A resource authorization use method and system based on shared zone

By directly setting the sharing scope and access rights in the sharing area, the problem of inefficient resource management under the centralized authorization platform is solved, efficient sharing and use of resources are achieved, the authorization process is simplified, and utilization efficiency is improved.

CN119249447BActive Publication Date: 2025-10-14SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411306568.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-10-14
Estimated Expiration
2044-09-19

AI Technical Summary

Technical Problem

The existing resource management system relies on a centralized authorization platform, resulting in cumbersome application and approval processes and low efficiency. It is difficult to meet the needs of modern enterprises for efficient resource utilization and rapid response, and there are problems of resource waste and duplicate authorization.

Method used

By creating a shared zone, the initiator designates participants and associates a resource directory. The provider directly sets the sharing scope and access rights within the zone, and uses interfaces or data exchange tools to implement resource authorization, avoiding the traditional application approval process and ensuring the consistency of authorization information.

Benefits of technology

It achieves efficient sharing and use of resources, simplifies the authorization process, improves utilization efficiency, reduces the approval pressure on providers, and prevents duplicate authorization and waste of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119249447B_ABST
    Figure CN119249447B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of government affair service data sharing and opening, in particular to a resource authorization use method and system based on a shared special area, which comprises the following steps: a special area is created by an initiator and specified participants: a shared special area is created by the initiator, and each party participating in the special area is specified, the participants can only be added by the initiator through a specific mode, and management control of the use range of the special area is ensured; resource association: through an interface of a data directory system, the participants associate their directory lists with the special area, resources under the directory are hung to the special area, association information is stored in a relational database, and the association information is soft-associated with special area information; beneficial effects are that: through the mode, departments in the shared special area can freely share and exchange resources without applying for an audit process, and the use efficiency of the resources is improved. Non-related personnel can be prevented from applying for corresponding resources, and the approval pressure of a provider is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of government service data sharing and opening, in particular to a resource authorization use method and system based on a shared special area. BACKGROUND

[0002] The government service data sharing and opening technology generates authorization based on department application records, and then the user obtains the shared content by using the authorization. This technology requires the user to select the resources shared by the provider in the sharing platform, and then initiates an application to the provider. After the provider approves, the user can obtain the resources.

[0003] In the traditional resource authorization use mode, the provider and the user of the resources usually need to go through a cumbersome application and approval process to realize the sharing and use of the resources. This mode is not only inefficient, but also may cause waste and repeated authorization of resources. With the continuous development of data sharing and cloud computing technology, higher requirements are put forward for efficient management and flexible authorization of resources.

[0004] Most existing resource management systems rely on centralized authorization platforms to control resource access permissions through complex application and approval processes. However, this approach is not sufficient when dealing with large-scale, multi-level resource sharing, and it is difficult to meet the needs of modern enterprises for efficient use and rapid response of resources. SUMMARY

[0005] The purpose of the present application is to provide a resource authorization use method and system based on a shared special area to solve the problems raised in the background technology.

[0006] To achieve the above purpose, the present application provides the following technical solution: a resource authorization use method based on a shared special area, the method comprising the following steps:

[0007] The initiator creates a special area and specifies participants: the initiator creates a shared special area and specifies the parties participating in the special area. The participants can only be added by the initiator through a specific way to ensure the management and control of the use range of the special area;

[0008] Resource association: through the interface of the data directory system, the participants associate their directory lists with the special area, realize the hanging of the resources under the directory to the special area, and store the association information in the relational database and perform soft association with the special area information.

[0009] Preferably, the method further comprises the following steps:

[0010] Resource management: the resource provider manages the attributes of the upper directory of the resources in the special area, sets the sharing range and access permissions of the resources by setting the sharing range of the directory, and includes the authorization verification and cancellation process before moving the resources out of the shared special area;

[0011] Authorization management: The resource provider directly authorizes other participants in the special zone, sets usage rules, and associates the rules with the users, without the traditional application and approval process.

