification device after being verified by the verification password.
进一步地,所述发送模块,还用于向所述存证设备发送第二验证请求,所述第二验证请求包含:所述第一数据串;Further, the sending module is further configured to send a second verification request to the certificate storage device, where the second verification request includes: the first data string;
所述第一接收模块,还用于接收所述存证设备根据所述第一数据进行查验后返回的第一验证回执。The first receiving module is further configured to receive a first verification receipt returned by the depositing device after checking according to the first data.
进一步地,所述第一接收模块:具体用于当所述存证设备中没有存储所述第一数据串时,接收所述存证设备返回的未查到存证信息的响应消息;当所述存证设备中已存储所述第一数据串时,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。Further, the first receiving module is configured to: when the first data string is not stored in the certificate storage device, receive a response message returned by the certificate storage device that does not find the deposit certificate information; When the first data string has been stored in the depositing device, the response message of the verified certificate information returned by the certificate storage device and/or the certificate time information of the first data string is received.
进一步地,所述发送模块,还用于向所述存证设备发送第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;Further, the sending module is further configured to send a third verification request to the certificate storage device, where the third verification request includes: the first data string, a trusted timestamp;
所述第一接收模块,还用于接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执。The first receiving module is further configured to receive a second verification receipt returned by the verification device after checking according to the first data string and the trusted timestamp.
进一步地,所述第一接收模块:具体用于当所述存证设备中没有存储所述第一数据串时,接收所述存证设备返回的未查到存证信息的响应消息;当所述存证设备中已存储所述第一数据串,且所述存证设备基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第三数据串;并基于所述可信时间戳解密得到第四数据串;当所述第三数据串与所述第四数据串完全匹配时,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。 Further, the first receiving module is configured to: when the first data string is not stored in the certificate storage device, receive a response message returned by the certificate storage device that does not find the deposit certificate information; The first data string is stored in the storage device, and the certificate storage device generates a unique third data string based on the first data string and the certificate time of the first data string; Decoding the trusted timestamp to obtain a fourth data string; when the third data string and the fourth data string completely match, receiving a response message and/or a location of the verified certificate information returned by the certificate storage device The time of deposit of the first data string is described.
进一步地,所述发送模块,具体用于向存证设备发送带有第一CA认证信息的存证请求,所述第一CA认证信息包含:企业客户端的身份验证信息,以使所述存证设备根据所述第一CA认证信息,对所述企业客户端的身份进行验证。Further, the sending module is specifically configured to send, to the certificate storage device, a certificate request with the first CA authentication information, where the first CA authentication information includes: identity verification information of the enterprise client, so that the certificate is saved The device verifies the identity of the enterprise client according to the first CA authentication information.
进一步地,所述第二接收模块,具体用于接收带有第二CA认证信息的企业创新创意技术文档,所述第二CA认证信息包含:发送所述企业创新创意技术文档的发送方的身份验证信息以及所述发送方所归属的部门的身份验证信息;以使所述企业客户端根据所述第二CA认证信息,对所述企业创新创意技术文档的发送方的身份进行验证。Further, the second receiving module is specifically configured to receive an enterprise innovation creative technical document with second CA authentication information, where the second CA authentication information includes: sending an identity of a sender of the enterprise innovation creative technical document Verification information and identity verification information of the department to which the sender belongs; so that the enterprise client verifies the identity of the sender of the enterprise innovation creative technical document according to the second CA authentication information.
进一步地,所述发送模块,还用于向所述存证设备发送注册请求;Further, the sending module is further configured to send a registration request to the depositing device;
所述第一接收模块,还用于接收所述存证设备返回的算法生成器;所述算法生成器用于根据预设算法生成与所述创新创意数据唯一对应的所述第一数据串。The first receiving module is further configured to receive an algorithm generator returned by the certificate storage device, where the algorithm generator is configured to generate the first data string that uniquely corresponds to the innovation creative data according to a preset algorithm.
本发明还提供一种创新创意数据存证设备,包括:The invention also provides an innovative creative data storage device, comprising:
接收模块,用于接收企业客户端发送的存证请求,所述存证请求包含:第一数据串;所述第一数据串是所述企业客户端基于创新创意数据生成的唯一数据信息;a receiving module, configured to receive a certificate request sent by the enterprise client, where the certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data;
比对模块,用于比对存证数据库中是否已存储有所述第一数据串;a comparison module, configured to compare whether the first data string is already stored in the certificate database;
存证时间获取模块,用于当所述比对模块比对后发现所述存证数据库中没有存储有所述第一数据串时,则向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备签发所述第一数据串的存证时间;所述存证时间为所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;a certificate time obtaining module, configured to send the first data string to the trusted time signing device when the comparison module finds that the first data string is not stored in the certificate database, And causing the trusted time issuing device to issue a certificate time of the first data string; the certificate time is a credibility issued by the trusted time signing device based on the time when the first data string is received time;
数据串生成模块,用于基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第二数据串;a data string generating module, configured to generate a unique second data string based on the first data string and the certificate time of the first data string;
签名模块,用于采用私钥对所述第二数据串进行数字签名,得到与所述第一数据串对应的可信时间戳;a signature module, configured to digitally sign the second data string by using a private key, to obtain a trusted timestamp corresponding to the first data string;
存储模块,用于将所述第一数据串、所述第一数据串的存证时间、所述可信时间戳关联存储;a storage module, configured to store the first data string, the certificate time of the first data string, and the trusted timestamp;
发送模块,用于向所述企业客户端返回存证回执; a sending module, configured to return a deposit receipt to the enterprise client;
所述存证回执包含:所述第一数据串的存证时间,The deposit receipt includes: a time of deposit of the first data string,
或者包含:所述第一数据串的存证时间和所述可信时间戳。Or comprising: a certificate time of the first data string and the trusted timestamp.
进一步地,所述接收模块,还用于接收所述企业客户端发送的出证请求,所述出证请求包含:所述存证回执的标识信息;Further, the receiving module is further configured to receive a certificate request sent by the enterprise client, where the certificate request includes: identifier information of the certificate receipt;
所述发送模块,还用于根据所述存证回执的标识信息,向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;The sending module is further configured to: return, according to the identifier information of the certificate receipt, a certificate of the certificate of the creative creative data corresponding to the identifier information to the enterprise client; the certificate of deposit includes: a certificate Number, time of deposit;
相应的,所述接收模块,还用于接收所述企业客户端发送的第一验证请求,所述第一验证请求包含:所述证书编号;Correspondingly, the receiving module is further configured to receive a first verification request sent by the enterprise client, where the first verification request includes: the certificate number;
所述存证设备还包括:The depositing device further includes:
查验模块,用于根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;a checking module, configured to check, according to the certificate number, whether a certificate of deposit corresponding to the certificate number has been stored;
所述发送模块,还用于当所述查验模块查验到已存储与所述证书编号对应的存证证书时,发送所述存证证书。The sending module is further configured to: when the checking module detects that the certificate of deposit corresponding to the certificate number has been stored, send the certificate of deposit.
进一步地,所述接收模块,还用于接收所述企业客户端发送的所述创新创意数据的描述信息,将所述描述信息与所述第一数据串关联存储;Further, the receiving module is further configured to receive description information of the innovation creative data sent by the enterprise client, and associate the description information with the first data string;
相应的,所述接收模块接收到的所述第一验证请求还包含:验证密码;Correspondingly, the first verification request received by the receiving module further includes: verifying a password;
所述发送模块,还用于根据所述验证密码查验所述验证密码是否正确,若正确,向所述企业客户端反馈所述存证证书对应的描述信息。The sending module is further configured to check whether the verification password is correct according to the verification password, and if yes, feed back, to the enterprise client, description information corresponding to the certificate.
进一步地,所述描述信息包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息;Further, the description information includes: an item ID, a creator, a version number, a customer ID, a research and development department ID, or location information;
所述存证设备还包括:The depositing device further includes:
归类模块,用于根据至少一种所述描述信息对接收到的所述创新创意数据进行归类,形成所述创新创意数据的索引文档;以使所述企业客户端根据任一所述描述信息查找到对应的所述创新创意数据的归类信息。a categorization module, configured to classify the received innovation creative data according to at least one of the description information to form an index document of the innovation creative data; so that the enterprise client describes according to any description The information finds the categorization information of the corresponding innovative creative data.
进一步地,所述接收模块,还用于接收所述企业客户端发送的第二验证请求,所述第二验证请求包含:所述第一数据串;Further, the receiving module is further configured to receive a second verification request sent by the enterprise client, where the second verification request includes: the first data string;
所述查验模块,还用于在存证数据库中查验是否已存储所述第一数据串;The checking module is further configured to check, in the certificate database, whether the first data string has been stored;
所述发送模块,还用于根据所述查验模块查验后得到的查验结果返回第 一验证回执。The sending module is further configured to return according to the inspection result obtained after the inspection module checks A verification receipt.
进一步地,所述发送模块:具体用于当所述存证数据库中没有存储所述第一数据串时,向所述企业客户端返回未查到存证信息的响应消息;当所述存证数据库中已存储所述第一数据串时,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。Further, the sending module is configured to: when the first data string is not stored in the certificate database, return a response message to the enterprise client that does not find the deposit information; When the first data string has been stored in the database, the response message of the certificate storage information and/or the certificate time information of the first data string is returned to the enterprise client.
进一步地,所述接收模块,还用于接收所述企业客户端发送的第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;Further, the receiving module is further configured to receive a third verification request that is sent by the enterprise client, where the third verification request includes: the first data string, a trusted timestamp;
所述查验模块,还用于当存证数据库中已存储所述第一数据串时,根据所述第一数据串、所述可信时间戳进行验证,得到验证结果;The checking module is further configured to: when the first data string is stored in the certificate database, perform verification according to the first data string and the trusted timestamp, and obtain a verification result;
所述发送模块,还用于根据所述查验模块验证后得到的验证结果返回第二验证回执。The sending module is further configured to return a second verification receipt according to the verification result obtained after the verification module is verified.
进一步地,所述查验模块包括:Further, the verification module includes:
查找子模块,用于查找与所述第一数据串对应的存证时间;a searching submodule, configured to search for a deposit time corresponding to the first data string;
数据串生成子模块,用于根据所述第一数据串和所述存证时间生成唯一对应的第三数据串;a data string generation submodule, configured to generate a unique third data string according to the first data string and the certificate time;
解密子模块,用于对所述可信时间戳进行解密,得到第四数据串;a decryption submodule, configured to decrypt the trusted timestamp to obtain a fourth data string;
所述发送模块,还用于当所述数据串生成子模块生成的所述第三数据串与所述解密子模块解密后得到的所述第四数据串完全匹配时,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。The sending module is further configured to: when the third data string generated by the data string generating submodule completely matches the fourth data string obtained by decrypting the decrypting submodule, to the enterprise client Returning the response message for checking the deposit information and/or the deposit time information of the first data string.
进一步地,所述发送模块:具体用于向所述企业客户端返回带有CA认证信息的存证回执,以向所述企业客户端提供所述存证设备的身份验证信息。Further, the sending module is specifically configured to return a certificate receipt with CA authentication information to the enterprise client, to provide the enterprise client with the identity verification information of the certificate device.
进一步地,所述接收模块,还用于接收所述企业客户端发送的注册请求;Further, the receiving module is further configured to receive a registration request sent by the enterprise client;
所述发送模块,还用于返回用于生成所述第一数据串的算法生成器,以使所述企业客户端根据所述算法生成器提供的预设算法生成与所述创新创意数据唯一对应的所述第一数据串。The sending module is further configured to: return an algorithm generator for generating the first data string, so that the enterprise client generates a unique correspondence with the innovation creative data according to a preset algorithm provided by the algorithm generator The first data string.
本发明还提供一种创新创意数据处理系统,包括:本发明提供的创新创意数据处理装置;以及本发明提供的创新创意数据存证设备。The invention also provides an innovative creative data processing system, comprising: the innovative creative data processing device provided by the invention; and the innovative creative data storage device provided by the invention.
进一步地,所述系统还包括: Further, the system further includes:
可信时间签发设备,用于接收所述创新创意数据存证设备发送的所述第一数据串,基于接收到所述第一数据串的时间签发所述第一数据串的存证时间;将所述第一数据串的存证时间发送给所述创新创意数据存证设备。a trusted time issuing device, configured to receive the first data string sent by the innovative creative data storage device, and issue a time of depositing the first data string based on a time when the first data string is received; The certificate time of the first data string is sent to the innovative creative data storage device.
本发明提供的创新创意数据处理方法、装置、系统及存证设备,企业客户端基于创新创意数据生成与之唯一对应的第一数据串,并将该第一数据串发送给存证设备进行存证,得到存证设备返回的包含有该第一数据串对应的存证时间的存证回执,或者得到包含有存证时间和可信时间戳的存证回执;其中,存证时间是存证设备向可信时间签发设备发送第一数据串,由可信时间签发设备基于接收到第一数据串的时间所签发的可信时间;可信时间戳是存证设备基于第一数据串、存证时间生成的唯一对应的第二数据串;并由该存证设备采用私钥对第二数据串进行数字签名后得到的,以证明该存证设备的真实性及可信性。通过由可信时间源进行时间同步的可信时间签发设备签发可信存证时间,固化了企业的创新创意数据的存证时间;且该创新创意数据的存证过程是基于企业创新创意数据所对应的唯一数据串进行的,有效保证了企业创新创意数据原始内容的保密性;同时,存证过程是由与用户无利害关系的第三方来实现的,提高了企业创新创意数据原创性鉴证的公信力。The innovative creative data processing method, device, system and depositing device provided by the invention, the enterprise client generates a first data string corresponding to the unique creative data based on the innovative creative data, and sends the first data string to the depositing device for storage The certificate returns a certificate receipt containing the time of deposit corresponding to the first data string, or a certificate receipt containing the time of deposit and a trusted time stamp; wherein the time of deposit is a certificate The device sends a first data string to the trusted time signing device, and the trusted time signing device sends the trusted time according to the time when the first data string is received; the trusted time stamp is based on the first data string and the storage device The only corresponding second data string generated by the time is obtained by the certificate device by digitally signing the second data string with the private key to prove the authenticity and credibility of the certificate storage device. The credential time of the credential issuance device issued by the trusted time source for time synchronization is issued, which solidifies the time of depositing the innovative creative data of the enterprise; and the process of depositing the innovative creative data is based on the innovation and creative data of the enterprise. The corresponding unique data string is carried out to effectively guarantee the confidentiality of the original content of the enterprise's innovative creative data. At the same time, the depositing process is realized by a third party who has no interest in the user, and improves the originality verification of the enterprise's innovative creative data. Credibility.
附图说明DRAWINGS
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, a brief description of the drawings used in the embodiments or the prior art description will be briefly described below. Obviously, the drawings in the following description It is a certain embodiment of the present invention, and other drawings can be obtained from those skilled in the art without any inventive labor.
图1是根据一示例性实施例示出的一种创新创意数据处理方法的流程图;FIG. 1 is a flowchart of an innovative creative data processing method according to an exemplary embodiment;
图2是根据另一示例性实施例示出的一种创新创意数据处理方法的流程图;2 is a flow chart showing an innovative creative data processing method according to another exemplary embodiment;
图3是根据另一示例性实施例示出的一种创新创意数据处理方法的流程图;FIG. 3 is a flowchart of an innovative creative data processing method according to another exemplary embodiment; FIG.
图4是根据一示例性实施例示出的另一种创新创意数据处理方法的流 程图;FIG. 4 is a flow diagram of another innovative creative data processing method according to an exemplary embodiment. Cheng Tu
图5是根据一示例性实施例示出的一种创新创意数据处理装置的结构示意图;FIG. 5 is a schematic structural diagram of an innovative creative data processing apparatus according to an exemplary embodiment; FIG.
图6是根据另一示例性实施例示出的一种创新创意数据处理装置的结构示意图;FIG. 6 is a schematic structural diagram of an innovative creative data processing apparatus according to another exemplary embodiment; FIG.
