The monitoring of a kind of Self-help optical-disk imprinting Life cycle and auditing method
Technical field
The invention belongs to computer technology and information security field, particularly relate to the security management and control system and method for CD burning.
Background technology
In concerning security matters fields such as military project, army, national defence scientific researches, there are strict management system and management method to the importing of data, derivation, transmission.In the process of exchanges data, what play important instrumentality is exactly all kinds of concerning security matters carriers, comprises paper medium, light medium, electromagnetic medium.Wherein, light medium and CD, because limited, the content of CD write data mode is not easily distorted, safe coefficient is relatively high, and low price, easy to carry, so be widely used in exchanges data.But, this does not also mean that the safety management requirement that can reduce CD burning, on the contrary, the process control of CD burning and audit are needed especially to pay close attention to, except setting up and improving except management system, also need to assist mutually with technological means, carry out monitoring to the Life cycle of CD burning and audit.
The management of CD burning secret and safe comprises several key link: imprinting examination & approval, imprinting export, optical disc identified, CD reclaims and imprinting log audit.Existing solution normally adds technology management and control means in certain link, supervises and operate recording device thus realize the security management to CD burning in conjunction with special messenger.Such as imprinting examination & approval are undertaken by the approval process of OA system, time applicant logs in OA system submission imprinting application, need to safeguard the information such as title, level of confidentiality, and upload engraving data.Examination & approval leader examine in OA system, when examine by after, applicant can look for imprinting keeper to carry out imprinting to exchanges data room or reference room.Imprinting keeper can log in the result that OA system views imprinting examination & approval, by imprinting keeper downloading data and imprinting becomes CD, be by adhesive label in CD card to the mark of CD or manual write the information such as numbering, organization, level of confidentiality, imprinting people, imprinting date, finally will Handwork register imprinting daily record on register, comprise writing time, imprinting people, title, level of confidentiality, whereabouts etc.Whether usage of CD-ROM is complete when carrying out reclaiming, need artificial nucleus consistent with imprinting daily record to the mark in CD card, and hand-kept CD reclaims state.
Have some technological means be applied to CD burning export and audit link (see patent " a kind of method of safe imprinting and audit ", application number 201010553013.3), realize the management to recording device and imprinting control, such as imprinting authority is controlled, imprinting is encrypted to data of optical disk, automatically record imprinting daily record.
Existing technical scheme can only carry out technology management and control in some or certain several link, in the process of imprinting, still need special messenger to exercise supervision management, in secret and safe and convenience, there is some risks and problem: 1. lack that complete and coherent technological means and solution realize exporting from imprinting examination & approval, imprinting, optical disc identified, CD reclaims and the Life cycle safety management of imprinting audit.Easily occur between each link disconnecting, thus cause the problem that responsibility is not clear to occur, and be difficult to review.2. submit imprinting application to by OA, often have the restriction of annex size when uploading data, can only Single document be submitted to, and can not according to bibliographic structure uploading data.3. need special messenger to carry out operating and supervising in writing process, also exist and expand the risk that classified information knows scope, and under running into the situations such as overtime work, add the work load of keeper, there is the inconvenience in work.4. CD mark and reclaim owing to depending on manual operation, easily make mistakes, cause the situation occurring that concerning security matters CD account is unclear.
Summary of the invention
Goal of the invention: the problems referred to above security management of CD burning being required and existed for concerning security matters industry, the present invention proposes the monitoring of a kind of self-service CD burning Life cycle and auditing method, realizes from imprinting examination & approval, engraving data, the optical disc identified lifecycle management reclaimed to CD; And a kind of self-service imprinting mode of operation of swiping the card is proposed, both convenient work, can improve again the security of CD burning.