[0012] Preferably, the method further comprises the following steps:

[0013] Authorization information synchronization: Through the dubbo interface or rest interface, the authorization information of the special zone is pushed to the application authorization system of the platform to ensure the consistency of the shared special zone authorization information and the application system authorization information, and to prevent repeated authorization.

[0014] Resource usage mode: According to the resource type, such as interface service, file or library table, different modes such as interface authorization code and data exchange task are adopted to enable the user to obtain and use the resource, and record the resource usage operation.

[0015] Preferably, the method further comprises the following detailed steps about resource usage rules:

[0016] Interface type resource: Three default usage rules, including interface call frequency, usage period and available time range, are designed for interface type resources, and the provider creates custom rules based on the default rules and associates the rules with the users to realize authorization.

[0017] Library table type resource: The default rule is all fields of the shared library table, the provider selects the authorized fields to create new rules, and pushes the rules to the exchange tool through the data exchange system interface to generate data exchange tasks for the user to transfer data.

[0018] File type resource: The provider directly associates the file resource with the user to complete the authorization without additional rule configuration.

[0019] Preferably, the method further comprises the following authorization cancellation and permission change steps:

[0020] Authorization cancellation: When the provider cancels the association between the user and the usage rule, the special zone automatically cancels the authorization of the user, and pushes the cancellation authorization information through the corresponding interface, such as gateway and data exchange system, to ensure that the user cannot access the canceled resource again.

[0021] Permission change: The provider modifies the set usage rule at any time in the special zone, and updates the authorization information through the corresponding mechanism to adapt to the changes of resource usage demand.

[0022] A resource authorization and usage system based on a shared special zone, the system comprising:

[0023] A special zone creation module for creating a shared special zone by an initiator and specifying participants to ensure the management ability of the initiator on the usage range of the special zone.

[0024] The resource association module is configured to associate the directory resources of the participants to the special zone through a data directory system interface and store the association information in a relational database in soft association with the special zone information.

[0025] The resource sharing management module is configured to allow the resource provider to set a sharing range and access permission of the resource in the special zone, including an authorization check function before the resource is moved out of the shared special zone.

[0026] The resource authorization module is configured to allow the resource provider to directly authorize other participants in the special zone, and to achieve authorization by setting usage rules and associating the rules with the users, without the traditional application and approval process.

[0027] The authorization synchronization module is configured to push the authorization information of the special zone to an application authorization system of the platform through a dubbo interface or a rest interface, to maintain consistency of the authorization information and prevent repeated authorization.

[0028] Preferably, the resource sharing management module further comprises:

[0029] The permission control unit is configured to limit the shared resource in the special zone by modifying the display range of the directory and the resource, and not to display the shared resource externally on the sharing platform.

[0030] The authorization check unit is configured to check whether the resource has been authorized to other users before the resource is moved out of the shared special zone, and to require the authorization to be cancelled before the resource is moved out.

[0031] Preferably, the resource authorization module further comprises:

[0032] The rule configuration unit is configured to generate different types of resource usage rules, including high, medium and low frequency usage rules of interface type resources, field authorization rules of library table type resources, and direct authorization rules of file type resources.

[0033] The rule application unit is configured to associate the configured usage rules with the users in the special zone, to achieve authorization management of the resource.

[0034] Preferably, the rule configuration unit further comprises:

[0035] The interface rule configuration sub-unit is configured to set the values of the interface call frequency, usage period and available time range according to the upper limit of the gateway performance, to create a custom interface usage rule.

[0036] The library table rule configuration sub-unit is configured to select the library table fields to be authorized, to create a new library table resource usage rule.

[0037] The file rule configuration sub-unit is configured to directly associate the resource with the user, without additional rule configuration.

[0038] Preferably, the system further comprises:

[0039] A resource usage recording module is configured to record all resource usage operations, including interface calls and data exchange tasks, to facilitate the initiator and the participant to check resource usage and audit tracking;

[0040] An authorization revocation module is configured to automatically cancel the authorization of the user after the resource provider cancels the association between the user and the usage rules, and synchronously update the authorization record and the system state.