图7是根据一示例性实施例示出的一种创新创意数据存证设备的结构示意图;FIG. 7 is a schematic structural diagram of an innovative creative data depositing device according to an exemplary embodiment; FIG.
图8是根据另一示例性实施例示出的一种创新创意数据存证设备的结构示意图;FIG. 8 is a schematic structural diagram of an innovative creative data depositing device according to another exemplary embodiment; FIG.
图9是根据一示例性实施例示出的一种创新创意数据处理系统的结构示意图;FIG. 9 is a schematic structural diagram of an innovative creative data processing system according to an exemplary embodiment; FIG.
图10是根据另一示例性实施例示出的一种创新创意数据处理系统结构示意图。FIG. 10 is a schematic structural diagram of an innovative creative data processing system according to another exemplary embodiment.
具体实施方式detailed description
为使本发明实施例的目的、技术方案和优点更加清楚,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。The technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. It is a partial embodiment of the invention, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
图1是根据一示例性实施例示出的一种创新创意数据处理方法的流程图。如图1所示,本实施例提供的创新创意数据处理方法适用于企业对任何创新创意的技术文档进行存证处理的过程,以保证企业创新创意技术成果的保密性和原创性。本实施例提供的创新创意数据处理方法可以基于创新创意数据处理系统实现,该系统包括具备创新创意数据处理功能的企业客户端、创新创意数据存证设备和可信时间签发设备,本实施例的方法可以通过企业客户端来执行,具体包括如下步骤:FIG. 1 is a flow chart showing an innovative creative data processing method according to an exemplary embodiment. As shown in FIG. 1 , the innovative creative data processing method provided by the embodiment is applicable to a process in which a company performs a certificate storage process on any innovative creative technical document to ensure the confidentiality and originality of the enterprise's innovative creative technology achievements. The innovative creative data processing method provided by this embodiment can be implemented based on an innovative creative data processing system, which includes an enterprise client with innovative creative data processing functions, an innovative creative data depositing device, and a trusted time issuing device, which is the embodiment of the present invention. The method can be executed by the enterprise client, and includes the following steps:
步骤A101、企业客户端根据创新创意数据,生成第一数据串。Step A101: The enterprise client generates a first data string according to the innovation creative data.
其中,第一数据串是与创新创意数据唯一对应的数据信息。The first data string is data information uniquely corresponding to the innovative creative data.
具体地,企业客户端可以为个人电脑、笔记本电脑、智能手机、平板电脑等具有处理单元的电子装置。企业客户端上设置有创新创意数据处理 客户端应用程序,该应用程序可以与企业的管理软件进行绑定或嵌入企业管理软件的各个节点中,从而使得企业管理软件中各个节点处所产生的创新创意数据可以自动生成与该创新创意数据对应第一数据串,并发送该第一数据串到存证设备中进行存证保护;此外,企业客户端也可以通过网页形式实现与存证设备的交互。创新创意数据可以为任何格式的电子数据,其内容可以是纯文本、图片、音视频、网页、短信、邮件等等,该创新创意数据可以存储在企业客户端中,可以为企业客户端从其他设备中获取的,也可以为企业客户端实时产生的数据,如正在拍摄的视频或照片、正在录制的音频等。Specifically, the enterprise client may be an electronic device having a processing unit such as a personal computer, a notebook computer, a smart phone, or a tablet computer. Innovative creative data processing on the corporate client a client application, which can be bound to the enterprise management software or embedded in each node of the enterprise management software, so that the innovative creative data generated at each node of the enterprise management software can be automatically generated and corresponding to the innovative creative data. The first data string is sent to the certificate storage device for certificate protection; in addition, the enterprise client can also implement interaction with the certificate storage device through the webpage form. Innovative creative data can be electronic data in any format, the content can be plain text, pictures, audio and video, web pages, text messages, emails, etc. The innovative creative data can be stored in the enterprise client, and can be used for enterprise clients from other The data obtained in the device can also be generated in real time by the enterprise client, such as the video or photo being taken, the audio being recorded, and the like.
步骤A102、向存证设备发送存证请求。Step A102: Send a deposit request to the depositing device.
其中,存证请求包含:与创新创意数据唯一对应的第一数据串。The certificate request includes: a first data string uniquely corresponding to the innovation creative data.
存证请求可以仅包含与创新创意数据唯一对应的第一数据串,也可以既包含创新创意数据本身,又包含基于该创新创意数据生成的第一数据串。对于企业来说,其在研发过程中产生的技术创新成果,不希望被第三方获取到,但同时又希望其技术创新成果能够由可信的第三方进行原创归属及原创时间的鉴证,则可以采取仅发送与创新创意数据唯一对应的第一数据串的存证方式;第一数据串是基于创新创意数据生成的,且与该创新创意数据唯一对应,这就使得第三方的存证设备无法获得创新创意数据的具体内容,但可以获得与该创新创意数据完全等价的第一数据串。第一数据串的生成可以由企业客户端安装由存证设备提供的算法生成器生成,也可以由企业客户端自行设置符合国际标准的算法模块生成。当然,企业客户端也可以将创新创意数据连同第一数据串一起发送给存证设备;或者仅将创新创意数据发送给存证设备,由存证设备对该创新创意数据进行处理生成第一数据串。以使其创新创意数据同时在第三方的存证设备上进行备份保护。其中,第一数据串的生成过程可以根据预设哈希算法,如信息摘要算法第五版(Message Digest Algorithm,简称MD5)或者安全散列算法(Secure Hash Algorithm,简称SHA)等,得到该创新创意数据的哈希值,即第一数据串。对于企业客户端将第一数据串和创新创意数据发送给第三方存证设备的情况,存证设备可以根据接收到的第一数据串对创新创意数据进行完整性验证,该完成性验证过程可以为,存证设备根据预设哈希算法对接收到的 创新创意数据进行处理得到验证值,该预设哈希算法与企业客户端生成第一数据串时所采用的预设哈希算法相同。通过哈希值对创新创意数据的完整性进行验证,如果该验证值与第一数据串相同,则验证成功,则将创新创意数据和第一数据串关联存储。若验证不成功,向企业客户端发送重传指示信息,以提示重新上传该创新创意数据。The deposit request may include only the first data string uniquely corresponding to the innovative creative data, or may include both the innovative creative data itself and the first data string generated based on the innovative creative data. For enterprises, the technological innovations they produce in the R&D process do not want to be acquired by third parties, but at the same time they hope that their technological innovations can be verified by original parties and original time by trusted third parties. Adopting a method of depositing only the first data string uniquely corresponding to the innovative creative data; the first data string is generated based on the innovative creative data and uniquely corresponding to the innovative creative data, which makes the third-party depositing device unable to Get the specific content of the innovative creative data, but get the first data string that is fully equivalent to the innovative creative data. The generation of the first data string may be generated by the enterprise client installation algorithm generator provided by the depositing device, or may be generated by the enterprise client setting an algorithm module conforming to international standards. Of course, the enterprise client can also send the innovative creative data together with the first data string to the depositing device; or only the innovative creative data is sent to the depositing device, and the innovative creative data is processed by the depositing device to generate the first data. string. In order to make its innovative creative data backup protection on third-party depository devices. The process of generating the first data string may be obtained according to a preset hash algorithm, such as a Message Digest Algorithm (MD5) or a Secure Hash Algorithm (SHA). The hash of the creative data, the first data string. For the case where the enterprise client sends the first data string and the innovative creative data to the third-party certificate storage device, the certificate storage device can perform integrity verification on the innovation creative data according to the received first data string, and the completion verification process can The received device is received according to a preset hash algorithm. The innovative creative data is processed to obtain a verification value, and the preset hash algorithm is the same as the preset hash algorithm used by the enterprise client to generate the first data string. The integrity of the innovative creative data is verified by the hash value. If the verification value is the same as the first data string, if the verification is successful, the creative creative data is stored in association with the first data string. If the verification is unsuccessful, a retransmission indication message is sent to the enterprise client to prompt to re-upload the innovative creative data.
步骤A103、接收存证设备返回的存证回执。Step A103: Receive a certificate receipt returned by the depositing device.
其中,存证回执包含:第一数据串对应的存证时间;或者存证回执包含:存证时间、可信时间戳。存证时间是存证设备向可信时间签发设备发送第一数据串,可信时间签发设备基于接收到第一数据串的时间签发的可信时间信息;可信时间戳是存证设备基于第一数据串、存证时间生成的唯一对应的第二数据串;且存证设备采用私钥对该第二数据串进行数字签名后得到的。存证设备在接收到企业客户端发送的第一数据串后,将该第一数据串与自身存证数据库中已存储的数据串进行比对,若没有存储过该第一数据串,则向可信时间签发设备发送该第一数据串,以使可信时间签发设备签发第一数据串的存证时间。可信时间签发设备的时间是与可信时间源同步的,可信时间源可以包括:授时中心发布的用于标识可信时间的长波信号或者卫星信号;或者,可信时间授权机构发布的可信时间;或者,符合相关标准要求的硬件系统提供的可信时间,例如原子钟,能够确保可信时间源所同步的时间是可信的、可审计的即可,其实现形式不以本实施例为限。存证时间是该可信时间签发设备基于接收到第一数据串的时间所签发的可信时间,且该可信时间中可以包含该可信时间签发设备的数字签名,以证明该可信时间签发设备的可信性。同样的,存证设备向企业客户端返回的可信时间戳中也包含有存证设备的数字签名信息,其具体实现是通过基于第一数据串和存证时间信息,生成唯一对应的第二数据串,并采用存证设备的私钥对第二数据串进行数字签名后得到的。该数字签名处理过程可以采用RSA、ElGamal、Fiat-Shamir、Guillou-Quisquarter、Schnorr、Ong-Schnorr-Shamir数字签名算法、Des/DSA、椭圆曲线数字签名算法和有限自动机数字签名算法等来实现。企业客户端可以通过存证设备的公钥对第二数据串的数字签名进行验证,以证明该可信时间戳是可信性,保证可信时间戳在传输过程中的真实性、安全性。由此,使得存证的创新创 意数据是可追溯的、可审计的、未被篡改的。用户使用该存证的创新创意数据作为电子证据是可以被采信的。The certificate receipt includes: a certificate time corresponding to the first data string; or the certificate receipt includes: a certificate time and a trusted time stamp. The credential time is that the depositing device sends the first data string to the trusted time issuing device, and the trusted time signing device sends the trusted time information based on the time when the first data string is received; the trusted time stamp is based on the a data string, a unique corresponding second data string generated by the certificate time; and the certificate device obtains the digital data signature by using the private key. After receiving the first data string sent by the enterprise client, the certificate storage device compares the first data string with the stored data string in the own certificate database, and if the first data string is not stored, The trusted time signing device sends the first data string to enable the trusted time signing device to issue the first data string. The trusted time is synchronized with the trusted time source. The trusted time source may include: a long-wave signal or a satellite signal issued by the timing center for identifying the trusted time; or a trusted time authority may issue Trust time; or, the trusted time provided by the hardware system that meets the requirements of the relevant standards, such as an atomic clock, can ensure that the time synchronized by the trusted time source is credible and auditable, and the implementation form is not in this embodiment. Limited. The credential time is a trusted time that the trusted time signing device issues based on the time when the first data string is received, and the trusted time may include a digital signature of the trusted time signing device to prove the trusted time. The credibility of the issuing device. Similarly, the trusted timestamp returned by the certificate storage device to the enterprise client also includes the digital signature information of the certificate storage device, and the specific implementation is to generate a unique corresponding second by using the first data string and the certificate time information. The data string is obtained by digitally signing the second data string with the private key of the certificate device. The digital signature processing process can be implemented by using RSA, ElGamal, Fiat-Shamir, Guillou-Quisquarter, Schnorr, Ong-Schnorr-Shamir digital signature algorithm, Des/DSA, elliptic curve digital signature algorithm, and finite automaton digital signature algorithm. The enterprise client can verify the digital signature of the second data string by using the public key of the certificate device to prove that the trusted timestamp is credible and ensure the authenticity and security of the trusted timestamp in the transmission process. Thus, the innovation of the deposit The data is traceable, auditable, and not tampered with. The user can use the innovative creative data of the deposit as electronic evidence.
步骤A104、企业客户端将存证时间与创新创意数据关联存储;或者将存证时间、创新创意数据、可信时间戳关联存储。Step A104: The enterprise client associates the deposit time with the innovation creative data; or stores the deposit time, the innovation creative data, and the trusted time stamp.
本实施例提供的创新创意数据处理方法,企业客户端基于创新创意数据生成与之唯一对应的第一数据串,并将该第一数据串发送给存证设备进行存证,得到存证设备返回的包含有该第一数据串对应的存证时间的存证回执,或者得到包含有存证时间和可信时间戳的存证回执;其中,存证时间是存证设备向可信时间签发设备发送第一数据串,由可信时间签发设备基于接收到第一数据串的时间所签发的可信时间;可信时间戳是存证设备基于第一数据串、存证时间生成的唯一对应的第二数据串;并由该存证设备采用私钥对第二数据串进行数字签名后得到的,以证明该存证设备的真实性及可信性。通过由可信时间源进行时间同步的可信时间签发设备签发可信存证时间,固化了企业的创新创意数据的存证时间;且该创新创意数据的存证过程是基于企业创新创意数据所对应的唯一数据串进行的,有效保证了企业创新创意数据原始内容的保密性;同时,存证过程是由与用户无利害关系的第三方来实现的,提高了企业创新创意数据原创性鉴证的公信力。In the innovative creative data processing method provided by the embodiment, the enterprise client generates a first data string corresponding to the unique data based on the innovation creative data, and sends the first data string to the depositing device for verification, and obtains the certificate device return. a certificate receipt containing the certificate time corresponding to the first data string, or a certificate receipt containing the certificate time and the trusted time stamp; wherein the certificate time is the certificate issuing device issues the device to the trusted time Transmitting a first data string, the trusted time issued by the trusted time signing device based on the time when the first data string is received; the trusted timestamp is a unique correspondence generated by the depositing device based on the first data string and the certificate time The second data string is obtained by the certificate device using the private key to digitally sign the second data string to prove the authenticity and credibility of the certificate storage device. The credential time of the credential issuance device issued by the trusted time source for time synchronization is issued, which solidifies the time of depositing the innovative creative data of the enterprise; and the process of depositing the innovative creative data is based on the innovation and creative data of the enterprise. The corresponding unique data string is carried out to effectively guarantee the confidentiality of the original content of the enterprise's innovative creative data. At the same time, the depositing process is realized by a third party who has no interest in the user, and improves the originality verification of the enterprise's innovative creative data. Credibility.
图2是根据另一示例性实施例示出的一种创新创意数据处理方法的流程图。如图2所示,在上述实施例的基础上,进一步地,步骤A101、企业客户端根据创新创意数据,生成第一数据串之前,还可以包括:2 is a flow chart of an innovative creative data processing method, according to another exemplary embodiment. As shown in FIG. 2, on the basis of the foregoing embodiment, further, the step A101, before the enterprise client generates the first data string according to the innovation creative data, may further include:
A201、接收企业创新创意技术文档。A201. Receive corporate innovation and technical documentation.
其中,技术文档包含:技术文档内容信息、多种属性信息。Among them, the technical documents include: technical document content information, a variety of attribute information.
企业创新创意技术文档可以是基于企业标准作业程序SOP架构所产生的文档。通过在企业客户端上安装创新创意数据处理应用程序,该应用程序与企业的SOP架构的管理软件进行绑定或嵌入企业SOP架构的管理软件的各个节点中,从而使得各个节点处接收到的企业创新创意技术文档通过应用接口与第三方存证设备自动链接,从而及时有效地对企业随时随刻产生的创新创意技术文档进行存证保护。The enterprise innovation creative technical documentation can be based on the documentation generated by the enterprise standard operating procedure SOP architecture. By installing an innovative creative data processing application on the enterprise client, the application is bound to the enterprise SOP architecture management software or embedded in each node of the enterprise SOP architecture management software, so that the enterprise received at each node The innovative creative technical documents are automatically linked with the third-party depository devices through the application interface, so as to timely and effectively protect and protect the innovative creative technical documents generated by the enterprise at any time.
A202、根据至少一种属性信息对接收到的技术文档进行归类,形成归类 后的技术文档数据包。A202. Classify the received technical documents according to at least one attribute information to form a classification. After the technical documentation package.
其中,属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息。企业的技术文档通常是以项目ID进行分类的,一个项目下可以包含多个技术文档,当项目完成后,可以根据项目ID对不同项目内的文档进行打包处理;得到归类后的技术文档数据包。其中项目ID内还可以包含不同时期研发的版本分类号等;此外,还可以以企业所服务的客户对象进行分类,还可以以不同的研发人员、研发部门、研发地点等进行分类,具体的属性信息可以根据企业内实际应用场景和需求进行限定,本申请对此不作限定。The attribute information includes one or more of the following: a project ID, a technical document creator, a version number, a customer ID, a research and development department ID, and a location information. The technical documents of an enterprise are usually classified by project ID. A project can contain multiple technical documents. When the project is completed, the documents in different projects can be packaged according to the project ID; the classified technical document data is obtained. package. The project ID may also include the version number of the version developed in different periods; in addition, it may be classified by the client object served by the enterprise, and may also be classified by different R&D personnel, R&D department, R&D site, etc., specific attributes. The information may be limited according to the actual application scenarios and requirements in the enterprise, which is not limited in this application.
A203、当技术文档数据包满足企业预设存证条件时,对技术文档数据包进行数据处理得到创新创意数据。A203. When the technical document data package satisfies the enterprise preset deposit certificate condition, the technical document data packet is processed by the data to obtain innovative creative data.
