Express delivery management method and system for preventing information leakage
Technical Field
The invention belongs to the technical field of information security, and particularly relates to an express delivery management method and system capable of protecting personal information security by using a two-dimensional code technology.
Background
The rapid development of electronic commerce drives the development of offline express delivery industry, according to statistics of the state post and government offices, by 20 days in 12 months in 2016, the Chinese express delivery package volume breaks through 300 hundred million, and the first in the world, particularly in the period of 'twenty-one' the express delivery package volume exceeds 37 hundred million, which is increased by 44.5 percent on year-by-year basis. When 24 days 11 and 13 months in the two eleven years 2017, postal and express enterprises can collectively collect 8.91 hundred million express items, the consistence increases by 32.2 percent, according to information display issued by the national post and government office in 11 and 12 days, and according to monitoring data display of the national post and government office, the main electric enterprise and enterprise can jointly generate 8.5 million express logistics orders all day long, and the consistence increases by 29.4 percent; each post and express enterprise processes 3.31 hundred million pieces all day, and the increase is 31.5 percent on year-on-year basis. With the continuous development and growth of the express delivery industry, the national economic development is promoted, convenience is brought to the life of people, and meanwhile, a great deal of threat is brought to the life of people.
First, express delivery needs to pass through a plurality of delivery network points, and each network point can obtain part or all of the information of the user, and the user information leakage probability is increased.
Secondly, in the link that each delivery network sends the goods to the receiver, the courier can obtain the customer information on the first hand, and the courier of each express company has different qualities and qualities, which is easy to cause the leakage of the customer information.
Therefore, it is expected that express workers at any link have fewer chances to obtain user information, and the better the express workers at any link. In recent years, the property loss of people and even life threatening events caused by the leakage of express information are frequently seen, and the user information on the express bill is completely exposed to the public sight, so that the express bill provides a chance for lawbreakers. In 2015, 26 th express delivery regulations (survey comments) in the state stipulate that express companies must standardize management systems to ensure user information security. Related laws and regulations and systems ensure the information safety of users to a certain extent, but the popularization is slow and the pertinence is not strong.
At present, a plurality of schemes are provided at home and abroad aiming at the problem of information leakage of express waybills, one is an express parcel label method, a user directly pulls one end of a label after receiving a parcel to easily tear off related information by utilizing a special express label, and the express information is easily illegally photographed or recorded in the express transportation process due to the fact that the express information is exposed outside; the other method is a K-anonymous model method, which still keeps the name and the telephone number of the user on the express bill and does not meet the requirement of confidentiality. At present, a method for hiding user information in a two-dimensional code mode and generating a novel privacy list based on the hidden user information does not exist.
In addition, various disputes often occur in the process of delivering express at present, for example, in order to save trouble, for some couriers, before express delivery is not successfully delivered, false sign-off caused by batch sign-off in a system is performed in advance, or overtime sign-off caused by that a receiver takes away express but has not signed-off in the system is performed, or express delivery is falsely received by illegal personnel, and the like.
Disclosure of Invention
In order to overcome the defects of the prior art in the background art, the invention provides an express management method capable of protecting personal information safety and an express management system based on the method.
