[embodiment]
In order to make object of the present invention, technical scheme and advantage clearly understand, below in conjunction with drawings and Examples, the present invention is further elaborated.Should be appreciated that specific embodiment described herein only in order to explain the present invention, be not intended to limit the present invention.
Embodiments provide a kind of point of group's election system, described system comprises main meeting-place front-end server, vote-counting center's server and guard station election system server, wherein:
Main meeting-place front-end server, for receiving the count of votes result of point group's election through encryption that guard station election system server sends, and verifies the data integrity of described count of votes result;
Vote-counting center's server, for generating and configuration session key, and by described session key stored in USBKey; According to the session key stored in described USB Key, data deciphering is carried out to the count of votes result through encryption, add up all field delegations and divide a count of votes result for election, generate final count of votes result;
Guard station election system server, dividing a count of votes result for election for adding up each delegation, encrypting according to the session key stored in described USB Key to described count of votes result; Transmit the described count of votes result through encryption.
The embodiment of the present invention additionally provides a kind of point of group's poll information processing method, and described method comprises the steps:
Steps A: complete in each delegation guard station a point count of votes for group's poll result, generates a point count of votes result for group's election;
Step B: described count of votes result is encrypted according to session key, and by through encryption count of votes result by secure network transmission to main meeting-place;
Step C: add up all field delegations at main meeting-place end and divide a count of votes result for election, generate final count of votes result.
The embodiment of the present invention is by completing count of votes in each delegation guard station, and count of votes result, after data encryption, realizes gathering to main meeting-place by secure network transmission, and then complete whole election count of votes task, without the need to transporting ballot paper, security is high, risk is low, and on the life of the people without impact.
Embodiment 1
The embodiment of the present invention 1 provides a kind of point of group's election system.As shown in Figure 1, complete tallying system is furnished with at guard station sub-venue, comprise ballot box, guard station election system server, main control software (can be installed on the election system server of guard station), alternative people and invalid ballots (i.e. invalidated ticket) process software (can be installed on the election system server of guard station, also can be installed on independent hardware), result output software (being installed on the election system server of guard station) and LAN (Local Area Network) etc.Main control software and election results output software comprise two kinds of modules, one directly exports Word document, another kind of output XML file, concrete block configuration is specified by user's request, in the present embodiment, count of votes result form adopts XML, is denoted as Result [Hotel ID] [Delegation ID].Therefore, the minimum Equipments Setting needed for the sub-venue of guard station comprises: 1 ballot box, 1 PC (runtime database server, each application software) and 1 switch.May there be more than one above delegation a guard station, and above-mentioned the whole series configuration need process the ballot paper of each delegation of a guard station.About alternative people and the process of invalid ballots, can complete in guard station, also can complete in main meeting-place, select people in the present embodiment else and invalid ballots process completes in guard station.
Setting up between guard station with main meeting-place has safe network to be connected (hereinafter referred to as private network), is communicated, complete safe and reliable file transfer by private network.The communication mode support broadcast of private network, to group busy and the mode such as point-to-point communication.Meeting dependent instruction (such as obtain voting pattern, start election, stop election etc.) is passed on by private network.Private network between guard station and main meeting-place and election system LAN (Local Area Network) completely isolated, the exchanges data between private network and election system by USB flash disk or special computing machine transmission, election system LAN (Local Area Network) comprises main meeting-place LAN (Local Area Network) and guard station sub-venue LAN (Local Area Network).A total M guard station is established, being denoted as of i-th guard station: Hoteli(1≤i≤M) in the present embodiment; If total N number of delegation, jGe delegation is expressed as: Delegationj(1≤j≤N).
This system, except comprising guard station election system server, also comprises main meeting-place front-end server and vote-counting center's server.Wherein, main meeting-place front-end server respectively with vote-counting center's server and guard station election system server communication, main meeting-place front-end server is to guard station election system server distribution voting pattern, receive the count of votes result of point group's election through encryption that guard station election system server sends, and verify the data integrity of count of votes result.For convenience of in real time distribution voting pattern and fast transport count of votes result, the present embodiment, based on traditional ftp file server, carries out exchange and the transmission of data according to File Transfer Protocol, is provided with ftp file server main meeting-place front-end server is added.