其中,预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。通过在企业客户端上安装创新创意数据处理应用程序,并在该应用程序中进行预设存证条件的设定,可以实现技术文档数据包在满足企业预设存证条件时,自动与第三方存证设备进行存证的操作处理。例如,对于保密等级高的技术文档,一旦企业客户端的管理软件接收到该等级的技术文档,立刻触发存证程序,以及时对保密等级高的技术文档进行原创性保护;或当项目完结时,将该项目内的技术文档打包后进行存证等。The preset depositing conditions include: a preset depositing period, a project completion identifier, or a technical document security level. By installing an innovative creative data processing application on the enterprise client and setting the default deposit conditions in the application, the technical document data package can be automatically combined with the third party when the enterprise presets the deposit condition. The certificate storage device performs the operation processing of the deposit certificate. For example, for a technical document with a high level of confidentiality, once the management software of the enterprise client receives the technical document of the level, the depositing program is triggered immediately, and the technical document with high security level is protected in an original manner; or when the project is finished, Package the technical documents in the project and then deposit the certificates.
进一步地,对技术文档数据包进行数据处理得到创新创意数据具体可以包括:根据预设数据格式和/或加密算法,对技术文档数据包进行数据处理。Further, the data processing of the technical document data packet to obtain the innovative creative data may include: performing data processing on the technical document data packet according to the preset data format and/or the encryption algorithm.
在形成待存证的创新创意数据前,企业客户端可以对不同格式的技术文档数据包进行数据格式和/或加密算法的数据处理,得到规范格式或以规范加密算法进行处理后的规范的创新创意数据。由于企业通常希望可以将创新创意数据保留在企业内部,仅将基于创新创意数据生成的第一数据串发送到第三方存证设备进行存证保护,且创新创意数据与该第一数据串是唯一对应的关系,若该创新创意数据发生了任何变更,则之前生成的第一数据串将不再与变更后的创新创意数据存在对应关系,因此,企业需要对存证的创新创意数据进行完整的保护,使其内容不被篡改,可以采用上述根据预设数据格式和/或加密算法,对技术文档数据包进行数据处理,然后将处理后的创新创意 数据进行本地保存或异地数据库保存,以保证在第三方存证设备中的第一数据串与该创新创意数据的对应关系不变。Before forming the innovative creative data to be deposited, the enterprise client can perform data processing on the data format and/or encryption algorithm of the technical document data packets of different formats, and obtain the normative format or the innovation of the specification after processing the standard encryption algorithm. Creative data. Since the enterprise usually hopes to keep the innovative creative data inside the enterprise, only the first data string generated based on the innovative creative data is sent to the third-party certificate device for certificate protection, and the innovative creative data and the first data string are unique. Corresponding relationship, if any changes are made to the innovative creative data, the previously generated first data string will no longer correspond to the changed creative creative data. Therefore, the enterprise needs to complete the creative creative data of the deposit. Protection, so that its content is not tampered with, you can use the above-mentioned data format according to the preset data format and / or encryption algorithm to process the technical document data packet, and then the innovative ideas after processing The data is saved locally or stored in an off-site database to ensure that the correspondence between the first data string in the third-party certificate device and the innovative creative data remains unchanged.
进一步地,步骤A203之后,还可以包括:将创新创意数据存储在企业客户端的本地数据库中。Further, after step A203, the method further includes: storing the creative creative data in a local database of the enterprise client.
图3是根据另一示例性实施例示出的一种创新创意数据处理方法的流程图。如图3所示,在上述实施例的基础上,进一步地,步骤A103、接收存证设备返回的存证回执之后,还可以包括:FIG. 3 is a flowchart of an innovative creative data processing method according to another exemplary embodiment. As shown in FIG. 3, on the basis of the foregoing embodiment, further, after receiving the certificate receipt returned by the depositing device, the step A103 may further include:
步骤A301、向存证设备发送出证请求。Step A301: Send a certificate request to the depositing device.
其中,出证请求包含:存证回执的标识信息。存证回执中所包含的信息相对简单,仅作为通知企业客户端,其创新创意数据已于什么时间进行了存证。若企业客户端需要电子或纸质的存证证书,还需要向存证设备发送出证请求,以获得存证证书。The certificate request includes: identification information of the certificate receipt. The information contained in the deposit receipt is relatively simple, only as a notification to the enterprise client, when the creative creative data has been verified. If the enterprise client needs an electronic or paper certificate, it also needs to send a certificate request to the card-issuing device to obtain a certificate of deposit.
步骤A302、接收存证设备根据存证回执的标识信息返回的创新创意数据的存证证书。Step A302: Receive a certificate of deposit of the innovative creative data returned by the depositing device according to the identification information of the certificate receipt.
其中,存证证书包含:证书编号、存证时间。存证证书上还可以记录有第一数据串,存证企业的名称以及可信时间戳,以证明什么企业在什么时间完成了什么电子数据的存证。Among them, the certificate of deposit includes: the certificate number and the time of deposit. The certificate of deposit can also record the first data string, the name of the depositing company and the trusted timestamp to prove what enterprise has completed the electronic data storage at what time.
进一步地,步骤A302之后,还可以包括:Further, after step A302, the method may further include:
步骤A303、向存证设备发送第一验证请求。若存证设备中存储有与第一验证请求中的证书编号对应的存证证书,执行步骤A304;若存证设备中没有存储与第一验证请求中的证书编号对应的存证证书,执行步骤A305。Step A303: Send a first verification request to the depositing device. If the certificate card corresponding to the certificate number in the first verification request is stored in the certificate storage device, step A304 is performed; if the certificate card corresponding to the certificate number in the first verification request is not stored in the certificate storage device, the step is performed. A305.
其中,第一验证请求包含:证书编号,以使存证设备根据证书编号查验是否已存储与证书编号对应的存证证书。The first verification request includes: a certificate number, so that the certificate storage device checks whether the certificate certificate corresponding to the certificate number has been stored according to the certificate number.
步骤A304、接收存证设备根据证书编号查验后返回的存证证书。Step A304: Receive a certificate of deposit returned after the certificate storage device checks according to the certificate number.
步骤A305、接收存证设备发送的未查询到与该证书编号对应的存证证书的响应消息。Step A305: Receive a response message sent by the certificate storage device that does not query the certificate of the certificate corresponding to the certificate number.
进一步地,在上述实施例的基础上,企业客户端还可以向存证设备发送创新创意数据的描述信息,以使存证设备将描述信息与第一数据串关联存储。Further, on the basis of the foregoing embodiment, the enterprise client may further send description information of the innovation creative data to the certificate storage device, so that the certificate storage device stores the description information in association with the first data string.
根据实际应用场景需要,企业客户端还可以将企业信息、创新创意数 据的创作者信息、设备信息、上传时间、地点信息、研发部门、项目简介、研发成员等有关该创新创意数据的自描述信息等发送给存证设备,以便对第一数据串和/或创新创意数据进行管理。According to the actual application scenario, the enterprise client can also add enterprise information and creative ideas. According to the creator information, equipment information, upload time, location information, research and development department, project profile, research and development members, and other self-description information about the innovative creative data, etc. are sent to the depository device for the first data string and/or innovation Creative data management.
相应的,步骤A303、向存证设备发送第一验证请求,第一验证请求还可以包含:验证密码;则该方法还包括:接收存证设备根据验证密码查验通过后,反馈的创新创意数据的描述信息。从而使得该第一验证请求的发送方可以获得与该创新创意数据关联的更加丰富的存证信息。Correspondingly, in step A303, the first verification request is sent to the certificate storage device, and the first verification request may further include: verifying the password; and the method further comprises: receiving the innovative creative data fed back by the verification device after the verification password is passed. Description. Thereby, the sender of the first verification request can obtain richer deposit information associated with the innovative creative data.
进一步地,对存证的创新创意数据进行验证的方式除了上述实施例中根据证书编号获取对应的存证证书之外,还可以通过步骤A101、企业客户端根据创新创意数据,生成第一数据串之后,向存证设备发送第二验证请求,其中,第二验证请求包含:第一数据串;接收存证设备根据该第一数据串进行查验后返回的第一验证回执。Further, in addition to obtaining the corresponding certificate of deposit according to the certificate number in the above embodiment, in addition to the above-mentioned embodiment, the first data string may be generated according to the innovation creative data by the enterprise client. Then, the second verification request is sent to the certificate storage device, where the second verification request includes: a first data string; and a first verification receipt returned by the verification device after checking according to the first data string.
进一步地,接收存证设备根据该第一数据串进行查验后返回的第一验证回执具体可以包括:若存证设备中没有存储第一数据串,接收存证设备返回的未查到存证信息的响应消息;若存证设备中已存储第一数据串,接收存证设备返回的查到存证信息的响应消息和/或第一数据串的存证时间信息。Further, the receiving the first verification receipt returned by the verification device according to the first data string may further include: if the first data string is not stored in the certificate storage device, receiving the unchecked certificate information returned by the certificate storage device The response message; if the first data string has been stored in the certificate storage device, receiving the response message of the certificate storage information returned by the certificate storage device and/or the certificate time information of the first data string.
进一步地,对存证的创新创意数据进行验证的方式还可以通过步骤A101、企业客户端根据创新创意数据,生成第一数据串之后,向所述存证设备发送第三验证请求,其中,第三验证请求包含:第一数据串、可信时间戳;若存证数据库中已存储第一数据串,接收存证设备根据第一数据串和可信时间戳进行查验后返回的第二验证回执。Further, the method for verifying the creative creative data of the deposited certificate may further generate a third verification request to the certificate storage device after the first data string is generated according to the innovation creative data in step A101, where The third verification request includes: a first data string, a trusted timestamp; if the first data string is stored in the certificate database, the second verification receipt returned by the receiving certificate device after checking according to the first data string and the trusted timestamp .
进一步地,接收存证设备根据第一数据串和可信时间戳进行查验后返回的第二验证回执具体可以包括:若存证设备基于该第一数据串、该第一数据串的存证时间生成唯一对应的第三数据串;并基于可信时间戳解密得到第四数据串;且第三数据串与第四数据串完全匹配,则接收存证设备返回的查到存证信息的响应消息和/或第一数据串的存证时间信息。Further, the receiving, by the verification device, the second verification receipt returned after checking according to the first data string and the trusted timestamp may include: if the certificate storage device is based on the first data string, the time of depositing the first data string Generating a unique third data string; and decrypting the fourth data string based on the trusted time stamp; and the third data string and the fourth data string completely match, receiving the response message of the verified information returned by the certificate device And/or the time of deposit of the first data string.
具体的实现过程为,存证设备接收到验证请求后,在存证数据库中查找是否之前存储有相同的第一数据串,若存在,找到第一数据串的固化存证时间,并基于存证时间和第一数据串一起生成唯一对应的第三数据串;存证设备再根据接收到的可信时间戳,采用自身的私钥对可信时间戳进行解密,若 可以解密说明该时间戳是由该存证设备发出的,解密后得到第四数据串,若第三和第四数据串一致,则说明第三验证请求中的第一数据串和可信时间戳是对应的,若不一致则说明第一数据串和可信时间戳是不对应的。The specific implementation process is: after receiving the verification request, the certificate storage device searches whether the same first data string is stored in the certificate database, and if so, finds the curing time of the first data string, and based on the certificate The time and the first data string together generate a unique corresponding third data string; the certificate storage device decrypts the trusted timestamp by using its own private key according to the received trusted timestamp, if The decryption indicates that the timestamp is sent by the certificate storage device, and after decryption, the fourth data string is obtained. If the third and fourth data strings are consistent, the first data string and the trusted timestamp in the third verification request are indicated. Corresponding. If they are inconsistent, the first data string and the trusted timestamp are not corresponding.
进一步地,企业客户端、存证设备在进行创新创意数据的存证、验证之前都可以通过数字证书认证机构,如CA可信鉴定机构进行实体认证后,申请其各自的数字证书以实现对发送信息的数字签名,对于通过实体认证的企业客户端来说,上述步骤向存证设备发送存证请求,可以包括:向存证设备发送带有第一CA认证信息的存证请求,其中,第一CA认证信息包含:企业客户端的身份验证信息,以使存证设备根据第一CA认证信息,对企业客户端的身份进行验证。表明发送该存证请求的企业客户端的身份,且保证该存证请求在传输过程中未被篡改。Further, before the enterprise client and the certificate storage device perform the verification and verification of the innovative creative data, the digital certificate certification institution, such as the CA credible authentication institution, can apply for its own digital certificate to realize the transmission. The digital signature of the information, for the enterprise client that is authenticated by the entity, the foregoing step of sending the deposit request to the depositing device may include: sending a deposit request with the first CA authentication information to the depositing device, wherein, The CA authentication information includes: authentication information of the enterprise client, so that the certificate storage device verifies the identity of the enterprise client according to the first CA authentication information. Indicates the identity of the enterprise client that sent the certificate request, and guarantees that the certificate request has not been tampered with during transmission.
进一步地,对于企业客户端从各个技术文档创建人或技术文档发送者那里接收到的技术文档也可以是附加了CA认证信息的技术文档。具体的,上述步骤接收企业创新创意技术文档,可以包括:接收带有第二CA认证信息的企业创新创意技术文档,其中,第二CA认证信息包含:发送企业创新创意技术文档的发送方的身份验证信息以及发送方所归属的部门的身份验证信息;以使企业客户端根据第二CA认证信息,对企业创新创意技术文档的发送方的身份进行验证。为了保证企业技术文档、技术秘密的保密性,保证文档在传输过程中是安全的,没有被篡改过的,可以对企业内部的各个发明人,即技术文档的创建人进行个人身份认证,并对发送方所归属的部门进行身份认证,并将发明人个人认证信息绑定部门身份认证信息形成第二CA认证信息,具体可以由CA认证机构颁发数字证书作为该第二CA认证信息的电子证明文档。其中,该身份验证信息必须是由权威公正的第三方CA认证机构颁发的一种权威性的电子文档,即数字证书作为身份验证信息。按照存储介质的不同,数字证书可以为硬证书(介质证书),通过硬件安全介质(如UKEY)固化存放;也可以是以电子文件形式存放的软证书,软证书无需数字证书介质,可以在任何电脑上进行操作,只需下载导入即可使用。数字证书中包含有发明人个人的认证信息以及发明人所归属部门的实体认证信息。从而提供在Internet上进行身份验证,证明自己的身份和识别对方的身份。Further, the technical document received by the enterprise client from each technical document creator or technical document sender may also be a technical document to which the CA authentication information is attached. Specifically, the foregoing step of receiving the enterprise innovation creative technical document may include: receiving an enterprise innovation creative technical document with the second CA authentication information, where the second CA authentication information includes: sending the identity of the sender of the enterprise innovation creative technical document Verification information and authentication information of the department to which the sender belongs; so that the enterprise client verifies the identity of the sender of the enterprise innovation creative technical document according to the second CA authentication information. In order to ensure the confidentiality of the technical documents and technical secrets of the enterprise and ensure that the documents are safe in the transmission process and have not been tampered with, the individual inventors within the enterprise, that is, the creators of the technical documents, can be authenticated personally. The department to which the sender belongs belongs to the identity authentication, and the inventor's personal authentication information is bound to the department identity authentication information to form the second CA authentication information, and the CA certificate authority may issue the digital certificate as the electronic certification document of the second CA authentication information. . The authentication information must be an authoritative electronic document issued by an authoritative and impartial third-party CA certification authority, that is, a digital certificate as the authentication information. According to different storage media, the digital certificate can be a hard certificate (media certificate), and can be stored by hardware security media (such as UKEY). It can also be a soft certificate stored in the form of an electronic file. The soft certificate does not need a digital certificate medium. To operate on your computer, just download and import to use. The digital certificate contains the personal identification information of the inventor and the entity authentication information of the department to which the inventor belongs. This provides authentication on the Internet, proving your identity and identifying each other's identity.
进一步地,企业客户端可以安装算法生成器插件,从而利用该插件生 成基于创新创意数据的第一数据串,其中算法生成器插件可以通过如下过程获得,企业客户端根据创新创意数据,生成第一数据串之前,向存证设备发送注册请求;接收存证设备返回的算法生成器;该算法生成器用于根据预设算法生成与创新创意数据唯一对应的第一数据串。预设算法可以为预设哈希算法,如信息摘要算法第五版(Message Digest Algorithm,简称MD5)或者安全散列算法(Secure Hash Algorithm,简称SHA)等,得到创新创意数据的哈希值,即该第一数据串。Further, the enterprise client can install an algorithm generator plugin to utilize the plugin to generate The first data string is based on the innovative creative data, wherein the algorithm generator plug-in can be obtained by the following process: the enterprise client sends a registration request to the depositing device before generating the first data string according to the innovative creative data; receiving the depositing device returns An algorithm generator for generating a first data string uniquely corresponding to the innovation creative data according to a preset algorithm. The preset algorithm may be a preset hash algorithm, such as a Message Digest Algorithm (MD5) or a Secure Hash Algorithm (SHA), to obtain a hash value of the innovative creative data. That is, the first data string.
图4是根据一示例性实施例示出的另一种创新创意数据处理方法的流程图。如图4所示,本实施例提供的创新创意数据处理方法具体可以通过创新创意数据存证设备来执行,可与应用于企业客户端的方法配合实现,其具体实现过程参照上述实施例的描述,在此不再赘述。4 is a flow chart of another innovative creative data processing method, according to an exemplary embodiment. As shown in FIG. 4, the innovative creative data processing method provided in this embodiment may be specifically implemented by using an innovative creative data storage device, and may be implemented in conjunction with a method applied to an enterprise client, and the specific implementation process is described with reference to the foregoing embodiment. I will not repeat them here.