Technical scheme: a kind of self-service CD burning Life cycle monitoring and auditing system, comprise several PC, several optical disk printing recording devices, CD recovery point computer, server, networks; Arrange CD burning monitoring and auditing system on the server, PC is installed imprinting application/examination & approval client, on CD recovery point computer, fixing disc reclaims client; Server and the equal access network of PC; Every platform optical disk printing recording device binds an imprinting control terminal, access network;
Described imprinting control terminal comprises CPU, internal memory, power supply, liquid crystal touch screen, card reading module and network interface card, the process of CPU primary responsibility come from card reading module, liquid crystal touch screen, network interface card data and carry out data communication with optical disk printing recording device and server; Card reading module is used for carrying out user identity discriminating by recognition user card number; Liquid crystal touch screen had both supported input information, and also can show information, primary responsibility is alternately man-machine; Imprinting control terminal is connected with optical disk printing recording device by network interface, controls optical disk printing recording device and starts card printing and imprinting task, and imprinting daily record uploaded onto the server in real time;
Fixing disc imprinting monitoring and auditing system on the server, realizes user management, imprinting control of authority, approval process configures, barcode encoding is regular, optical disk printing recording device controls and records imprinting daily record; CD burning monitoring can realize the registration of user and enable with auditing system, controls user's imprinting authority, only has the user giving imprinting authority just can submit imprinting application to and carry out the self-service imprinting of CD, does not have the user of imprinting authority cannot imprinting; Imprinting examination & approval had both supported that one-level examination & approval also supported multistage examination & approval, and keeper can log in CD burning monitoring and examine the self-defined approval process of dimension with auditing system according to level of confidentiality, whereabouts etc.; Can arrange optical disc encoding rule, guarantee that in the bar code of often opening spray printing in CD card be all unique; CD card print format can also be defined, design card will print the relative putting position etc. of which data and data; The imprinting daily record of omnidistance record can be carried out query composition, thus greatly improve imprinting audit efficiency according to writing time, imprinting people, level of confidentiality, the condition such as whether to reclaim;
Optical disk printing recording device is built-in CD writer, cd printer and mechanical arm, print in CD card and do not need manual intervention completely in data carving process, monitored by CD burning and automatically controlled with auditing system: first control mechanical arm and capture CD groove put into cd printer from coiling, the coding rule pre-set according to user and card print format, adopt the mode such as ink-jet or hot transfer printing to print card, card prints the information such as bar code, title, level of confidentiality, imprinting people, writing time; Then, control mechanical arm to capture CD and put into CD writer and carry out data carving; After hours, CD exports from printing recording device placing mouth for card printing and data carving;
PC is installed imprinting application/examination & approval client, and user submits imprinting application to by this client, and approver can examine imprinting application;
Reclaim fixing disc on computer at CD and reclaim client, retrieval management person can be scanned the bar code on CD with barcode scanner or input bar code number, the imprinting daily record before inquiring, and also reclaims state by amendment CD and reclaims CD; Recording disk is reclaimed daily record by system, comprises and reclaims people, recovery time, title, bar code number etc.
The present invention discloses the method for the monitoring of a kind of Self-help optical-disk imprinting Life cycle and auditing system, its step comprises:
1) applicant logs in CD burning application client and submits imprinting application to, uploads engraving data;
2) approver checks imprinting application, downloads engraving data examining content, carries out imprinting examination & approval;
3) examination & approval are by rear, and applicant swipes the card to imprinting control terminal, and can view by the imprinting application of examination & approval, applicant selects an imprinting application and determines;
4) optical disk printing recording device prints card and engraving data, and card data comprise the information such as bar code number, level of confidentiality;
5), when CD reclaims, retrieval management person scans the data of CD card, carries out CD recovery;
6) the Life cycle log content such as CD burning monitoring and auditing system record imprinting examination & approval, imprinting operation and CD recovery, is convenient to inquiry and audit.