Vote-counting center's server communicates with main meeting-place front-end server, and vote-counting center's server is unified to be generated and configuration session key, and by session key stored in USB Key, is distributed to each guard station operating personnel and vote-counting center operating personnel.Consider that private network can provide secure connection, in the present embodiment, this session key adopts symmetric key, and all operations personnel all use identical key, do not adopt unsymmetrical key.Vote-counting center's server is also provided with server end Special safety program, carries out data deciphering according to the session key stored in USB Key to the count of votes result through encryption, adds up all field delegations and divides a count of votes result for election, generate final count of votes result.
Guard station election system server communicates with main meeting-place front-end server, and guard station election system server obtains voting pattern, the data integrity of checking voting pattern; Add up each delegation and divide a count of votes result for election, according to the session key stored in USB Key, count of votes result is encrypted; Be transferred through the count of votes result of encryption.Guard station election system server is provided with special ftp client software, and guard station end connects main meeting-place end Ftp file server by this software in private security net, carries out uploading/down operation.
The present embodiment is by completing count of votes in each delegation guard station, and count of votes result, after data encryption, realizes gathering to main meeting-place by secure network transmission, and then complete whole election count of votes task, without the need to transporting ballot paper, security is high, risk is low, and on the life of the people without impact.
Embodiment 2
The embodiment of the present invention 2 also provides a kind of point of group's election system.The difference of the present embodiment and embodiment 1 is: in the present embodiment, and vote-counting center's server is made up of key distribution servers and count of votes server, and guard station election system server is made up of guard station voting server and guard station front-end server.Parts only different from embodiment 1 to the present embodiment is below set forth, and remainder, because of similar to Example 1, will repeat no more herein.
As shown in Figure 2, in the present embodiment, key distribution servers is used for generating and configuration session key, and by session key stored in USB Key; Count of votes server communicates with main meeting-place front-end server, for carrying out data deciphering according to the session key stored in USB Key to the count of votes result through encryption, adding up all field delegations and dividing a count of votes result for election, generating final count of votes result.Guard station voting server communicates with guard station front-end server, dividing a count of votes result for election, encrypting according to the session key stored in USB Key to count of votes result for adding up each delegation; Guard station front-end server communicates with main meeting-place front-end server with guard station voting server respectively, for obtaining voting pattern, and the data integrity of checking voting pattern; Be transferred through the count of votes result of encryption.
The function that vote-counting center's server and guard station election system server need complete by the present embodiment, divides separately and has been gone by two servers, alleviate the burden of individual server, and whole system is run faster, system works is also more stable.
working-flow:
The principle of work of embodiment 1 and embodiment 2 is similar.Below for embodiment 2, the workflow of point group's election system that embodiment 1 and embodiment 2 provide is described:
(1) preproduction phase: generate account and key
Main meeting-place front-end server is that the user of access this host FTP file transmission service distributes a public login account and password, this login account and password are provided to each guard station operator by the mode printing expressly strip, to conduct an election the acquisition of pattern and the transmission of enciphered data for logging in ftp server.
It is that the USB Key of all ready states (also namely in use) generates a unified encryption key CryptKey that key distribution servers utilizes initial key to generate software, and this key is stored in USB Key.Encryption method can adopt the 3DES symmetric encipherment algorithm carried such as but not limited to USB Key, and namely encryption key is decruption key, and client and server enciphering/deciphering data all use this key.In actual use, need to use multiple USB Key, the key of generation can be stored in the USB Key of all uses in batches.
(2) voting pattern distribution
Main meeting-place generates and tests by after voting pattern, is published in ftp server by voting pattern file and hash value thereof, and main meeting-place operating personnel notify that each guard station operating personnel can download up-to-date voting pattern.