本实施例提供的电子数据的处理方法,具体包括:The method for processing electronic data provided in this embodiment specifically includes:
步骤B101、存证设备接收企业客户端发送的存证请求。Step B101: The depositing device receives the deposit request sent by the enterprise client.
其中,存证请求包含:第一数据串;第一数据串是企业客户端基于创新创意数据生成的唯一数据信息。The certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data.
步骤B102、比对存证数据库中是否已存储有第一数据串。Step B102: Align whether the first data string is stored in the certificate database.
步骤B103、若存证数据库中未存储有第一数据串,向可信时间签发设备发送该第一数据串,以使可信时间签发设备签发该第一数据串的存证时间。Step B103: If the first data string is not stored in the certificate database, send the first data string to the trusted time signing device, so that the trusted time signing device issues the time of depositing the first data string.
其中,存证时间为可信时间签发设备基于接收到第一数据串的时间所签发的可信时间。The certificate time is a trusted time that the trusted time signing device issues based on the time when the first data string is received.
步骤B104、基于第一数据串、第一数据串的存证时间生成唯一对应的第二数据串。Step B104: Generate a unique corresponding second data string based on the first data string and the certificate time of the first data string.
步骤B105、采用私钥对第二数据串进行数字签名,得到与第一数据串对应的可信时间戳。Step B105: Digitally sign the second data string by using a private key to obtain a trusted timestamp corresponding to the first data string.
步骤B106、将第一数据串、第一数据串的存证时间、可信时间戳关联存储。Step B106: Store the first data string, the certificate time of the first data string, and the trusted timestamp.
步骤B107、向企业客户端返回存证回执。Step B107: Returning a deposit receipt to the enterprise client.
其中,存证回执包含:第一数据串的存证时间;或者包含:第一数据串的存证时间和可信时间戳。The certificate receipt includes: a certificate time of the first data string; or: a certificate time and a trusted time stamp of the first data string.
本实施例提供的创新创意数据处理方法,存证设备接收企业客户端发 送的包含第一数据串的存证请求,该第一数据串是企业客户端基于创新创意数据生成的唯一数据信息;若存证数据库没有存储过该第一数据串,则向可信时间签发设备发送第一数据串,以使可信时间签发设备基于接收到该第一数据串的时间签发可信的存证时间;存证设备基于第一数据串、第一数据串的存证时间生成唯一对应的第二数据串;并采用私钥对该第二数据串进行数字签名,得到可信时间戳;以证明该存证设备的真实性及可信性。并向企业客户端返回包含第一数据串存证时间的存证回执,或者包含:第一数据串的存证时间和可信时间戳的存证回执。通过由可信时间源进行时间同步的可信时间签发设备签发可信存证时间,固化了企业的创新创意数据的存证时间;且该创新创意数据的存证过程是基于企业创新创意数据所对应的唯一数据串进行的,有效保证了企业创新创意数据原始内容的保密性;同时,存证过程是由与用户无利害关系的第三方来实现的,提高了企业创新创意数据原创性鉴证的公信力。基于上述实施例,进一步地,该方法还包括如下步骤:The innovative creative data processing method provided by the embodiment, the depositing device receives the enterprise client Sending a deposit request containing the first data string, the first data string is unique data information generated by the enterprise client based on the innovation creative data; if the certificate database does not store the first data string, the certificate is issued to the trusted time The device sends the first data string, so that the trusted time signing device issues a trusted certificate time based on the time when the first data string is received; the certificate storage device generates the certificate time based on the first data string and the first data string. The only corresponding second data string; and the second data string is digitally signed by the private key to obtain a trusted time stamp; to prove the authenticity and credibility of the certificate storage device. And returning the certificate receipt containing the first data string deposit time to the enterprise client, or including: the deposit time of the first data string and the certificate receipt of the trusted time stamp. The credential time of the credential issuance device issued by the trusted time source for time synchronization is issued, which solidifies the time of depositing the innovative creative data of the enterprise; and the process of depositing the innovative creative data is based on the innovation and creative data of the enterprise. The corresponding unique data string is carried out to effectively guarantee the confidentiality of the original content of the enterprise's innovative creative data. At the same time, the depositing process is realized by a third party who has no interest in the user, and improves the originality verification of the enterprise's innovative creative data. Credibility. Based on the foregoing embodiment, the method further includes the following steps:
接收企业客户端发送的出证请求,出证请求包含:存证回执的标识信息;根据存证回执的标识信息,向企业客户端返回与标识信息对应的创新创意数据的存证证书;存证证书包含:证书编号、存证时间;Receiving a certificate issuing request sent by the enterprise client, the certificate issuing request includes: identification information of the certificate receipt receipt; and returning the certificate of the creative creative data corresponding to the identification information to the enterprise client according to the identification information of the certificate receipt receipt; The certificate includes: certificate number and time of deposit;
进一步地,存证设备还可以提供多种对创新创意数据的验证方式:Further, the certificate storage device can also provide a variety of ways to verify innovative creative data:
第一种验证方式,向企业客户端返回与标识信息对应的创新创意数据的存证证书之后,接收企业客户端发送的第一验证请求,第一验证请求包含:证书编号;根据证书编号查验是否已存储与证书编号对应的存证证书;若存储,发送存证证书。The first verification method, after returning the certificate of the creative creative data corresponding to the identification information to the enterprise client, receives the first verification request sent by the enterprise client, where the first verification request includes: a certificate number; The certificate of deposit corresponding to the certificate number has been stored; if it is stored, the certificate of the certificate is sent.
进一步地,该方法还可以包括如下步骤:接收企业客户端发送的创新创意数据的描述信息,将描述信息与第一数据串关联存储;相应的,第一验证请求还可以包含:验证密码;则验证过程还包括:根据验证密码查验验证密码是否正确,若正确,向企业客户端反馈存证证书对应的描述信息。其中,描述信息可以包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息;相应的,上述步骤接收企业客户端发送的创新创意数据的描述信息之后,还可以包括:根据至少一种描述信息对接收到的创新创意数据进行归类,形成创新创意数据的索引文档;以使企业客户端根据任一描述信息查找 到对应的创新创意数据的归类信息。从而方便第三方存证设备对企业客户端的存证创新创意数据进行归类管理,方便企业对已存证数据的查询。Further, the method may further include the following steps: receiving description information of the innovative creative data sent by the enterprise client, and storing the description information in association with the first data string; correspondingly, the first verification request may further include: verifying the password; The verification process further includes: verifying whether the password is correct according to the verification password, and if correct, feeding back to the enterprise client the description information corresponding to the certificate. The description information may include: a project ID, a creator, a version number, a customer ID, a R&D department ID, or location information. Correspondingly, after receiving the description information of the innovation creative data sent by the enterprise client, the foregoing step may further include: At least one descriptive information classifies the received innovative creative data to form an index document of innovative creative data; so that the enterprise client searches according to any description information Correspondence information to the corresponding innovative creative data. Therefore, it is convenient for the third-party depository device to classify and manage the creative and creative data of the enterprise client, so that the enterprise can query the stored data.
第二种验证方式,接收企业客户端发送的第二验证请求,第二验证请求包含:第一数据串;在存证数据库中查验是否已存储第一数据串,根据查验结果返回第一验证回执。进一步地,根据查验结果返回第一验证回执具体包括:若存证数据库中没有存储第一数据串,向企业客户端返回未查到存证信息的响应消息;若存证数据库中已存储第一数据串,向企业客户端返回查到存证信息的响应消息和/或第一数据串的存证时间信息。The second verification method is: receiving a second verification request sent by the enterprise client, where the second verification request includes: a first data string; checking whether the first data string has been stored in the certificate database, and returning the first verification receipt according to the verification result . Further, returning the first verification receipt according to the verification result specifically includes: if the first data string is not stored in the certificate database, returning a response message that the certificate information is not found to the enterprise client; if the certificate database has stored the first The data string returns a response message for checking the deposit information and/or the time of deposit of the first data string to the enterprise client.
第三种验证方式,接收企业客户端发送的第三验证请求,第三验证请求包含:第一数据串、可信时间戳;若存证数据库中已存储第一数据串,根据第一数据串、可信时间戳进行验证,得到验证结果,并根据验证结果返回第二验证回执。进一步地,根据第一数据串、可信时间戳进行验证,得到验证结果,并根据验证结果返回第二验证回执具体包括:查找与第一数据串对应的存证时间,并根据第一数据串和存证时间生成唯一对应的第三数据串;对可信时间戳进行解密,得到第四数据串;若第三数据串与第四数据串完全匹配,向企业客户端返回查到存证信息的响应消息和/或第一数据串的存证时间信息。The third verification mode is to receive a third verification request sent by the enterprise client, where the third verification request includes: a first data string and a trusted timestamp; if the first data string is stored in the certificate database, according to the first data string The trusted timestamp is verified, the verification result is obtained, and the second verification receipt is returned according to the verification result. Further, performing verification according to the first data string and the trusted timestamp, obtaining the verification result, and returning the second verification receipt according to the verification result specifically includes: searching for a certificate time corresponding to the first data string, and according to the first data string And generating a unique corresponding third data string with the deposit time; decrypting the trusted time stamp to obtain the fourth data string; if the third data string and the fourth data string completely match, returning the check information to the enterprise client Response message and/or certificate time information of the first data string.
进一步地,该方法还包括如下步骤:Further, the method further includes the following steps:
向企业客户端返回存证回执,具体包括:向企业客户端返回带有CA认证信息的存证回执,以向企业客户端提供存证设备的身份验证信息。Returning the deposit receipt to the enterprise client, specifically: returning the certificate receipt with the CA authentication information to the enterprise client to provide the enterprise client with the authentication information of the certificate device.
进一步地,该方法还包括如下步骤:Further, the method further includes the following steps:
接收企业客户端发送的注册请求;返回用于生成第一数据串的算法生成器,以使企业客户端根据算法生成器提供的预设算法生成与创新创意数据唯一对应的第一数据串。Receiving a registration request sent by the enterprise client; returning an algorithm generator for generating the first data string, so that the enterprise client generates a first data string uniquely corresponding to the innovation creative data according to a preset algorithm provided by the algorithm generator.
图5是根据一示例性实施例示出的一种创新创意数据处理装置的结构示意图。如图5所示,本实施例提供的创新创意数据处理装置51具体可以实现应用于企业客户端的创新创意数据处理方法的各个步骤,其具体实现过程在此不再赘述。FIG. 5 is a schematic structural diagram of an innovative creative data processing apparatus according to an exemplary embodiment. As shown in FIG. 5, the innovative creative data processing apparatus 51 provided in this embodiment can implement various steps of the innovative creative data processing method applied to the enterprise client, and the specific implementation process is not described herein.
本实施例提供的创新创意数据处理装置51,具体包括:The innovative creative data processing device 51 provided in this embodiment specifically includes:
数据串生成模块11,用于根据创新创意数据,生成第一数据串,第一数 据串是与创新创意数据唯一对应的数据信息;The data string generating module 11 is configured to generate a first data string according to the innovation creative data, the first number The string is the only data information corresponding to the innovative creative data;
发送模块12,用于向存证设备发送存证请求,存证请求包含:第一数据串;The sending module 12 is configured to send a deposit request to the depositing device, where the deposit request includes: a first data string;
第一接收模块13,用于接收存证设备返回的存证回执;存证回执包含:第一数据串对应的存证时间;或者存证回执包含:存证时间、可信时间戳;The first receiving module 13 is configured to receive a certificate receipt returned by the certificate storage device; the certificate receipt includes: a certificate time corresponding to the first data string; or the certificate receipt includes: a certificate time and a trusted time stamp;
存储模块14,用于当存证回执包含存证时间时,将存证时间与创新创意数据关联存储;或者用于,当存证回执包含存证时间、可信时间戳时,将存证时间、创新创意数据、可信时间戳关联存储;The storage module 14 is configured to store the deposit time with the creative creative data when the deposit receipt includes the deposit time, or for storing the deposit time when the deposit receipt includes the deposit time and the trusted time stamp , innovative creative data, trusted timestamp associated storage;
其中,存证时间是存证设备向可信时间签发设备发送第一数据串,以使可信时间签发设备基于接收到第一数据串的时间所签发的可信时间;可信时间戳是存证设备基于第一数据串、存证时间生成的唯一对应的第二数据串;且存证设备采用私钥对第二数据串进行数字签名后得到的。The credential time is a credential time that the credential device sends the first data string to the trusted time signing device, so that the trusted time signing device sends the trusted data according to the time when the first data string is received; The card device is based on the first data string and the unique corresponding second data string generated by the certificate time; and the certificate device obtains the digital data signature by using the private key.
图6是根据另一示例性实施例示出的一种创新创意数据处理装置的结构示意图。如图6所示,在上述实施例的基础上,本实施例提供的创新创意数据处理装置51还可以包括:FIG. 6 is a schematic structural diagram of an innovative creative data processing apparatus according to another exemplary embodiment. As shown in FIG. 6, on the basis of the foregoing embodiment, the innovative creative data processing apparatus 51 provided in this embodiment may further include:
第二接收模块15,用于接收企业创新创意技术文档;技术文档包含:技术文档内容信息、多种属性信息;The second receiving module 15 is configured to receive an enterprise creative creative technical document; the technical document includes: technical document content information, and multiple attribute information;
归类模块16,用于根据至少一种属性信息对接收到的技术文档进行归类,形成归类后的技术文档数据包;The categorization module 16 is configured to classify the received technical documents according to the at least one attribute information to form a classified technical document data package;
处理模块17,用于当技术文档数据包满足企业预设存证条件时,对所述技术文档数据包进行数据处理得到创新创意数据。The processing module 17 is configured to perform data processing on the technical document data packet to obtain innovative creative data when the technical document data package satisfies the enterprise preset depositing condition.
其中,属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息;预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。The attribute information includes one or more of the following: a project ID, a technical document creator, a version number, a customer ID, a R&D department ID, and a location information; and the preset depositing conditions include: a preset depositing period, and a project completion identifier. , or technical document security level.
进一步地,处理模块17:具体用于根据预设数据格式和/或加密算法,对技术文档数据包进行数据处理得到创新创意数据;Further, the processing module 17 is specifically configured to perform data processing on the technical document data packet according to a preset data format and/or an encryption algorithm to obtain innovative creative data;
该装置还包括:存储模块14,还用于将创新创意数据存储在企业客户端的本地数据库中。The apparatus also includes a storage module 14 for storing innovative creative data in a local database of the enterprise client.
进一步地,发送模块12,还用于向存证设备发送出证请求,出证请求包含:存证回执的标识信息; Further, the sending module 12 is further configured to send a certificate issuing request to the certificate issuing device, where the certificate issuing request includes: identifier information of the certificate receipt receipt;
第一接收模块13,还用于接收存证设备根据存证回执的标识信息返回的创新创意数据的存证证书;存证证书包含:证书编号、存证时间;The first receiving module 13 is further configured to receive a certificate of deposit of the innovative creative data returned by the depositing device according to the identification information of the certificate receipt; the certificate of deposit includes: a certificate number and a time of depositing the certificate;
相应的,corresponding,
发送模块12,还用于向存证设备发送第一验证请求,第一验证请求包含:证书编号,以使存证设备根据证书编号查验是否已存储与证书编号对应的存证证书;The sending module 12 is further configured to send a first verification request to the certificate storage device, where the first verification request includes: a certificate number, so that the certificate storage device checks, according to the certificate number, whether the certificate of deposit corresponding to the certificate number has been stored;
第一接收模块13,还用于接收存证设备根据证书编号查验后返回的存证证书。The first receiving module 13 is further configured to receive a certificate of deposit returned by the certificate storage device after checking according to the certificate number.
进一步地,发送模块12,还用于向存证设备发送创新创意数据的描述信息,以使存证设备将描述信息与第一数据串关联存储;Further, the sending module 12 is further configured to send the description information of the creative creative data to the depositing device, so that the depositing device stores the description information in association with the first data string;
相应的,发送模块12发送的第一验证请求还包含:验证密码;Correspondingly, the first verification request sent by the sending module 12 further includes: verifying the password;
第一接收模块13,还用于接收存证设备根据验证密码查验通过后,反馈的创新创意数据的描述信息。The first receiving module 13 is further configured to receive description information of the innovative creative data fed back by the verification device after the verification password is passed.
进一步地,发送模块12,还用于向存证设备发送第二验证请求,第二验证请求包含:第一数据串;Further, the sending module 12 is further configured to send a second verification request to the certificate storage device, where the second verification request includes: a first data string;
第一接收模块13,还用于接收存证设备根据第一数据进行查验后返回的第一验证回执。The first receiving module 13 is further configured to receive a first verification receipt returned by the verification device after checking according to the first data.