Wherein, in step 1), when user needs to imprint CDs, first in PC, log in imprinting application client, and submit record information to, comprise title, level of confidentiality, purposes, whereabouts, number, application reason etc., then upload engraving data and be stored in server end, graded batch uploads engraving data, and can keep the bibliographic structure of uploading data.When user's uploading data is more than a CD capacity, as the capacity of a DVD CD, will point out user, and require to submit engraving data to according to the data volume of a CD;
In step 2) in, after user submits imprinting application to, CD burning monitoring can, according to the imprinting approval process configured, transfer immediate news to corresponding examination & approval leader with auditing system; Examination & approval leader can check imprinting application, and can download engraving data and audit file content, carries out imprinting examination & approval; Applicant can obtain the message audited by or refuse in time; System log (SYSLOG) imprinting examination & approval daily record, comprises applicant, application time, title, level of confidentiality, number, examination & approval leader, approval status etc.;
In step 3), 4) in, when imprinting examination & approval by after, user can to imprinting control terminal, swipe the card in the card-reading zone of imprinting control terminal, the contact type intelligent card of main flow on the card reading module identifiable design market of imprinting control terminal, such as HID, EM, Mifare etc., built-in chip in smart card, often open in card and store unique card number, can be used as the unique identification of user identity; When card reading module recognizes card number, the card number of acquisition is passed to server and is carried out authenticating user identification by CPU1; User also can pass through to input account on the liquid crystal touch screen of imprinting control terminal, password carries out authentication; After certification is passed through, this user of display submits to and examines the imprinting operation passed through by the liquid crystal display of imprinting control terminal; User can select certain imprinting operation and confirm, announcement server Bootable CD-ROM is printed recording device and carries out automatic card printing and CD burning by imprinting control terminal;
In step 5), when CD needs to reclaim, retrieval management person logs in CD and reclaims client in PC, by the bar code on barcode scanner scanning CD or input bar code number, imprinting daily record before can inquiring, keeper reclaims state by amendment CD and reclaims CD.Recording disk is reclaimed daily record by system, comprises and reclaims people, recovery time, title, bar code number etc.
Advantage of the present invention and beneficial effect: 1. by the enforcement of the program, can realize CD burning from imprinting examination & approval, imprinting exports, optical disc identified, CD reclaims Life cycle monitoring and auditing.Breach and only implement technological means and limitation in the safety brought in conjunction with labor management and efficiency in some or certain several link, the supvr that can be secret industry realize CD burning secret and safe management full range and become more meticulous horizontal in useful support is provided.2. solve and upload engraving data to size of data, the conditional problem of data structure by OA.3. the self-service CD burning mode of innovation, effectively can alleviate the working pressure of keeper, and solve the problem that unconscious expansion classified information knows scope, facilitate work greatly.4.. CD card can automatic printing bar code as unique identification, make CD reclaim more accurate, convenient.5. the log audit record of full range, can record each key link of writing process comprehensively and accurately, and log recording is easy to inquiry, imprinting is audited and is easier to operation.6. the deployment of the technical program does not need to change user's existing network framework, has and disposes easy feature.
Accompanying drawing explanation
Fig. 1 is system architecture schematic diagram of the present invention;
Fig. 2 is method flow block diagram of the present invention.
Embodiment
In order to make the object, technical solutions and advantages of the present invention clearly, describe the present invention below in conjunction with the drawings and specific embodiments.
As shown in Figure 1, a kind of self-service CD burning Life cycle monitoring and auditing system, comprise several PC, several optical disk printing recording devices, CD recovery point computer, server, networks; Arrange CD burning monitoring and auditing system on the server, PC is installed imprinting application/examination & approval client, on CD recovery point computer, fixing disc reclaims client; Server and the equal access network of PC; Every platform optical disk printing recording device binds an imprinting control terminal, access network;
Described imprinting control terminal comprises CPU, internal memory, power supply, liquid crystal touch screen, card reading module and network interface card, the process of CPU primary responsibility come from card reading module, liquid crystal touch screen, network interface card data and carry out data communication with optical disk printing recording device and server; Card reading module is used for carrying out user identity discriminating by recognition user card number; Liquid crystal touch screen had both supported input information, and also can show information, primary responsibility is alternately man-machine; Imprinting control terminal is connected with optical disk printing recording device by network interface, controls optical disk printing recording device and starts card printing and imprinting task, and imprinting daily record uploaded onto the server in real time;