After obtaining main meeting-place notice, guard station operating personnel, by private network, coordinate special FTP transmitting software, use the FTP Account Logon main meeting-place front-end server distributed, download up-to-date voting pattern, and verify the integrality of its data.Then utilize USB flash disk (or other modes) that voting pattern is copied to guard station voting server, import voting pattern, carry out election preliminary work.
(3) group's ballot is divided
Each field delegation divides a ballot, after each delegation finishes ballot paper, generates this count of votes result Result [Hotel ID] [Delegation ID].
Use client dedicated encrypted software, the USB Key in conjunction with distribution is encrypted count of votes result, carries out hash value calculating and is packaged into the first packet together with ciphertext, copy the first packet USB flash disk to guard station front-end server to ciphertext.Particularly, first final count of votes result in resident dataset storehouse is derived, by being loaded into the count of votes result of expressly XML format, expressly will pass to USB Key, the hardware 3DES algorithm combining encryption ciphering key ryptKey utilizing USB Key to carry is to being expressly encrypted, can use simultaneously, such as but not limited to SHA-1 algorithm, hashed value process be carried out to the file after encryption, hashed value and encrypt file are packaged into the second packet.
(4) statistics
Guard station front-end server access ftp server, uploads the second packet.
Main meeting-place front-end server verifies the integrality of ciphertext in the second packet uploaded, ciphertext after checking utilizes USB flash disk to be copied to vote-counting center's server, use the special decryption software of server end, USBKey in conjunction with distribution carries out data deciphering operation, and after confirmation, this count of votes result can include net result statistics in.Particularly, when carrying out the integrity verification of transfer files, after obtaining the second packet, use file in SHA-1 proof of algorithm packaging file whether complete; Software decryption class of operation is similar to encrypting step, uses reverse operating, and each guard station count of votes result of final deciphering can pass through the quick tabulate statistics of enciphering/deciphering software.
After main meeting-place receives point group's count of votes result of all delegations, statistics produces final count of votes result, submits Bureau of the Assembly to.
(5) election terminates
After election count of votes result submits Bureau of the Assembly to, then elect count of votes to terminate, now will destroy the encryption key CryptKey of this session.
Embodiment 3
The embodiment of the present invention 3 provides a kind of point of group's poll information processing method, and the method can be applicable in point group's election system that embodiment 1 and embodiment 2 provide.As shown in Figure 3, the method comprises the steps:
Step S1: ballot paper process;
In each delegation guard station, ballot paper process is carried out to point group's poll.Certainly, this step separately can also propose candidate's process and invalid ballots process.
Step S2: count of votes;
Propose candidate's process and the result of invalid ballots process is added up to ballot paper process, separately, generate each delegation respectively and divide a count of votes result for election.
Step S3: encryption count of votes result;
According to symmetric key, count of votes result is encrypted.
Step S4: private network transmits;
Count of votes result through symmetric key encryption is transferred to main meeting-place by the private network of safety, and this private network communication mode is broadcast communication, grouies busy communication or point-to-point communication.
Step S5: verification of data integrity;
Main meeting-place termination receives the count of votes result of point group's election through encryption, and verifies the data integrity of count of votes result.
Step S6: deciphering count of votes result;
According to session key, data deciphering is carried out to the count of votes result through encryption.
Step S7: tabulate statistics.
Add up all field delegations and divide a count of votes result for election, generate final count of votes result.
In above-mentioned steps, step S1 ~ S3 completes in guard station, and step S5 ~ S7 completes in main meeting-place.The above-mentioned working-flow to embodiment 1 and embodiment 2 has contained the detailed introduction to the present embodiment method, therefore, has no longer repeated some details in the method herein in introducing, specifically can with reference to above-mentioned working-flow.
The foregoing is only preferred embodiment of the present invention, not in order to limit the present invention, all any amendments done within the spirit and principles in the present invention, equivalent replacement and improvement etc., all should be included within protection scope of the present invention.