进一步地,第一接收模块13:具体用于当存证设备中没有存储第一数据串时,接收存证设备返回的未查到存证信息的响应消息;当存证设备中已存储第一数据串时,接收存证设备返回的查到存证信息的响应消息和/或第一数据串的存证时间信息。Further, the first receiving module 13 is specifically configured to: when the first data string is not stored in the certificate storage device, receive a response message that is not found by the certificate storage device and does not find the deposit information; when the first storage device has stored the first When the data string is received, the response message of the found evidence information returned by the depositing device and/or the certificate time information of the first data string is received.
进一步地,发送模块12,还用于向存证设备发送第三验证请求,第三验证请求包含:第一数据串、可信时间戳;Further, the sending module 12 is further configured to send a third verification request to the certificate storage device, where the third verification request includes: a first data string, a trusted time stamp;
第一接收模块13,还用于接收存证设备根据第一数据串和可信时间戳进行查验后返回的第二验证回执。The first receiving module 13 is further configured to receive a second verification receipt returned by the verification device after checking according to the first data string and the trusted timestamp.
进一步地,第一接收模块13:具体用于当存证设备中没有存储第一数据串时,接收存证设备返回的未查到存证信息的响应消息;当存证设备中已存储第一数据串,且存证设备基于第一数据串、第一数据串的存证时间生成唯一对应的第三数据串;并基于可信时间戳解密得到第四数据串;当第三数据串与第四数据串完全匹配时,接收存证设备返回的查到存证信息的响应消息 和/或第一数据串的存证时间信息。Further, the first receiving module 13 is specifically configured to: when the first data string is not stored in the certificate storage device, receive a response message that is not found by the certificate storage device and does not find the deposit information; when the first storage device has stored the first a data string, and the certificate storage device generates a unique third data string based on the first data string and the certificate time of the first data string; and decrypts the fourth data string based on the trusted time stamp; when the third data string and the third data string When the four data strings are completely matched, the response message of the stored certificate information returned by the depositing device is received. And/or the time of deposit of the first data string.
进一步地,发送模块12,具体用于向存证设备发送带有第一CA认证信息的存证请求,第一CA认证信息包含:企业客户端的身份验证信息,以使存证设备根据第一CA认证信息,对企业客户端的身份进行验证。Further, the sending module 12 is specifically configured to send, to the certificate storage device, a certificate request with the first CA authentication information, where the first CA authentication information includes: identity verification information of the enterprise client, so that the certificate device is based on the first CA Authentication information to verify the identity of the enterprise client.
进一步地,第二接收模块15,具体用于接收带有第二CA认证信息的企业创新创意技术文档,第二CA认证信息包含:发送企业创新创意技术文档的发送方的身份验证信息以及发送方所归属的部门的身份验证信息;以使企业客户端根据第二CA认证信息,对企业创新创意技术文档的发送方的身份进行验证。Further, the second receiving module 15 is specifically configured to receive an enterprise innovation creative technical document with the second CA authentication information, where the second CA authentication information includes: sending the identity verification information of the sender of the enterprise innovation creative technical document and the sender The authentication information of the belonging department; in order for the enterprise client to verify the identity of the sender of the enterprise innovation creative technical document according to the second CA authentication information.
进一步地,发送模块12,还用于向存证设备发送注册请求;Further, the sending module 12 is further configured to send a registration request to the depositing device;
第一接收模块13,还用于接收存证设备返回的算法生成器;算法生成器用于根据预设算法生成与创新创意数据唯一对应的第一数据串。The first receiving module 13 is further configured to receive an algorithm generator returned by the certificate storage device, and the algorithm generator is configured to generate a first data string uniquely corresponding to the innovation creative data according to the preset algorithm.
图7是根据一示例性实施例示出的一种创新创意数据存证设备的结构示意图。如图7所示,本实施例提供的创新创意数据存证设备52具体可以实现应用于存证设备的创新创意数据处理方法的各个步骤,其具体实现过程在此不再赘述。FIG. 7 is a schematic structural diagram of an innovative creative data depositing device according to an exemplary embodiment. As shown in FIG. 7, the innovative creative data storage device 52 provided in this embodiment can implement various steps of the innovative creative data processing method applied to the certificate storage device, and the specific implementation process is not described herein.
本实施例提供的创新创意数据存证设备52,具体包括:The innovative creative data storage device 52 provided in this embodiment specifically includes:
接收模块21,用于接收企业客户端发送的存证请求,存证请求包含:第一数据串;第一数据串是企业客户端基于创新创意数据生成的唯一数据信息;The receiving module 21 is configured to receive a certificate request sent by the enterprise client, where the certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data;
比对模块22,用于比对存证数据库50中是否已存储有第一数据串;其中,存证数据库50可以为创新创意数据存证设备52内的一组成部分,也可以为独立于该存证设备52之外的云存储数据库。The comparison module 22 is configured to compare whether the first data string has been stored in the certificate database 50; wherein the certificate database 50 may be an integral part of the innovative creative data storage device 52, or may be independent of the A cloud storage database other than the depositing device 52.
存证时间获取模块23,用于当比对模块22比对后发现存证数据库50中没有存储有第一数据串时,则向可信时间签发设备53发送第一数据串,以使可信时间签发设备53签发第一数据串的存证时间;存证时间为可信时间签发设备基于接收到第一数据串的时间所签发的可信时间;The certificate time obtaining module 23 is configured to: when the comparison module 22 compares, find that the first data string is not stored in the certificate database 50, send the first data string to the trusted time signing device 53 to make the trusted data string The time issuance device 53 issues a certificate time of the first data string; the certificate time is a trusted time issued by the trusted time signing device based on the time when the first data string is received;
数据串生成模块24,用于基于第一数据串、第一数据串的存证时间生成唯一对应的第二数据串;The data string generating module 24 is configured to generate a unique second data string based on the first data string and the certificate time of the first data string;
签名模块25,用于采用私钥对第二数据串进行数字签名,得到与第一数 据串对应的可信时间戳;The signing module 25 is configured to digitally sign the second data string by using a private key to obtain the first number According to the trusted timestamp corresponding to the string;
存储模块26,用于将第一数据串、第一数据串的存证时间、可信时间戳关联存储;The storage module 26 is configured to store the first data string, the certificate time of the first data string, and the trusted time stamp in association with each other;
发送模块27,用于向企业客户端返回存证回执;存证回执包含:第一数据串的存证时间,或者包含:第一数据串的存证时间和可信时间戳。The sending module 27 is configured to return a certificate receipt to the enterprise client. The certificate receipt includes: a certificate time of the first data string, or a: a certificate time and a trusted time stamp of the first data string.
本实施例提供的创新创意数据存证设备,通过接收企业客户端发送的包含第一数据串的存证请求,该第一数据串是企业客户端基于创新创意数据生成的唯一数据信息;若存证数据库没有存储过该第一数据串,则向可信时间签发设备发送第一数据串,以使可信时间签发设备基于接收到该第一数据串的时间签发可信的存证时间;存证设备基于第一数据串、第一数据串的存证时间生成唯一对应的第二数据串;并采用私钥对该第二数据串进行数字签名,得到可信时间戳;以证明该存证设备的真实性及可信性。并向企业客户端返回包含第一数据串存证时间的存证回执,或者包含:第一数据串的存证时间和可信时间戳的存证回执。通过由可信时间源进行时间同步的可信时间签发设备签发可信存证时间,固化了企业的创新创意数据的存证时间;且该创新创意数据的存证过程是基于企业创新创意数据所对应的唯一数据串进行的,有效保证了企业创新创意数据原始内容的保密性;同时,存证过程是由与用户无利害关系的第三方来实现的,提高了企业创新创意数据原创性鉴证的公信力。The innovative creative data storage device provided by the embodiment receives the certificate request containing the first data string sent by the enterprise client, and the first data string is the unique data information generated by the enterprise client based on the innovation creative data; If the first data string is not stored in the certificate database, the first data string is sent to the trusted time signing device, so that the trusted time signing device issues a trusted time for depositing the certificate based on the time when the first data string is received; The card device generates a unique second data string based on the first data string and the first data string, and digitally signs the second data string with the private key to obtain a trusted timestamp; The authenticity and credibility of the equipment. And returning the certificate receipt containing the first data string deposit time to the enterprise client, or including: the deposit time of the first data string and the certificate receipt of the trusted time stamp. The credential time of the credential issuance device issued by the trusted time source for time synchronization is issued, which solidifies the time of depositing the innovative creative data of the enterprise; and the process of depositing the innovative creative data is based on the innovation and creative data of the enterprise. The corresponding unique data string is carried out to effectively guarantee the confidentiality of the original content of the enterprise's innovative creative data. At the same time, the depositing process is realized by a third party who has no interest in the user, and improves the originality verification of the enterprise's innovative creative data. Credibility.
图8是根据另一示例性实施例示出的一种创新创意数据存证设备的结构示意图。如图8所示,在上述实施例的基础上,FIG. 8 is a schematic structural diagram of an innovative creative data depositing device according to another exemplary embodiment. As shown in FIG. 8, on the basis of the above embodiment,
接收模块21,还用于接收企业客户端发送的出证请求,出证请求包含:存证回执的标识信息;The receiving module 21 is further configured to receive a certificate request sent by the enterprise client, where the certificate request includes: identifier information of the certificate receipt;
发送模块27,还用于根据存证回执的标识信息,向企业客户端返回与标识信息对应的创新创意数据的存证证书;存证证书包含:证书编号、存证时间;The sending module 27 is further configured to return, according to the identification information of the certificate receipt, the certificate of the certificate of the creative creative data corresponding to the identifier information to the enterprise client; the certificate of deposit includes: a certificate number and a time of depositing the certificate;
相应的,接收模块21,还用于接收企业客户端发送的第一验证请求,第一验证请求包含:证书编号;Correspondingly, the receiving module 21 is further configured to receive a first verification request sent by the enterprise client, where the first verification request includes: a certificate number;
该存证设备52还包括:The depositing device 52 further includes:
查验模块28,用于根据证书编号查验是否已存储与证书编号对应的存证 证书;The checking module 28 is configured to check, according to the certificate number, whether the deposit certificate corresponding to the certificate number has been stored certificate;
发送模块27,还用于当查验模块28查验到已存储与证书编号对应的存证证书时,发送存证证书。The sending module 27 is further configured to send the certificate of deposit when the checking module 28 checks that the certificate of deposit corresponding to the certificate number has been stored.
进一步地,接收模块21,还用于接收企业客户端发送的创新创意数据的描述信息,将描述信息与第一数据串关联存储;Further, the receiving module 21 is further configured to receive description information of the innovative creative data sent by the enterprise client, and associate the description information with the first data string;
相应的,接收模块21接收到的第一验证请求还包含:验证密码;Correspondingly, the first verification request received by the receiving module 21 further includes: verifying the password;
发送模块27,还用于根据验证密码查验验证密码是否正确,若正确,向企业客户端反馈存证证书对应的描述信息。The sending module 27 is further configured to check whether the password is correct according to the verification password, and if yes, feed back to the enterprise client the description information corresponding to the certificate.
其中,描述信息包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息;The description information includes: a project ID, a creator, a version number, a customer ID, a R&D department ID, or location information;
进一步地,该存证设备52还包括:Further, the depositing device 52 further includes:
归类模块29,用于根据至少一种描述信息对接收到的创新创意数据进行归类,形成创新创意数据的索引文档;以使企业客户端根据任一描述信息查找到对应的创新创意数据的归类信息。The categorization module 29 is configured to classify the received innovative creative data according to the at least one description information to form an index document of the innovative creative data, so that the enterprise client finds the corresponding innovative creative data according to any description information. Classification information.
进一步地,接收模块21,还用于接收企业客户端发送的第二验证请求,第二验证请求包含:第一数据串;Further, the receiving module 21 is further configured to receive a second verification request sent by the enterprise client, where the second verification request includes: a first data string;
查验模块28,还用于在存证数据库50中查验是否已存储第一数据串;The checking module 28 is further configured to check, in the certificate database 50, whether the first data string has been stored;
发送模块27,用于根据查验模块28查验后得到的查验结果返回第一验证回执。The sending module 27 is configured to return a first verification receipt according to the verification result obtained after the inspection module 28 checks.
进一步地,发送模块27:具体用于当存证数据库50中没有存储第一数据串时,向企业客户端返回未查到存证信息的响应消息;当存证数据库中已存储第一数据串时,向企业客户端返回查到存证信息的响应消息和/或第一数据串的存证时间信息。Further, the sending module 27 is specifically configured to: when the first data string is not stored in the certificate database 50, return a response message that the certificate information is not found to the enterprise client; when the first data string is stored in the certificate database When the enterprise client returns a response message for checking the deposit information and/or the deposit time information of the first data string.
进一步地,接收模块21,还用于接收企业客户端发送的第三验证请求,第三验证请求包含:第一数据串、可信时间戳;Further, the receiving module 21 is further configured to receive a third verification request sent by the enterprise client, where the third verification request includes: a first data string, a trusted timestamp;
查验模块28,还用于当存证数据库50中已存储第一数据串时,根据第一数据串、可信时间戳进行验证,得到验证结果;The checking module 28 is further configured to: when the first data string is stored in the certificate database 50, perform verification according to the first data string and the trusted time stamp, and obtain a verification result;
发送模块27,还用于根据查验模块28验证后得到的验证结果返回第二验证回执。The sending module 27 is further configured to return a second verification receipt according to the verification result obtained after the verification module 28 verifies.
进一步地,查验模块28包括: Further, the inspection module 28 includes:
查找子模块281,用于查找与第一数据串对应的存证时间;The finding submodule 281 is configured to search for a deposit time corresponding to the first data string;
数据串生成子模块282,用于根据第一数据串和存证时间生成唯一对应的第三数据串;a data string generation sub-module 282, configured to generate a unique third data string according to the first data string and the certificate time;
解密子模块283,用于对可信时间戳进行解密,得到第四数据串;a decryption sub-module 283, configured to decrypt the trusted timestamp to obtain a fourth data string;
发送模块27,还用于当数据串生成子模块282生成的第三数据串与解密子模块283解密后得到的第四数据串完全匹配时,向企业客户端返回查到存证信息的响应消息和/或第一数据串的存证时间信息。The sending module 27 is further configured to: when the third data string generated by the data string generating sub-module 282 and the fourth data string obtained by the decrypting sub-module 283 are completely matched, return a response message for checking the deposit information to the enterprise client. And/or the time of deposit of the first data string.
进一步地,发送模块27:具体用于向企业客户端返回带有CA认证信息的存证回执,以向企业客户端提供存证设备的身份验证信息。Further, the sending module 27 is specifically configured to return a certificate receipt with CA authentication information to the enterprise client to provide the enterprise client with the identity verification information of the certificate device.
进一步地,接收模块21,还用于接收企业客户端发送的注册请求;Further, the receiving module 21 is further configured to receive a registration request sent by the enterprise client;
发送模块27,还用于返回用于生成第一数据串的算法生成器,以使企业客户端根据算法生成器提供的预设算法生成与创新创意数据唯一对应的第一数据串。The sending module 27 is further configured to return an algorithm generator for generating the first data string, so that the enterprise client generates a first data string uniquely corresponding to the creative creative data according to a preset algorithm provided by the algorithm generator.
图9是根据一示例性实施例示出的一种创新创意数据处理系统的结构示意图。如图9所示,本实施例提供的创新创意数据处理系统包括本发明任意实施例提供的创新创意数据处理装置51,以及本发明任意实施例提供的创新创意数据存证设备52。FIG. 9 is a schematic structural diagram of an innovative creative data processing system according to an exemplary embodiment. As shown in FIG. 9, the innovative creative data processing system provided by this embodiment includes an innovative creative data processing device 51 provided by any embodiment of the present invention, and an innovative creative data storage device 52 provided by any embodiment of the present invention.
图10是根据另一示例性实施例示出的一种创新创意数据处理系统结构示意图。如图10所示,该系统还可以包括:FIG. 10 is a schematic structural diagram of an innovative creative data processing system according to another exemplary embodiment. As shown in FIG. 10, the system may further include:
可信时间签发设备53,用于接收创新创意数据存证设备52发送的第一数据串,基于接收到第一数据串的时间签发第一数据串的存证时间;将第一数据串的存证时间发送给创新创意数据存证设备52。最后应说明的是:以上各实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述各实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。 The trusted time issuing device 53 is configured to receive the first data string sent by the innovative creative data storage device 52, and issue the first data string based on the time when the first data string is received; and save the first data string The time is sent to the innovative creative data storage device 52. Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the present invention, and are not intended to be limiting; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art will understand that The technical solutions described in the foregoing embodiments may be modified, or some or all of the technical features may be equivalently replaced; and the modifications or substitutions do not deviate from the technical solutions of the embodiments of the present invention. range.