An information leakage prevention express delivery management method comprises the steps of user information receiving, privacy bill generation, courier delivery and recipient signing; the method is characterized in that:
the user information receiving is that the express server receives a request of a user and stores the mail information filled by the user at a user client into a database;
the privacy bill generation is that the bill processing client side calls information stored in a database by a user and guides the information into a privacy bill single template to generate and print the privacy bill; the generated privacy list comprises four areas, and the four areas are sequentially from top to bottom: the first area displays express company information, and the express company information comprises an express company trademark and 12 goods codes, wherein the goods codes are 12, the 1 st to 2 nd places represent provinces from left to right, the 3 th to 4 th places represent cities, the 5 th to 6 th places represent areas, the 7 th to 8 th places represent streets, and the 9 th to 12 th places are goods taking codes and are randomly generated by a system; the second area displays the address of the receiver; the third area displays order information, the third area is divided into a left area and a right area by a vertical line, the left side of the vertical line displays an order two-dimensional code, and the right side of the vertical line displays a goods taking code, order receiving time, an article name, a charging weight and other remarks; the fourth area displays the address of the sender;
after the express delivery of the courier reaches a delivery point to which an address of a recipient belongs, the courier scans an order two-dimensional code on the left side of a third area of the privacy menu through a receiving and delivering client, the receiving and delivering client sends an http request to an express server, then the express server operates a database to inquire a mobile phone number of the recipient, and sends a short message to inform the recipient of taking the delivery or receiving a reply short message through an SMS server, and the courier cannot see personal information of the recipient in the whole process;
the receiver signs for receiving, namely the receiver scans the order two-dimensional code on the left side in the third area of the privacy list through the user client authorized to receive the goods to obtain a goods receiving page for confirming the goods receiving operation; the authorized receiving user client is the user client which receives the authorization information sent by the sender client before scanning the order two-dimensional code, if the receiver needs to be received by others, the authorization information needs to be forwarded to the receiver client so that the receiver client becomes the authorized receiving user client, and if the receiver does not install the app, a link for registering the app is installed for the receiver; if the user client used for scanning the order two-dimensional code does not receive the authorization information in advance, the user client does not enter a sign-in page when scanning the order two-dimensional code, and if the order is confirmed to be received, the user client scans the two-dimensional code again to be invalid.
An information leakage prevention express delivery management system comprises an express delivery server, an SMS server, a database, a user client, a bill processing client and a delivery receiving client; the express server is a network server for receiving the request of the client to process order information, the SMS server is a server for sending pickup short messages to the user, the database is a network database for storing user and order information, the user client is an application program which can enable the user to input order information, scan two-dimensional codes and receive authorization functions, the order processing client is an application program used by couriers, and can generate a privacy bill according to the order number provided by the user and the corresponding order information in the database, the receiving and dispatching client is an application program which is used by the courier and has the function of scanning the two-dimensional code, when scanning the order two-dimensional code in the privacy order, sending an http request to an express server, then the express server operates the database to inquire the mobile phone number of the receiver, and sends a notification short message to the mobile phone of the receiver through the SMS server.
Has the advantages that:
1. the invention has the most prominent characteristic that most information of a user is hidden through the two-dimensional code, in the process of delivery, all levels of delivery areas can only know the address information of a sender/receiver, the real name and the contact way are replaced by the two-dimensional code, and only the database manager of the head office of an express company, the order processing client and the sender/receiver know the address information. The courier uses the two-dimension code area on the receiving and dispatching client to scan the menu, and the server sends a short message to inform the receiver to take the delivery or receive a reply short message to send the delivery to the home. The current market bills do not hide all user information, and privacy disclosure is avoided to a great extent.
2. The receiving mode has strong safety. Only the user authorized to receive the mail can confirm the mail, and the user can be replaced only by the authorization of the receiver when the user is replaced, so that the risk of malicious falsifying by other people is avoided.
3. The responsibility is clear, and the receiving can be confirmed only by scanning the order two-dimensional code on site by an authorized user, so that the condition that some couriers are delivered and processed in the system before the express is actually delivered to the addressee for trouble saving is effectively avoided, the condition that the addressee takes the express away but signs the express over time is also avoided, and the responsibility division has clear basis when the express is in dispute.
4. The practical applicability of the 12-bit goods coding on the bill is strong, wherein the last 4 bits are the goods taking codes randomly generated by the system, and the goods taking codes are independently placed on the order information column and are convenient to check.
5. The invention can be suitable for all logistics systems and express delivery systems at the present stage, and has strong transportability
6. After the user finishes ordering, the user can obtain the picture of the privacy order, and the user can obtain logistics information by scanning the picture.
Drawings
Fig. 1 is a flow chart of express delivery of the present invention.
Fig. 2 is a privacy mask single reference style used by the present invention.
Detailed Description
The present invention will be described in detail with reference to examples.