[0041] Compared with the prior art, the present application has the following advantages:

[0042] The resource authorization usage method and system based on the shared special area provided by the present application can freely share and exchange resources in the shared special area without the need for an application and review process, thereby improving the resource usage efficiency. The application can also prevent non-related personnel from applying for corresponding resources, thereby reducing the approval pressure of the provider. The user can directly use the resources through the shared special area without the need to enter the shared platform to find the required resources and then apply for them, thereby simplifying the usage steps. BRIEF DESCRIPTION OF DRAWINGS

[0043] Figure 1 The method flowchart of the present application. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solutions of the present application clear and complete, and the advantages more clear and obvious, the embodiments of the present application are further described in detail below in combination with the drawings. It should be understood that the specific embodiments described herein are part of the embodiments of the present application, rather than all the embodiments, and are only used to explain the embodiments of the present application, and do not limit the embodiments of the present application. All other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0045] Embodiment one, please refer to Figure 1 The present application provides a technical solution: a resource authorization usage method based on a shared special area, which comprises the following steps:

[0046] 1. The initiator creates a private zone and designates participants. The participants can only be designated by the initiator and cannot be added through other means, thereby ensuring the initiator's management capabilities for the scope of use of the private zone. Resource association is performed according to the dimensions of the data directory, that is, all resources under the data directory are directly associated. The private zone uses the rest interface of the directory system to obtain the directory list of the participants, and then the participants select the directory and associate it with the corresponding private zone, thereby realizing the hanging of the resources under the directory to the private zone. The association information is directly stored in the relational database and is soft-associated with the private zone information.

[0047] 2. In the private zone, the resource provider (i.e., the original uploader of the resource) manages the attributes of the upper-level directory of the resource in the private zone and sets the sharing range and access rights of the resource by setting the sharing range of the directory. Specifically, the resource provider can choose to limit the accessibility of the resource to the private zone. The provider can also move the resource out of the shared private zone. Before moving out, the shared private zone will verify the authorization of the resource. If the resource has been authorized to other users in the private zone, the resource must be de-authorized before it can be moved out of the private zone. The private zone pushes the sharing range of the private zone directory to the directory system and the resource system, modifies the display range of the directory and the resource, and makes them not publicly displayed on the sharing platform.

[0048] 3. The resource provider directly authorizes other participants in the private zone without going through the traditional application and approval process. It only needs to set the usage rules and associate them with the users. The participants of the private zone can also directly browse the resources in the private zone and apply for authorization for resources that are not shared to themselves through the normal application process.

[0049] 4. The private zone uses the dubbo interface or the rest interface to communicate with the platform's application authorization and push the authorization information to the platform's application authorization system to ensure the consistency of the shared private zone authorization information and the application system authorization information and avoid repeated authorization.

[0050] 5. After the authorization of the shared private zone, different methods are used to let the users use the resources according to the different types of authorized resources. For interface service type resources, the rest interface is used to obtain the interface authorization code and usage document to provide to the users, thereby enabling the users to correctly call the interface. For file or library table type resources, the interface of the encapsulated data exchange tool (such as nifi) is called to generate an exchange task, enabling the users to transfer the resources to their own environment through the exchange tool. All resource usage operations are recorded for the convenience of the initiator and the participants to view.

[0051] 6. The shared zone will generate different resource usage rules for the provider to choose according to the different types of resources. The provider will associate the usage rules with the users in the zone to complete the authorization of the users, and the users will use the resources according to the restrictions of the usage rules. Different types of resource rules are as follows

[0052] 1) Interface type resource, the zone designs three default usage rules of high frequency, medium frequency and low frequency. The values of interface call frequency, usage period and available time range of each usage rule are different. The rule index is set according to the performance upper limit of the gateway, and the provider creates its own usage rule according to the default rule. After creating the rule, the user is associated with the rule to complete the authorization of the user. The usage rule will be pushed to the gateway after the user binds the application of the usage interface, and then the gateway will control the user's call according to the usage rule. When the user is moved out of the usage rule, the de-authorization information will be directly pushed to the gateway, so that the user cannot use the interface again

[0053] 2) Library table type resource, the default rule is to share all fields of the library table. The provider can select the fields to be authorized and create a new usage rule. After the user selects the rule, the zone will push the rule to the data exchange tool through the interface of the data exchange system, and the exchange tool will generate an exchange task according to the rule. The user transfers data to its own environment through the exchange tool. A rule can be used to authorize multiple users. When the user is moved out of the rule, the interface of the exchange system is called again to stop the data exchange task, so as to stop the sharing of data.