Claims (48)

  1. 一种创新创意数据处理方法,其特征在于,包括:An innovative creative data processing method, characterized in that it comprises:
    企业客户端根据创新创意数据,生成第一数据串,所述第一数据串是与所述创新创意数据唯一对应的数据信息;The enterprise client generates a first data string according to the innovation creative data, where the first data string is data information uniquely corresponding to the innovation creative data;
    向存证设备发送存证请求,所述存证请求包含:所述第一数据串;Sending a deposit request to the depositing device, the deposit request comprising: the first data string;
    接收所述存证设备返回的存证回执,所述存证回执包含:所述第一数据串对应的存证时间;则所述企业客户端将所述存证时间与所述创新创意数据关联存储;Receiving a certificate receipt returned by the depositing device, where the certificate receipt includes: a deposit time corresponding to the first data string; and the enterprise client associates the deposit time with the innovation creative data storage;
    或者所述存证回执包含:所述存证时间、可信时间戳;则所述企业客户端Or the deposit receipt includes: the deposit time, a trusted time stamp; and the enterprise client
    将所述存证时间、所述创新创意数据、所述可信时间戳关联存储;And storing the deposit time, the innovation creative data, and the trusted time stamp;
    所述存证时间是所述存证设备向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;所述可信时间戳是所述存证设备基于所述第一数据串、所述存证时间生成的唯一对应的第二数据串;且所述存证设备采用私钥对所述第二数据串进行数字签名后得到的。The depositing time is that the depositing device sends the first data string to the trusted time issuing device, so that the trusted time signing device is trusted according to the time when the first data string is received. The trusted timestamp is a unique second data string generated by the depositing device based on the first data string and the deposit time; and the depositing device uses the private key pair Two data strings are obtained after digital signature.
  2. 根据权利要求1所述的方法,其特征在于,所述企业客户端根据创新创意数据,生成第一数据串之前,还包括:The method according to claim 1, wherein the enterprise client further generates: before generating the first data string according to the innovation creative data, the method further comprises:
    接收企业创新创意技术文档,所述技术文档包含:技术文档内容信息、多种属性信息;Receiving an enterprise creative creative technical document, the technical document comprising: technical document content information, and multiple attribute information;
    根据至少一种所述属性信息对接收到的所述技术文档进行归类,形成归类后的技术文档数据包;Sorting the received technical documents according to at least one of the attribute information to form a classified technical document data package;
    当所述技术文档数据包满足企业预设存证条件时,对所述技术文档数据包进行数据处理得到所述创新创意数据。When the technical document data package satisfies the enterprise preset depositing condition, data processing is performed on the technical document data packet to obtain the innovative creative data.
  3. 根据权利要求2所述的方法,其特征在于,The method of claim 2 wherein:
    所述属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息;The attribute information includes one or more of the following: a project ID, a technical document creator, a version number, a customer ID, a R&D department ID, and location information;
    所述预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。The preset depositing conditions include: a preset depositing period, an item completion identifier, or a technical document security level.
  4. 根据权利要求2所述的方法,其特征在于,所述对所述技术文档数据 包进行数据处理得到所述创新创意数据包括:The method of claim 2, wherein said pair of said technical document data The data processing of the package to obtain the innovative creative data includes:
    根据预设数据格式和/或加密算法,对所述技术文档数据包进行数据处理;Performing data processing on the technical document data packet according to a preset data format and/or an encryption algorithm;
    所述对所述技术文档数据包进行数据处理得到所述创新创意数据之后,还包括:After the data processing of the technical document data packet to obtain the innovative creative data, the method further includes:
    将所述创新创意数据存储在所述企业客户端的本地数据库中。The innovative creative data is stored in a local database of the enterprise client.
  5. 根据权利要求1所述的方法,其特征在于,所述接收所述存证设备返回的存证回执之后,还包括:The method according to claim 1, wherein the receiving the receipt of the certificate returned by the depositing device further comprises:
    向所述存证设备发送出证请求,所述出证请求包含:所述存证回执的标识信息;Sending a certificate request to the depositing device, where the certificate request includes: identification information of the certificate receipt;
    接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;Receiving a certificate of deposit of the innovation creative data returned by the depositing device according to the identification information of the certificate receipt; the certificate of deposit includes: a certificate number and a time of depositing a certificate;
    相应的,所述接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书之后,还包括:Correspondingly, after receiving the certificate of deposit of the innovative creative data returned by the depositing device according to the identification information of the certificate receipt, the method further includes:
    向所述存证设备发送第一验证请求,所述第一验证请求包含:所述证书编号,以使所述存证设备根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;Sending a first verification request to the certificate storage device, where the first verification request includes: the certificate number, so that the certificate storage device checks, according to the certificate number, whether a certificate corresponding to the certificate number has been stored certificate;
    若存储,接收所述存证设备根据所述证书编号查验后返回的所述存证证书。And if stored, receiving the certificate of deposit returned by the depositing device after checking according to the certificate number.
  6. 根据权利要求5所述的方法,其特征在于,所述方法还包括:The method of claim 5, wherein the method further comprises:
    向所述存证设备发送所述创新创意数据的描述信息,以使所述存证设备将所述描述信息与所述第一数据串关联存储;Transmitting the description information of the innovation creative data to the certificate storage device, so that the certificate storage device stores the description information in association with the first data string;
    相应的,所述第一验证请求还包含:验证密码;Correspondingly, the first verification request further includes: a verification password;
    接收所述存证设备根据所述验证密码查验通过后,反馈的所述创新创意数据的所述描述信息。Receiving, by the verification device, the description information of the innovative creative data that is fed back after the verification password is passed.
  7. 根据权利要求1所述的方法,其特征在于,所述企业客户端根据创新创意数据,生成第一数据串之后,还包括:The method according to claim 1, wherein the enterprise client generates the first data string according to the innovation creative data, and further includes:
    向所述存证设备发送第二验证请求,所述第二验证请求包含:所述第一数据串;Sending a second verification request to the certificate storage device, where the second verification request includes: the first data string;
    接收所述存证设备根据所述第一数据串进行查验后返回的第一验证回 执。Receiving the first verification back returned by the depositing device after checking according to the first data string Executive.
  8. 根据权利要求7所述的方法,其特征在于,所述接收所述存证设备根据所述第一数据进行查验后返回的第一验证回执,包括:The method according to claim 7, wherein the receiving the first verification receipt returned by the depositing device after checking according to the first data comprises:
    若所述存证设备中没有存储所述第一数据串,接收所述存证设备返回的未查到存证信息的响应消息;If the first data string is not stored in the certificate storage device, receiving a response message returned by the certificate storage device that does not find the deposit certificate information;
    若所述存证设备中已存储所述第一数据串,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And if the first data string is already stored in the certificate storage device, receiving a response message for checking the certificate information returned by the certificate storage device and/or the certificate time information of the first data string.
  9. 根据权利要求1所述的方法,其特征在于,所述企业客户端根据创新创意数据,生成第一数据串之后,还包括:The method according to claim 1, wherein the enterprise client generates the first data string according to the innovation creative data, and further includes:
    向所述存证设备发送第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;Sending a third verification request to the certificate storage device, where the third verification request includes: the first data string, a trusted timestamp;
    若所述存证数据库中已存储所述第一数据串,接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执。And if the first data string is stored in the certificate database, receiving a second verification receipt returned by the certificate device according to the first data string and the trusted timestamp.
  10. 根据权利要求9所述的方法,其特征在于,所述接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执,包括:The method according to claim 9, wherein the receiving the second verification receipt returned by the certificate device after checking according to the first data string and the trusted timestamp comprises:
    若所述存证设备基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第三数据串;并基于所述可信时间戳解密得到第四数据串;且所述第三数据串与所述第四数据串完全匹配,则接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And generating, by the certificate storage device, a unique third data string based on the first data string and the certificate time of the first data string; and decrypting the fourth data string based on the trusted time stamp; And the third data string and the fourth data string are completely matched, and the response message of the found evidence information returned by the certificate storage device and/or the certificate time information of the first data string is received.
  11. 根据权利要求2所述的方法,其特征在于,所述向存证设备发送存证请求,包括:The method according to claim 2, wherein the sending the deposit request to the depositing device comprises:
    向存证设备发送带有第一CA认证信息的存证请求,所述第一CA认证信息包含:企业客户端的身份验证信息,以使所述存证设备根据所述第一CA认证信息,对所述企业客户端的身份进行验证。And sending, to the certificate storage device, a certificate request with the first CA authentication information, where the first CA authentication information includes: identity verification information of the enterprise client, so that the certificate storage device is configured according to the first CA authentication information, The identity of the enterprise client is verified.
  12. 根据权利要求11所述的方法,其特征在于,所述接收企业创新创意技术文档,包括:The method according to claim 11, wherein the receiving the enterprise innovation creative technical document comprises:
    接收带有第二CA认证信息的企业创新创意技术文档,所述第二CA认证信息包含:发送所述企业创新创意技术文档的发送方的身份验证信息以及所述发送方所归属的部门的身份验证信息;以使所述企业客户端根据所述第二 CA认证信息,对所述企业创新创意技术文档的发送方的身份进行验证。Receiving an enterprise innovation creative technical document with a second CA authentication information, where the second CA authentication information includes: sending identity verification information of a sender of the enterprise innovation creative technical document and identity of a department to which the sender belongs Verifying information; such that the enterprise client is based on the second The CA authentication information verifies the identity of the sender of the enterprise's innovative creative technical document.
  13. 根据权利要求1所述的方法,其特征在于,所述企业客户端根据创新创意数据,生成第一数据串之前,还包括:The method according to claim 1, wherein the enterprise client further generates: before generating the first data string according to the innovation creative data, the method further comprises:
    向所述存证设备发送注册请求;Sending a registration request to the depositing device;
    接收所述存证设备返回的算法生成器;所述算法生成器用于根据预设算法生成与所述创新创意数据唯一对应的所述第一数据串。Receiving an algorithm generator returned by the certificate storage device; the algorithm generator is configured to generate the first data string uniquely corresponding to the innovation creative data according to a preset algorithm.
  14. 一种创新创意数据处理方法,其特征在于,包括:An innovative creative data processing method, characterized in that it comprises:
    存证设备接收企业客户端发送的存证请求,所述存证请求包含:第一数据串;所述第一数据串是所述企业客户端基于创新创意数据生成的唯一数据信息;The certificate storage device receives a certificate request sent by the enterprise client, where the certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data;
    比对存证数据库中是否已存储有所述第一数据串,若没有,则向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备签发所述第一数据串的存证时间;所述存证时间为所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;Aligning whether the first data string is already stored in the certificate database, and if not, sending the first data string to the trusted time signing device, so that the trusted time signing device issues the first data The certificate time of the string; the certificate time is a trusted time issued by the trusted time signing device based on the time when the first data string is received;
    基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第二数据串;Generating a unique corresponding second data string based on the first data string and the certificate time of the first data string;
    采用私钥对所述第二数据串进行数字签名,得到与所述第一数据串对应的可信时间戳;Digitally signing the second data string with a private key to obtain a trusted timestamp corresponding to the first data string;
    将所述第一数据串、所述第一数据串的存证时间、所述可信时间戳关联存储;And storing the first data string, the certificate time of the first data string, and the trusted timestamp;
    向所述企业客户端返回存证回执;所述存证回执包含:所述第一数据串的存证时间,或者包含:所述第一数据串的存证时间和所述可信时间戳。Returning a deposit receipt to the enterprise client; the certificate receipt includes: a certificate time of the first data string, or a: a certificate time of the first data string and the trusted timestamp.
  15. 根据权利要求14所述的方法,其特征在于,所述方法还包括:The method of claim 14, wherein the method further comprises:
    接收所述企业客户端发送的出证请求,所述出证请求包含:所述存证回执的标识信息;Receiving a certificate request sent by the enterprise client, where the certificate request includes: identifier information of the certificate receipt;
    根据所述存证回执的标识信息,向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;And returning, to the enterprise client, a certificate of deposit of the innovation creative data corresponding to the identifier information according to the identifier information of the certificate receipt receipt; the certificate of deposit includes: a certificate number and a certificate time;
    相应的,所述向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书之后,还包括: Correspondingly, after the returning the certificate of the innovation creative data corresponding to the identifier information to the enterprise client, the method further includes:
    接收所述企业客户端发送的第一验证请求,所述第一验证请求包含:所述证书编号;Receiving a first verification request sent by the enterprise client, where the first verification request includes: the certificate number;
    根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;Checking, according to the certificate number, whether a certificate of deposit corresponding to the certificate number has been stored;
    若存储,发送所述存证证书。If stored, the certificate of deposit is sent.
  16. 根据权利要求15所述的方法,其特征在于,所述方法还包括:The method of claim 15 wherein the method further comprises:
    接收所述企业客户端发送的所述创新创意数据的描述信息,将所述描述信息与所述第一数据串关联存储;Receiving description information of the innovation creative data sent by the enterprise client, and storing the description information in association with the first data string;
    相应的,所述第一验证请求还包含:验证密码;Correspondingly, the first verification request further includes: a verification password;
    根据所述验证密码查验所述验证密码是否正确,若正确,向所述企业客户端反馈所述存证证书对应的描述信息。And verifying, according to the verification password, whether the verification password is correct, and if yes, feeding back, to the enterprise client, description information corresponding to the certificate.
  17. 根据权利要求16所述的方法,其特征在于,所述描述信息包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息;所述接收所述企业客户端发送的所述创新创意数据的描述信息之后,还包括:The method according to claim 16, wherein the description information comprises: an item ID, a creator, a version number, a customer ID, a R&D department ID or location information; and the receiving the After innovating the description of the creative data, it also includes:
    根据至少一种所述描述信息对接收到的所述创新创意数据进行归类,形成所述创新创意数据的索引文档;以使所述企业客户端根据任一所述描述信息查找到对应的所述创新创意数据的归类信息。And classifying the received innovation creative data according to at least one of the description information to form an index document of the innovation creative data; so that the enterprise client finds a corresponding location according to any description information. A classification of innovative creative data.
  18. 根据权利要求14所述的方法,其特征在于,所述方法还包括:The method of claim 14, wherein the method further comprises:
    接收所述企业客户端发送的第二验证请求,所述第二验证请求包含:所述第一数据串;Receiving a second verification request sent by the enterprise client, where the second verification request includes: the first data string;
    在存证数据库中查验是否已存储所述第一数据串,根据查验结果返回第一验证回执。Checking whether the first data string has been stored in the certificate database, and returning the first verification receipt according to the verification result.
  19. 根据权利要求18所述的方法,其特征在于,所述根据查验结果返回第一验证回执,包括:The method according to claim 18, wherein the returning the first verification receipt according to the verification result comprises:
    若所述存证数据库中没有存储所述第一数据串,向所述企业客户端返回未查到存证信息的响应消息;If the first data string is not stored in the certificate database, returning a response message that the certificate information is not found to the enterprise client;
    若所述存证数据库中已存储所述第一数据串,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And if the first data string is already stored in the certificate database, returning the response message of the certificate information and/or the certificate time information of the first data string to the enterprise client.
  20. 根据权利要求14所述的方法,其特征在于,所述方法还包括:The method of claim 14, wherein the method further comprises:
    接收所述企业客户端发送的第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳; Receiving a third verification request sent by the enterprise client, where the third verification request includes: the first data string, a trusted timestamp;
    若存证数据库中已存储所述第一数据串,根据所述第一数据串、所述可信时间戳进行验证,得到验证结果,并根据所述验证结果返回第二验证回执。If the first data string is stored in the certificate database, the verification is performed according to the first data string and the trusted timestamp, and the verification result is obtained, and the second verification receipt is returned according to the verification result.
  21. 根据权利要求20所述的方法,其特征在于,所述根据所述第一数据串、所述可信时间戳进行验证,得到验证结果,并根据所述验证结果返回第二验证回执,包括:The method according to claim 20, wherein the verifying according to the first data string and the trusted timestamp, obtaining a verification result, and returning a second verification receipt according to the verification result, includes:
    查找与所述第一数据串对应的存证时间,并根据所述第一数据串和所述存证时间生成唯一对应的第三数据串;Searching for a certificate time corresponding to the first data string, and generating a unique third data string according to the first data string and the certificate time;
    对所述可信时间戳进行解密,得到第四数据串;Decrypting the trusted timestamp to obtain a fourth data string;
    若所述第三数据串与所述第四数据串完全匹配,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。And if the third data string completely matches the fourth data string, returning, to the enterprise client, a response message for checking the deposit information and/or the certificate time information of the first data string.
  22. 根据权利要求14所述的方法,其特征在于,所述向所述企业客户端返回存证回执,包括:The method of claim 14, wherein the returning the deposit receipt to the enterprise client comprises:
    向所述企业客户端返回带有CA认证信息的存证回执,以向所述企业客户端提供所述存证设备的身份验证信息。Returning a certificate receipt with CA authentication information to the enterprise client to provide the enterprise client with the authentication information of the certificate device.
  23. 根据权利要求14所述的方法,其特征在于,所述方法还包括:The method of claim 14, wherein the method further comprises:
    接收所述企业客户端发送的注册请求;Receiving a registration request sent by the enterprise client;
    返回用于生成所述第一数据串的算法生成器,以使所述企业客户端根据所述算法生成器提供的预设算法生成与所述创新创意数据唯一对应的所述第一数据串。Returning an algorithm generator for generating the first data string, so that the enterprise client generates the first data string uniquely corresponding to the innovation creative data according to a preset algorithm provided by the algorithm generator.
  24. 一种创新创意数据处理装置,其特征在于,包括:An innovative creative data processing device, comprising:
    数据串生成模块,用于根据创新创意数据,生成第一数据串,所述第一数据串是与所述创新创意数据唯一对应的数据信息;a data string generating module, configured to generate, according to the innovative creative data, a first data string, where the first data string is data information uniquely corresponding to the innovative creative data;
    发送模块,用于向存证设备发送存证请求,所述存证请求包含:所述第一数据串;a sending module, configured to send a deposit request to the depositing device, where the deposit request includes: the first data string;
    第一接收模块,用于接收所述存证设备返回的存证回执;所述存证回执包含:所述第一数据串对应的存证时间;或者所述存证回执包含:所述存证时间、可信时间戳;a first receiving module, configured to receive a certificate receipt returned by the certificate storage device; the certificate receipt includes: a certificate time corresponding to the first data string; or the certificate receipt includes: the certificate Time, trusted timestamp;