Example 1 System configuration of the invention
The information leakage prevention express management system comprises an express server, an SMS server, a database, a user client, a bill processing client and a receiving and dispatching client. Wherein the express delivery server is a network server for receiving the order information processed by the instruction of the client, the SMS server is a server for sending short messages to inform recipients to take the mail, the database is used for storing user and order information, the order information may be stored in the form as shown in table 1, the user client is an application program that enables a user to input order information and has a function of scanning a two-dimensional code, the order processing client is an application program for a courier, and can generate a privacy bill according to the order number provided by the user and the corresponding order information in the database, the receiving and dispatching client is an application program which is used by the courier and has the function of scanning the two-dimensional code, when the order two-dimensional code in the privacy order is scanned, an http request can be sent to the server, and then the server sends a short message to a receiver.
Form of storing order data in the database described in Table 1
Example 2 mail Process
When a user sends a mail, the user registers personal information through a user client installed on a mobile phone, and inputs mail sending information, including: sender name, address, phone, recipient name, address, phone, etc. And after the information is submitted, the express delivery server receives the request of the user, stores the mailing information filled by the user into the database, generates an order number and returns the order number to the user. The user can select to make an appointment for the courier to get the courier home or send the courier to the courier delivery point, the user can browse the generated privacy bill picture through the user client side, the picture can be scanned to obtain logistics information, the courier can input an order number provided by the user at the bill processing client side to print the privacy bill, the courier can also use the receipt and dispatch client side to scan a two-dimensional code of the privacy bill of the user to authorize the courier server to call order information submitted by the user from an information base, and the information is imported into the bill processing client side of the courier to print the privacy bill.
The generated privacy list is shown in fig. 2, and includes four regions, which are, in order from top to bottom: the first area displays express company information, including an express company trademark logo and a goods code, the goods code is 12 bits in total, in a sample sheet shown in fig. 2, AB represents province, CD represents city, EF represents area, GH represents street, ILJK is system generated random goods picking code, the second area displays a receiver address, the area only displays an address, but does not display information related to personal privacy and easy leakage, such as receiver name, telephone, and the like, the third area displays order information, the left side column is an order two-dimensional code, the right side column includes a goods picking code, order receiving time, an article name, charging weight, and the like, the article information can be selectively hidden into the two-dimensional code if hidden, the fourth area displays a sender address, and the area only displays the sender address, but does not display information related to personal privacy and easy leakage, such as sender name, telephone, and the like. After the sender sends the mail, the server informs the receiver of the receiving authorization password and the sender information through the short message. If the receiver installs the user client, the receiver client also receives the sender information and the authorization information, and meanwhile, the mobile phone client of the receiver is authorized by the server to be the goods receiving user client.
Example 3 Dispatch and sign-on Process
And after receiving the reply short message from the client, the client sends the short message to the courier according to the appointed time of the short message. The receiver scans the order two-dimensional code in the third area of the privacy bill through the user client authorized to receive the goods to obtain a receiving link for confirming the receiving of the goods; if the receiver needs to be collected by others, the authorization information needs to be forwarded to the client of the collector so that the client of the collector becomes a user client authorized to receive goods; if the user client used for scanning the order two-dimensional code does not receive the authorization information in advance, the receiving link cannot be obtained when the order two-dimensional code is scanned, the receiving cannot be confirmed, and if the order is normally confirmed, the two-dimensional code is scanned again and is invalid.
According to the express management method and the express management system, due to the fact that the receiving can only be confirmed by the authorized user through field scanning of the two-dimensional code of the order, the signing-in time displayed in the system is the time when the addressee actually receives the express, the situations that the addressee signs in a false way, the addressee signs in an overtime way, other people maliciously give off the express and the like in the delivery process are effectively avoided, and when the express is in dispute, the division responsibility has a clear basis. Meanwhile, only address information is arranged on the bill and sensitive information such as telephone and name which relates to personal privacy is not arranged on the bill, so that the bill does not need to be torn off from a packaging box when the express package is discarded after the receiver finishes receiving the goods, and personal information cannot be leaked.