[0054] 3) File type resource, the provider directly associates the resource with the user to complete the authorization, without additional rule configuration.

[0055] Embodiment two, on the basis of embodiment one, a resource authorization and usage system based on a shared zone is proposed, the system comprises:

[0056] The zone creation module is used to create a shared zone by an initiator and specify participants, to ensure that the initiator has the management ability of the usage range of the zone;

[0057] The resource association module is used to associate the directory resources of the subordinates of the participants to the zone through the data directory system interface, and store the association information in the relational database and perform soft association with the zone information;

[0058] The resource sharing management module allows the resource provider to set the sharing range and access permission of the resource in the zone, including the authorization verification function before moving the resource out of the shared zone; further comprising: a permission control unit, used to limit the shared resource in the zone by modifying the display range of the directory and the resource, and not display externally on the sharing platform;

[0059] The authorization checking unit is configured to check whether the resource has been authorized to other users before the resource is removed from the shared private zone, and to require that the authorization be cancelled before the resource is removed.

[0060] The resource authorization module allows the resource provider to directly authorize other participants in the private zone. The authorization is achieved by setting usage rules and associating the rules with the users, without the traditional application and approval process. The resource authorization module further includes:

[0061] The rule configuration unit is configured to generate different types of resource usage rules, including high-frequency, medium-frequency, and low-frequency usage rules for interface type resources, field authorization rules for library table type resources, and direct authorization rules for file type resources.

[0062] The rule application unit is configured to associate the configured usage rules with the users in the private zone, to achieve authorization management of the resources.

[0063] The rule configuration unit further includes:

[0064] The interface rule configuration sub-unit is configured to set the values of interface call frequency, usage period, and available time range according to the upper limit of the gateway performance, to create a custom interface usage rule.

[0065] The library table rule configuration sub-unit is configured to select the library table fields to be authorized, to create a new library table resource usage rule.

[0066] The file rule configuration sub-unit is configured to directly associate the resource with the user, without additional rule configuration.

[0067] The authorization synchronization module is configured to push the authorization information of the private zone to the application authorization system of the platform through a dubbo interface or a rest interface, to maintain consistency of the authorization information and prevent repeated authorization.

[0068] The system further includes:

[0069] The resource usage record module is configured to record all resource usage operations, including interface calls and data exchange tasks, to facilitate the initiator and the participant to check resource usage and audit tracking.

[0070] The authorization revocation module is configured to automatically cancel the authorization of the user after the resource provider cancels the association between the user and the usage rule, and to synchronously update the authorization record and the system state.

[0071] Although embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements, and variations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. A resource authorization method based on a shared zone, characterized by: The method comprises the following steps: The initiator creates a zone and designates participants: The initiator creates a shared zone and designates the parties that will participate in it. Participants can only be added by the initiator, ensuring management and control over the use of the zone. Resource association: Through the interface of the data directory system, participants associate their directory lists with the zone, thus attaching the resources under the directory to the zone. The association information is stored in the relational database and soft-linked with the zone information. The following steps are also included: Resource management: Resource providers manage the properties of resource parent directories within a zone. They set the sharing scope and access permissions of resources by setting the directory's sharing scope, including the authorization verification and cancellation process before removing resources from the shared zone. Authorization management: Resource providers can directly authorize other participants to use resources within the zone by setting usage rules and associating them with users, eliminating the need for traditional application and approval processes. The following steps are also included: Authorization information synchronization: Push the zone's authorization information to the platform's application authorization system through the dubbo interface or rest interface to ensure the consistency of the shared zone's authorization information with the application authorization system's authorization information, and prevent duplicate authorization; Resource usage method: Based on the resource type, such as interface service, file or library table, different methods such as interface authorization code and data exchange task are used to allow users to obtain and use resources, and resource usage operations are recorded.