    存储模块,用于当所述存证回执包含所述存证时间时,将所述存证时间与所述创新创意数据关联存储;或者用于,当所述存证回执包含所述存证时 间、所述可信时间戳时,将所述存证时间、所述创新创意数据、所述可信时间戳关联存储;a storage module, configured to: when the deposit receipt includes the deposit time, store the deposit time with the innovation creative data; or when the deposit receipt includes the deposit certificate And storing the certificate time, the innovation creative data, and the trusted time stamp in association with each other;
    所述存证时间是所述存证设备向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间;所述可信时间戳是所述存证设备基于所述第一数据串、所述存证时间生成的唯一对应的第二数据串;且所述存证设备采用私钥对所述第二数据串进行数字签名后得到的。The depositing time is that the depositing device sends the first data string to the trusted time issuing device, so that the trusted time signing device is trusted according to the time when the first data string is received. The trusted timestamp is a unique second data string generated by the depositing device based on the first data string and the deposit time; and the depositing device uses the private key pair Two data strings are obtained after digital signature.
  25. 根据权利要求24所述的装置,其特征在于,还包括:The device according to claim 24, further comprising:
    第二接收模块,用于接收企业创新创意技术文档;所述技术文档包含:技术文档内容信息、多种属性信息;a second receiving module, configured to receive an enterprise creative creative technical document; the technical document includes: technical document content information, and multiple attribute information;
    归类模块,用于根据至少一种所述属性信息对接收到的所述技术文档进行归类,形成归类后的技术文档数据包;a categorization module, configured to classify the received technical documents according to the at least one attribute information, to form a classified technical document data package;
    处理模块,用于当所述技术文档数据包满足企业预设存证条件时,对所述技术文档数据包进行数据处理得到所述创新创意数据。And a processing module, configured to perform data processing on the technical document data packet to obtain the innovative creative data when the technical document data package satisfies an enterprise preset depositing condition.
  26. 根据权利要求25所述的装置,其特征在于,The device according to claim 25, wherein
    所述属性信息包括以下的一项或多项:项目ID、技术文档创建人、版本号、客户ID、研发部门ID、地点信息;The attribute information includes one or more of the following: a project ID, a technical document creator, a version number, a customer ID, a R&D department ID, and location information;
    所述预设存证条件包括:预设存证周期,项目完结标识,或者技术文档保密等级。The preset depositing conditions include: a preset depositing period, an item completion identifier, or a technical document security level.
  27. 根据权利要求25所述的装置,其特征在于,The device according to claim 25, wherein
    所述处理模块:具体用于根据预设数据格式和/或加密算法,对所述技术文档数据包进行数据处理得到创新创意数据;The processing module is specifically configured to perform data processing on the technical document data packet according to a preset data format and/or an encryption algorithm to obtain innovative creative data;
    所述存储模块,还用于将所述创新创意数据存储在所述企业客户端的本地数据库中。The storage module is further configured to store the innovative creative data in a local database of the enterprise client.
  28. 根据权利要求24所述的装置,其特征在于,The device according to claim 24, wherein
    所述发送模块,还用于向所述存证设备发送出证请求,所述出证请求包含:所述存证回执的标识信息;The sending module is further configured to send a certificate issuing request to the certificate issuing device, where the certificate issuing request includes: identifier information of the certificate receipt receipt;
    所述第一接收模块,还用于接收所述存证设备根据所述存证回执的标识信息返回的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间; The first receiving module is further configured to receive a certificate of deposit of the innovation creative data returned by the depositing device according to the identification information of the certificate receipt; the certificate of deposit includes: a certificate number, a certificate time ;
    相应的,corresponding,
    所述发送模块,还用于向所述存证设备发送第一验证请求,所述第一验证请求包含:所述证书编号,以使所述存证设备根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;The sending module is further configured to send a first verification request to the certificate storage device, where the first verification request includes: the certificate number, so that the certificate storage device checks whether the storage device has been stored according to the certificate number. a certificate of deposit corresponding to the certificate number;
    所述第一接收模块,还用于接收所述存证设备根据所述证书编号查验后返回的所述存证证书。The first receiving module is further configured to receive the certificate of deposit returned by the depositing device after checking according to the certificate number.
  29. 根据权利要求28所述的装置,其特征在于,The device of claim 28, wherein
    所述发送模块,还用于向所述存证设备发送所述创新创意数据的描述信息,以使所述存证设备将所述描述信息与所述第一数据串关联存储;The sending module is further configured to send the description information of the innovation creative data to the certificate storage device, so that the certificate storage device associates the description information with the first data string;
    相应的,所述发送模块发送的所述第一验证请求还包含:验证密码;Correspondingly, the first verification request sent by the sending module further includes: verifying a password;
    所述第一接收模块,还用于接收所述存证设备根据所述验证密码查验通过后,反馈的所述创新创意数据的所述描述信息。The first receiving module is further configured to receive the description information of the innovative creative data that is sent back by the verification device after being verified by the verification password.
  30. 根据权利要求24所述的装置,其特征在于,The device according to claim 24, wherein
    所述发送模块,还用于向所述存证设备发送第二验证请求,所述第二验证请求包含:所述第一数据串;The sending module is further configured to send a second verification request to the certificate storage device, where the second verification request includes: the first data string;
    所述第一接收模块,还用于接收所述存证设备根据所述第一数据进行查验后返回的第一验证回执。The first receiving module is further configured to receive a first verification receipt returned by the depositing device after checking according to the first data.
  31. 根据权利要求30所述的装置,其特征在于,The device of claim 30 wherein:
    所述第一接收模块:具体用于当所述存证设备中没有存储所述第一数据串时,接收所述存证设备返回的未查到存证信息的响应消息;当所述存证设备中已存储所述第一数据串时,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。The first receiving module is configured to: when the first data string is not stored in the certificate storage device, receive a response message returned by the certificate storage device that does not find the deposit certificate information; And when the first data string is stored in the device, receiving a response message of the stored certificate information returned by the certificate storage device and/or the certificate time information of the first data string.
  32. 根据权利要求24所述的装置,其特征在于,The device according to claim 24, wherein
    所述发送模块,还用于向所述存证设备发送第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;The sending module is further configured to send a third verification request to the certificate storage device, where the third verification request includes: the first data string, a trusted timestamp;
    所述第一接收模块,还用于接收所述存证设备根据所述第一数据串和所述可信时间戳进行查验后返回的第二验证回执。The first receiving module is further configured to receive a second verification receipt returned by the verification device after checking according to the first data string and the trusted timestamp.
  33. 根据权利要求32所述的装置,其特征在于,The device of claim 32, wherein
    所述第一接收模块:具体用于当所述存证设备中没有存储所述第一数据串时,接收所述存证设备返回的未查到存证信息的响应消息;当所述存证设 备中已存储所述第一数据串,且所述存证设备基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第三数据串;并基于所述可信时间戳解密得到第四数据串;当所述第三数据串与所述第四数据串完全匹配时,接收所述存证设备返回的查到存证信息的响应消息和/或所述第一数据串的存证时间信息。The first receiving module is configured to: when the first data string is not stored in the certificate storage device, receive a response message returned by the certificate storage device that does not find the deposit certificate information; Assume The first data string is stored in the standby, and the certificate storage device generates a unique third data string based on the first data string and the certificate time of the first data string; and based on the trusted Decrypting the timestamp to obtain a fourth data string; when the third data string and the fourth data string completely match, receiving a response message of the check-in information returned by the verification device and/or the first The time of deposit of the data string.
  34. 根据权利要求25所述的装置,其特征在于,The device according to claim 25, wherein
    所述发送模块,具体用于向存证设备发送带有第一CA认证信息的存证请求,所述第一CA认证信息包含:企业客户端的身份验证信息,以使所述存证设备根据所述第一CA认证信息,对所述企业客户端的身份进行验证。The sending module is specifically configured to send a certificate request with the first CA authentication information to the certificate storage device, where the first CA authentication information includes: identity verification information of the enterprise client, so that the certificate storage device is configured according to the The first CA authentication information is used to verify the identity of the enterprise client.
  35. 根据权利要求34所述的装置,其特征在于,The device of claim 34, wherein
    所述第二接收模块,具体用于接收带有第二CA认证信息的企业创新创意技术文档,所述第二CA认证信息包含:发送所述企业创新创意技术文档的发送方的身份验证信息以及所述发送方所归属的部门的身份验证信息;以使所述企业客户端根据所述第二CA认证信息,对所述企业创新创意技术文档的发送方的身份进行验证。The second receiving module is specifically configured to receive an enterprise innovation creative technical document with a second CA authentication information, where the second CA authentication information includes: sending identity verification information of a sender of the enterprise innovation creative technical document, and And the identity verification information of the department to which the sender belongs; so that the enterprise client verifies the identity of the sender of the enterprise innovation creative technical document according to the second CA authentication information.
  36. 根据权利要求24所述的装置,其特征在于,The device according to claim 24, wherein
    所述发送模块,还用于向所述存证设备发送注册请求;The sending module is further configured to send a registration request to the certificate storage device;
    所述第一接收模块,还用于接收所述存证设备返回的算法生成器;所述算法生成器用于根据预设算法生成与所述创新创意数据唯一对应的所述第一数据串。The first receiving module is further configured to receive an algorithm generator returned by the certificate storage device, where the algorithm generator is configured to generate the first data string that uniquely corresponds to the innovation creative data according to a preset algorithm.
  37. 一种创新创意数据存证设备,其特征在于,包括:An innovative creative data storage device characterized by comprising:
    接收模块,用于接收企业客户端发送的存证请求,所述存证请求包含:第一数据串;所述第一数据串是所述企业客户端基于创新创意数据生成的唯一数据信息;a receiving module, configured to receive a certificate request sent by the enterprise client, where the certificate request includes: a first data string; the first data string is unique data information generated by the enterprise client based on the innovation creative data;
    比对模块,用于比对存证数据库中是否已存储有所述第一数据串;a comparison module, configured to compare whether the first data string is already stored in the certificate database;
    存证时间获取模块,用于当所述比对模块比对后发现所述存证数据库中没有存储有所述第一数据串时,则向可信时间签发设备发送所述第一数据串,以使所述可信时间签发设备签发所述第一数据串的存证时间;所述存证时间为所述可信时间签发设备基于接收到所述第一数据串的时间所签发的可信时间; a certificate time obtaining module, configured to send the first data string to the trusted time signing device when the comparison module finds that the first data string is not stored in the certificate database, And causing the trusted time issuing device to issue a certificate time of the first data string; the certificate time is a credibility issued by the trusted time signing device based on the time when the first data string is received Time
    数据串生成模块,用于基于所述第一数据串、所述第一数据串的存证时间生成唯一对应的第二数据串;a data string generating module, configured to generate a unique second data string based on the first data string and the certificate time of the first data string;
    签名模块,用于采用私钥对所述第二数据串进行数字签名,得到与所述第一数据串对应的可信时间戳;a signature module, configured to digitally sign the second data string by using a private key, to obtain a trusted timestamp corresponding to the first data string;
    存储模块,用于将所述第一数据串、所述第一数据串的存证时间、所述可信时间戳关联存储;a storage module, configured to store the first data string, the certificate time of the first data string, and the trusted timestamp;
    发送模块,用于向所述企业客户端返回存证回执;a sending module, configured to return a deposit receipt to the enterprise client;
    所述存证回执包含:所述第一数据串的存证时间,The deposit receipt includes: a time of deposit of the first data string,
    或者包含:所述第一数据串的存证时间和所述可信时间戳。Or comprising: a certificate time of the first data string and the trusted timestamp.
  38. 根据权利要求37所述的存证设备,其特征在于,A depositing device according to claim 37, wherein
    所述接收模块,还用于接收所述企业客户端发送的出证请求,所述出证请求包含:所述存证回执的标识信息;The receiving module is further configured to receive a certificate request sent by the enterprise client, where the certificate request includes: identifier information of the certificate receipt;
    所述发送模块,还用于根据所述存证回执的标识信息,向所述企业客户端返回与所述标识信息对应的所述创新创意数据的存证证书;所述存证证书包含:证书编号、存证时间;The sending module is further configured to: return, according to the identifier information of the certificate receipt, a certificate of the certificate of the creative creative data corresponding to the identifier information to the enterprise client; the certificate of deposit includes: a certificate Number, time of deposit;
    相应的,所述接收模块,还用于接收所述企业客户端发送的第一验证请求,所述第一验证请求包含:所述证书编号;Correspondingly, the receiving module is further configured to receive a first verification request sent by the enterprise client, where the first verification request includes: the certificate number;
    所述存证设备还包括:The depositing device further includes:
    查验模块,用于根据所述证书编号查验是否已存储与所述证书编号对应的存证证书;a checking module, configured to check, according to the certificate number, whether a certificate of deposit corresponding to the certificate number has been stored;
    所述发送模块,还用于当所述查验模块查验到已存储与所述证书编号对应的存证证书时,发送所述存证证书。The sending module is further configured to: when the checking module detects that the certificate of deposit corresponding to the certificate number has been stored, send the certificate of deposit.
  39. 根据权利要求38所述的存证设备,其特征在于,A depositing device according to claim 38, characterized in that
    所述接收模块,还用于接收所述企业客户端发送的所述创新创意数据的描述信息,将所述描述信息与所述第一数据串关联存储;The receiving module is further configured to receive description information of the innovation creative data sent by the enterprise client, and associate the description information with the first data string;
    相应的,所述接收模块接收到的所述第一验证请求还包含:验证密码;Correspondingly, the first verification request received by the receiving module further includes: verifying a password;
    所述发送模块,还用于根据所述验证密码查验所述验证密码是否正确,若正确,向所述企业客户端反馈所述存证证书对应的描述信息。The sending module is further configured to check whether the verification password is correct according to the verification password, and if yes, feed back, to the enterprise client, description information corresponding to the certificate.
  40. 根据权利要求39所述的存证设备,其特征在于,所述描述信息包括:项目ID、创建人、版本号、客户ID、研发部门ID或地点信息; The certificate storage device according to claim 39, wherein the description information comprises: an item ID, a creator, a version number, a customer ID, a research and development department ID, or location information;
    所述存证设备还包括:The depositing device further includes:
    归类模块,用于根据至少一种所述描述信息对接收到的所述创新创意数据进行归类,形成所述创新创意数据的索引文档;以使所述企业客户端根据任一所述描述信息查找到对应的所述创新创意数据的归类信息。a categorization module, configured to classify the received innovation creative data according to at least one of the description information to form an index document of the innovation creative data; so that the enterprise client describes according to any description The information finds the categorization information of the corresponding innovative creative data.
  41. 根据权利要求37所述的存证设备,其特征在于,A depositing device according to claim 37, wherein
    所述接收模块,还用于接收所述企业客户端发送的第二验证请求,所述第二验证请求包含:所述第一数据串;The receiving module is further configured to receive a second verification request sent by the enterprise client, where the second verification request includes: the first data string;
    所述查验模块,还用于在存证数据库中查验是否已存储所述第一数据串;The checking module is further configured to check, in the certificate database, whether the first data string has been stored;
    所述发送模块,还用于根据所述查验模块查验后得到的查验结果返回第一验证回执。The sending module is further configured to return a first verification receipt according to the inspection result obtained after the inspection module checks.
  42. 根据权利要求41所述的存证设备,其特征在于,A depositing device according to claim 41, wherein
    所述发送模块:具体用于当所述存证数据库中没有存储所述第一数据串时,向所述企业客户端返回未查到存证信息的响应消息;当所述存证数据库中已存储所述第一数据串时,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。The sending module is configured to: when the first data string is not stored in the certificate database, return a response message to the enterprise client that does not find the deposit information; when the certificate database has been And storing, when the first data string is stored, a response message for checking the deposit information and/or the time of depositing the first data string to the enterprise client.
  43. 根据权利要求37所述的存证设备,其特征在于,A depositing device according to claim 37, wherein
    所述接收模块,还用于接收所述企业客户端发送的第三验证请求,所述第三验证请求包含:所述第一数据串、可信时间戳;The receiving module is further configured to receive a third verification request sent by the enterprise client, where the third verification request includes: the first data string, a trusted timestamp;
    所述查验模块,还用于当存证数据库中已存储所述第一数据串时,根据所述第一数据串、所述可信时间戳进行验证,得到验证结果;The checking module is further configured to: when the first data string is stored in the certificate database, perform verification according to the first data string and the trusted timestamp, and obtain a verification result;
    所述发送模块,还用于根据所述查验模块验证后得到的验证结果返回第二验证回执。The sending module is further configured to return a second verification receipt according to the verification result obtained after the verification module is verified.
  44. 根据权利要求43所述的存证设备,其特征在于,A depositing device according to claim 43, wherein:
    所述查验模块包括:The inspection module includes:
    查找子模块,用于查找与所述第一数据串对应的存证时间;a searching submodule, configured to search for a deposit time corresponding to the first data string;
    数据串生成子模块,用于根据所述第一数据串和所述存证时间生成唯一对应的第三数据串;a data string generation submodule, configured to generate a unique third data string according to the first data string and the certificate time;
    解密子模块,用于对所述可信时间戳进行解密,得到第四数据串;a decryption submodule, configured to decrypt the trusted timestamp to obtain a fourth data string;
    所述发送模块,还用于当所述数据串生成子模块生成的所述第三数据串 与所述解密子模块解密后得到的所述第四数据串完全匹配时,向所述企业客户端返回查到存证信息的响应消息和/或所述第一数据串的存证时间信息。The sending module is further configured to: when the data string generation submodule generates the third data string And when the fourth data string obtained by the decryption sub-module is completely matched, the enterprise client returns a response message for checking the deposit information and/or the certificate time information of the first data string.
  45. 根据权利要求37所述的存证设备,其特征在于,A depositing device according to claim 37, wherein
    所述发送模块:具体用于向所述企业客户端返回带有CA认证信息的存证回执,以向所述企业客户端提供所述存证设备的身份验证信息。The sending module is specifically configured to return a certificate receipt with CA authentication information to the enterprise client, to provide the enterprise client with identity verification information of the certificate device.
  46. 根据权利要求37所述的存证设备,其特征在于,A depositing device according to claim 37, wherein
    所述接收模块,还用于接收所述企业客户端发送的注册请求;The receiving module is further configured to receive a registration request sent by the enterprise client;
    所述发送模块,还用于返回用于生成所述第一数据串的算法生成器,以使所述企业客户端根据所述算法生成器提供的预设算法生成与所述创新创意数据唯一对应的所述第一数据串。The sending module is further configured to: return an algorithm generator for generating the first data string, so that the enterprise client generates a unique correspondence with the innovation creative data according to a preset algorithm provided by the algorithm generator The first data string.
  47. 一种创新创意数据处理系统,其特征在于,包括:An innovative creative data processing system, comprising:
    如权利要求24-36任一项所述的创新创意数据处理装置;以及An innovative creative data processing apparatus according to any of claims 24-36;
    如权利要求37-46任一项所述的创新创意数据存证设备。An innovative creative data depositing device according to any of claims 37-46.
  48. 根据权利要求47所述的系统,其特征在于,还包括:The system of claim 47, further comprising:
    可信时间签发设备,用于接收所述创新创意数据存证设备发送的所述第一数据串,基于接收到所述第一数据串的时间签发所述第一数据串的存证时间;将所述第一数据串的存证时间发送给所述创新创意数据存证设备。 a trusted time issuing device, configured to receive the first data string sent by the innovative creative data storage device, and issue a time of depositing the first data string based on a time when the first data string is received; The certificate time of the first data string is sent to the innovative creative data storage device.
PCT/CN2016/098152 2015-10-16 2016-09-06 Innovation and creativity data processing method, device and system and certificate storage device WO2017063465A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510674090.7 2015-10-16
CN201510674090.7A CN105335667B (en) 2015-10-16 2015-10-16 Innovate creative data processing method, device, system and deposit card equipment