Fixing disc imprinting monitoring and auditing system on the server, realizes user management, imprinting control of authority, approval process configures, barcode encoding is regular, optical disk printing recording device controls and records imprinting daily record; CD burning monitoring can realize the registration of user and enable with auditing system, controls user's imprinting authority, only has the user giving imprinting authority just can submit imprinting application to and carry out the self-service imprinting of CD, does not have the user of imprinting authority cannot imprinting; Imprinting examination & approval had both supported that one-level examination & approval also supported multistage examination & approval, and keeper can log in CD burning monitoring and examine the self-defined approval process of dimension with auditing system according to level of confidentiality, whereabouts etc.; Can arrange optical disc encoding rule, guarantee that in the bar code of often opening spray printing in CD card be all unique; CD card print format can also be defined, design card will print the relative putting position etc. of which data and data; The imprinting daily record of omnidistance record can be carried out query composition, thus greatly improve imprinting audit efficiency according to writing time, imprinting people, level of confidentiality, the condition such as whether to reclaim;
Optical disk printing recording device is built-in CD writer, cd printer and mechanical arm, print in CD card and do not need manual intervention completely in data carving process, monitored by CD burning and automatically controlled with auditing system: first control mechanical arm and capture CD groove put into cd printer from coiling, the coding rule pre-set according to user and card print format, adopt the mode such as ink-jet or hot transfer printing to print card, card prints the information such as bar code, title, level of confidentiality, imprinting people, writing time; Then, control mechanical arm to capture CD and put into CD writer and carry out data carving; After hours, CD exports from printing recording device placing mouth for card printing and data carving;
PC is installed imprinting application/examination & approval client, and user submits imprinting application to by this client, and approver can examine imprinting application;
Reclaim fixing disc on computer at CD and reclaim client, retrieval management person can be scanned the bar code on CD with barcode scanner or input bar code number, the imprinting daily record before inquiring, and also reclaims state by amendment CD and reclaims CD; Recording disk is reclaimed daily record by system, comprises and reclaims people, recovery time, title, bar code number etc.
The present invention discloses the method for the monitoring of a kind of Self-help optical-disk imprinting Life cycle and auditing system, its step comprises:
1) applicant logs in CD burning application client and submits imprinting application to, uploads engraving data;
2) approver checks imprinting application, downloads engraving data examining content, carries out imprinting examination & approval;
3) examination & approval are by rear, and applicant swipes the card to imprinting control terminal, and can view by the imprinting application of examination & approval, applicant selects an imprinting application and determines;
4) optical disk printing recording device prints card and engraving data, and card data comprise the information such as bar code number, level of confidentiality;
5), when CD reclaims, retrieval management person scans the data of CD card, carries out CD recovery;
6) the Life cycle log content such as CD burning monitoring and auditing system record imprinting examination & approval, imprinting operation and CD recovery, is convenient to inquiry and audit.
Fig. 2 is the FB(flow block) of the method.Wherein, in step 1), when user needs to imprint CDs, first in PC, log in imprinting application client, and submit record information to, comprise title, level of confidentiality, purposes, whereabouts, number, application reason etc., then upload engraving data and be stored in server end, graded batch uploads engraving data, and can keep the bibliographic structure of uploading data.When user's uploading data is more than a CD capacity, as the capacity of a DVD CD, will point out user, and require to submit engraving data to according to the data volume of a CD;
In step 2) in, after user submits imprinting application to, CD burning monitoring can, according to the imprinting approval process configured, transfer immediate news to corresponding examination & approval leader with auditing system; Examination & approval leader can check imprinting application, and can download engraving data and audit file content, carries out imprinting examination & approval; Applicant can obtain the message audited by or refuse in time; System log (SYSLOG) imprinting examination & approval daily record, comprises applicant, application time, title, level of confidentiality, number, examination & approval leader, approval status etc.;
In step 3), 4) in, when imprinting examination & approval by after, user can to imprinting control terminal, swipe the card in the card-reading zone of imprinting control terminal, the contact type intelligent card of main flow on the card reading module identifiable design market of imprinting control terminal, such as HID, EM, Mifare etc., built-in chip in smart card, often open in card and store unique card number, can be used as the unique identification of user identity; When card reading module recognizes card number, the card number of acquisition is passed to server and is carried out authenticating user identification by CPU1; User also can pass through to input account on the liquid crystal touch screen of imprinting control terminal, password carries out authentication; After certification is passed through, this user of display submits to and examines the imprinting operation passed through by the liquid crystal display of imprinting control terminal; User can select certain imprinting operation and confirm, announcement server Bootable CD-ROM is printed recording device and carries out automatic card printing and CD burning by imprinting control terminal;
In step 5), when CD needs to reclaim, retrieval management person logs in CD and reclaims client in PC, by the bar code on barcode scanner scanning CD or input bar code number, imprinting daily record before can inquiring, keeper reclaims state by amendment CD and reclaims CD.Recording disk is reclaimed daily record by system, comprises and reclaims people, recovery time, title, bar code number etc.