2. The resource authorization method based on a shared zone according to claim 1, characterized in that: The following detailed steps on resource usage rules are also included: Interface-type resources: Three default usage rules are designed for interface-type resources: high frequency, medium frequency, and low frequency. These rules include the frequency of interface calls, usage period, and available time range. Providers create custom rules based on the default rules and associate the rules with users to implement authorization. Library and table type resources: The default rule is for all fields in the shared library and table. The provider selects the authorized fields to create new rules and pushes the rules to the exchange tool through the data exchange system interface, generating a data exchange task for the user to transfer data. File type resources: The provider directly associates the file resource with the user to complete authorization, without the need for additional rule configuration.

3. The resource authorization method based on a shared zone according to claim 1, characterized in that: It also includes the following steps for revoking authorization and changing permissions: Authorization revocation: When the provider cancels the association between the user and the usage rules, the zone automatically cancels the user's authorization and pushes the revocation information through the corresponding interface, such as the gateway and data exchange system, to ensure that the user can no longer access the revoked resources; Permission changes: The provider may modify the established usage rules at any time within the zone and update the authorization information through the corresponding mechanism to adapt to changes in resource usage needs.

4. A resource authorization system based on a shared zone according to the resource authorization method based on a shared zone according to any one of claims 1 to 3, characterized in that: The system comprises: The zone creation module is used by the initiator to create a shared zone and designate participants, ensuring the initiator's ability to manage the zone's scope of use; The resource association module is used to associate the directory resources of the participants with the zone through the data directory system interface, and store the association information in the relational database to softly associate it with the zone information; The resource sharing management module allows resource providers to set the sharing scope and access rights of resources within the zone, including authorization verification before moving resources out of the shared zone; The resource authorization module allows resource providers to directly authorize resources to other participants within the zone. Authorization is achieved by setting usage rules and associating the rules with the users, without the need for traditional application and approval processes. The authorization synchronization module is used to push the zone's authorization information to the platform's application authorization system through the dubbo interface or rest interface to maintain the consistency of the authorization information and prevent duplicate authorization.

5. The resource authorization system based on a shared zone according to claim 4, characterized in that: The resource sharing management module also includes: The permission control unit is used to restrict shared resources to a dedicated area by modifying the display scope of directories and resources, preventing them from being displayed externally on the sharing platform. The authorization verification unit is used to verify whether the resource has been authorized to other users before it is moved out of the shared zone, and requires that the authorization be revoked before it can be moved out.

6. The resource authorization system based on a shared zone according to claim 4, characterized in that: The resource authorization module also includes: The rule configuration unit is used to generate different types of resource usage rules, including high-frequency, medium-frequency, and low-frequency usage rules for interface-type resources, field authorization rules for library and table-type resources, and direct authorization rules for file-type resources. The rule application unit is used to associate the configured usage rules with users in the zone to implement authorized resource management.

7. The resource authorization system based on a shared zone according to claim 6, characterized in that: The rule configuration unit further includes: The interface rule configuration subunit is used to set the values ​​of interface call frequency, usage period, and available time range according to the gateway performance upper limit, and create customized interface usage rules; The library table rule configuration subunit is used to select the library table fields you want to authorize and create new library table resource usage rules; The file rule configuration subunit is used to directly associate resources with users without the need for additional rule configuration.

8. The resource authorization system based on a shared zone according to claim 6, characterized in that: The system also includes: The resource usage record module is used to record all resource usage operations, including interface calls and data exchange tasks, so that the initiator and participants can view resource usage and audit trails. The authorization revocation module is used to automatically cancel the user's authorization after the resource provider cancels the association between the user and the usage rules, and synchronously update the authorization record and system status.

Citation Information

Patent Citations

  • Catalog management system used for government affairs information platform

    CN104933070A

  • Big data-based industry-university-research information resource sharing service system

    CN118505447A