Publications (1)

Publication Number Publication Date
WO2017063465A1 true WO2017063465A1 (en) 2017-04-20

Family

ID=55286186

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/098152 WO2017063465A1 (en) 2015-10-16 2016-09-06 Innovation and creativity data processing method, device and system and certificate storage device

Country Status (2)

Country Link
CN (1) CN105335667B (en)
WO (1) WO2017063465A1 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112801663A (en) * 2021-02-05 2021-05-14 北京众享比特科技有限公司 Block chain evidence storing method, device, system, equipment and medium
US11863390B1 (en) * 2022-08-16 2024-01-02 Nvidia Corporation Path attestation for computing resources

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105335667B (en) * 2015-10-16 2017-03-15 北京源创云网络科技有限公司 Innovate creative data processing method, device, system and deposit card equipment
CN106156345B (en) * 2016-07-21 2019-11-05 北京源创云网络科技有限公司 Item file deposits card method, deposits card equipment and terminal device
CN106548091A (en) * 2016-10-14 2017-03-29 北京爱接力科技发展有限公司 A kind of data deposit card, the method and device of checking
CN110378079B (en) * 2018-04-13 2023-07-04 胡小凡 Information processing, protecting and selling method and device based on original works
CN110533506A (en) * 2019-08-19 2019-12-03 广州华旻信息科技有限公司 Visualize the method and device of innovation plan-validation
CN110912802B (en) * 2019-11-07 2021-08-10 上海百事通信息技术股份有限公司 E-mail data processing method and device
CN111737365B (en) * 2020-07-22 2021-08-17 百度在线网络技术(北京)有限公司 Storage certificate processing method, device, equipment and storage medium
CN112364384B (en) * 2021-01-12 2021-04-23 支付宝(杭州)信息技术有限公司 Business record time service method based on credible account book database
CN114500321B (en) * 2022-04-12 2022-08-02 成方金融科技有限公司 Message verification method, device and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223374A (en) * 2011-06-22 2011-10-19 熊志海 Third-party authentication security protection system and third-party authentication security protection method based on online security protection of electronic evidence
CN102339370A (en) * 2011-09-14 2012-02-01 福建伊时代信息科技股份有限公司 Preservation method for electronic file, preservation system and verification system thereof
CN103514410A (en) * 2013-09-30 2014-01-15 上海市数字证书认证中心有限公司 Dependable preservation and evidence collection system and method for electronic contract
CN105335667A (en) * 2015-10-16 2016-02-17 北京源创云网络科技有限公司 Innovation and creativity data processing method, device and system and certificate storing equipment

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101826101A (en) * 2010-01-25 2010-09-08 王平 Search engine device and method
CN102404463B (en) * 2010-09-13 2014-12-10 中国移动通信集团福建有限公司 Achieving method, achieving system and achieving device of user generated content (UGC) ring-back tone
CN104134020A (en) * 2013-05-03 2014-11-05 杨高赟 Intelligent terminal software anti-piracy method and intelligent terminal software anti-piracy system based on network database
CN104636640A (en) * 2015-01-23 2015-05-20 杭州节点科技有限公司 File signing method based on intelligent mobile terminal
CN104992087B (en) * 2015-06-29 2017-03-15 北京源创云网络科技有限公司 Mobile terminal innovation creative data information processing method and mobile terminal

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223374A (en) * 2011-06-22 2011-10-19 熊志海 Third-party authentication security protection system and third-party authentication security protection method based on online security protection of electronic evidence
CN102339370A (en) * 2011-09-14 2012-02-01 福建伊时代信息科技股份有限公司 Preservation method for electronic file, preservation system and verification system thereof
CN103514410A (en) * 2013-09-30 2014-01-15 上海市数字证书认证中心有限公司 Dependable preservation and evidence collection system and method for electronic contract
CN105335667A (en) * 2015-10-16 2016-02-17 北京源创云网络科技有限公司 Innovation and creativity data processing method, device and system and certificate storing equipment

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112801663A (en) * 2021-02-05 2021-05-14 北京众享比特科技有限公司 Block chain evidence storing method, device, system, equipment and medium
CN112801663B (en) * 2021-02-05 2024-03-19 北京众享比特科技有限公司 Blockchain certification method, device, system, equipment and medium
US11863390B1 (en) * 2022-08-16 2024-01-02 Nvidia Corporation Path attestation for computing resources

Also Published As

Publication number Publication date
CN105335667A (en) 2016-02-17
CN105335667B (en) 2017-03-15

Similar Documents

Publication Publication Date Title
WO2017063465A1 (en) Innovation and creativity data processing method, device and system and certificate storage device
JP6941146B2 (en) Data security service
US20210319132A1 (en) Methods and Devices For Managing User Identity Authentication Data
US7925023B2 (en) Method and apparatus for managing cryptographic keys
US20200084045A1 (en) Establishing provenance of digital assets using blockchain system
CA2899027C (en) Data security service
US20100257370A1 (en) Apparatus And Method for Supporting Content Exchange Between Different DRM Domains
JP2004531918A (en) Method and system for obtaining a digital signature
KR20080104137A (en) Verification of electronic signatures
CN106464496A (en) Method and system for creating a certificate to authenticate a user identity
US8218763B2 (en) Method for ensuring the validity of recovered electronic documents from remote storage
GB2520056A (en) Digital data retention management
JP2004110197A (en) Information processing method and method of managing access authority for use at center system
US11301823B2 (en) System and method for electronic deposit and authentication of original electronic information objects
US9647837B2 (en) Securely filtering trust services records
CN106257483B (en) Processing method, equipment and the system of electronic data
CN102819695A (en) Authorization method and application server based on java archive (Jar)
CN112926031A (en) Safe block chain electronic certificate use method
CN113132109A (en) Electronic deposit certificate management method and device based on block chain and electronic equipment
Panse et al. DigiSecure: Attribute-Based Document Transfer Solution
CN112653773A (en) Top-level server registration information management method, system, electronic device and medium
CN113240418A (en) Intelligent private data access control method and equipment based on block chain
LACKO THE CRYPTOGRAPHIC PROTOCOL FOR MANAGEMENT AND APPROVAL OF DOCUMENT VERSIONS

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16854847

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16854847

Country of ref document: EP

Kind code of ref document: A1