Ontology-based data space dynamic access control method, equipment and medium
By building a data dictionary connector and a basic connector, a mapping relationship between the global ontology and the local ontology is established, which solves the permission change requirements in cross-organization collaboration in the data space, realizes fine-grained access control, and improves data security and policy adaptability.
Patent Information
- Application Number
- CN202510453967.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-29
AI Technical Summary
Existing data space technologies are difficult to achieve dynamic access control in cross-organizational collaboration, and cannot respond to permission changes in a timely manner, resulting in insufficient data security and policy adaptability.
By building a data dictionary connector and basic connector, establish semantic mapping and data field mapping between the global ontology and the local ontology, construct policy relationships, obtain data requests, and achieve fine-grained access control through virtual knowledge graph mapping.
It realizes dynamic analysis of data space access policies, improves the adaptability of data security and dynamic policy changes, and meets the needs of distributed management.
Smart Images

Figure CN120387176A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data space, and in particular, to an ontology-based dynamic access control method, device, and medium for data space. Background Art
[0002] A data space refers to a data sharing and collaboration environment that crosses organizations and domains, and its goal is to achieve secure, flexible circulation, and interoperability of data among different participants. With the continuous development of data space technology, the dynamic access control method for data space has become an important development direction, mainly involving how to ensure that data can be correctly understood and used in different semantic, technical, and system environments.
[0003] In practical applications, since the interoperability method of existing data space technology relies on standardized interfaces or formats, it is difficult to ensure semantic consistency and has poor adaptability for dynamically complex scenarios. For the management and dynamic change of resource policies, the existing technology cannot meet the distributed management requirements, and the rationality of policy deployment is insufficient. In terms of the organizational dimension and security dimension, the existing technology has the problem that the centralized access control policy is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner, and cannot meet the increasingly refined application requirements of data space technology. Summary of the Invention
[0004] Embodiments of this application provide an ontology-based dynamic access control method, device, and medium for data space, which solve the technical problem that the centralized access control policy in the existing technology is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner.
[0005] In a first aspect, embodiments of this application provide an ontology-based dynamic access control method for data space, which is characterized in that the method includes: constructing a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; establishing a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; establishing a data field mapping between the data source and the local ontology to obtain a second access mapping; constructing a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; obtaining a data request, and based on the data request and the first access mapping, determining the accessible fields corresponding to the identity of the requester through data access control; performing a policy relationship analysis on the accessible fields to obtain an access query statement; and obtaining fine-grained access data through virtual knowledge graph mapping according to the access query statement.
[0006] In an implementation manner of the present application, a mapping relationship is established between the global ontology and the local ontology to obtain a first access mapping, which specifically includes: configuring the role access fields of the rule library to obtain access rule data; based on the access rule data, determining the access mapping strategy through mapping strategy analysis; obtaining the mapping execution requirements, and according to the mapping execution requirements and the access mapping strategy, obtaining the first access mapping through mapping relationship construction.
[0007] In an implementation manner of the present application, a field mapping is established between the data source and the local ontology to obtain a second access mapping, which specifically includes: obtaining the data requirements of the data owner, and establishing the global policy of the policy library for the data requirements to obtain the local ontology instance; wherein, the global policy establishment is based on the SWAR rule library; based on the local ontology instance, determining the second access mapping through the virtual mapping construction of the data source and the local ontology.
[0008] In an implementation manner of the present application, based on the local ontology instance, constructing a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology, specifically including, the method further includes: obtaining the data owner policy based on the ORDL policy library, and setting the data owner policy as the data selection instance; inserting the data selection instance into the local ontology to establish a policy relationship between the data source and the local ontology.
[0009] In an implementation manner of the present application, based on the data request and the first access mapping, determining the accessible fields corresponding to the identity of the requester through data access control, specifically including: converting the data request into a SPARQL query statement, and inputting the SPARQL query statement into the data dictionary connector; through the rule library of the digital dictionary connector, performing query reasoning on the SPARQL query statement to obtain the accessible fields; wherein, the query reasoning is to query the instances associated with the resources and policies under the preset data negotiation.
[0010] In an implementation manner of the present application, performing policy relationship analysis on the accessible fields to obtain an access query statement, specifically including: based on the accessible fields, performing local ontology query through the basic connector to obtain the associated instances in the local ontology; according to the associated instances, rewriting the SPARQL query statement to obtain the access query statement.
[0011] In an implementation manner of the present application, according to the access query statement, obtaining fine-grained access data through virtual knowledge graph mapping, specifically including: calling the query interface of the preset virtual knowledge graph, and sending the access query statement to the virtual knowledge graph; based on the virtual knowledge graph, obtaining the access requirement data through data access request mapping analysis; summarizing the access requirement data to obtain the fine-grained access data.
[0012] In an implementation manner of the present application, after obtaining fine-grained access data through virtual knowledge graph mapping according to an access query statement, the method further includes: associating a global ontology with a local ontology based on a first access mapping and a second access mapping to obtain a global knowledge graph; constructing a unified query interface according to the global knowledge graph.
[0013] In a second aspect, an embodiment of the present application further provides an ontology-based data space dynamic access control device, characterized in that the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: construct a data dictionary connector and a basic connector; wherein the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; establish a data field mapping between the data source and the local ontology to obtain a second access mapping; construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; obtain a data request, and based on the data request and the first access mapping, determine accessible fields corresponding to the identity of the requester through data access control; perform policy relationship analysis on the accessible fields to obtain an access query statement; and obtain fine-grained access data through virtual knowledge graph mapping according to the access query statement.
[0014] In a third aspect, an embodiment of the present application further provides a non-volatile computer storage medium for ontology-based data space dynamic access control, storing computer-executable instructions, characterized in that the computer-executable instructions are set to: construct a data dictionary connector and a basic connector; wherein the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; establish a data field mapping between the data source and the local ontology to obtain a second access mapping; construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; obtain a data request, and based on the data request and the first access mapping, determine accessible fields corresponding to the identity of the requester through data access control; perform policy relationship analysis on the accessible fields to obtain an access query statement; and obtain fine-grained access data through virtual knowledge graph mapping according to the access query statement.
[0015] The embodiments of the present application provide a method, device, and medium for dynamic access control of an ontology-based data space. By connecting through a key connector, ontology mapping, and dynamic analysis of rule data, the technical problem that the centralized access control policy in the prior art is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner is solved, the dynamic analysis of the data space access policy is realized, and the data security of the dynamic change of the data space policy is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:
[0017] Figure 1 is a flowchart of a method for dynamic access control of an ontology-based data space provided by an embodiment of the present application;
[0018] Figure 2 is a schematic internal structure diagram of a device for dynamic access control of an ontology-based data space provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0020] The embodiments of the present application provide a method, device, and medium for dynamic access control of an ontology-based data space. By connecting through a key connector, ontology mapping, and dynamic analysis of rule data, the technical problem that the centralized access control policy in the prior art is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner is solved, the dynamic analysis of the data space access policy is realized, and the data security of the dynamic change of the data space policy is improved.
[0021] The technical solutions proposed in the embodiments of the present application will be described in detail below with reference to the drawings.
[0022] Figure 1 is a flowchart of a method for dynamic access control of an ontology-based data space provided by an embodiment of the present application. As Figure 1 shown, a method for dynamic access control of an ontology-based data space provided by an embodiment of the present application specifically includes the following steps:
[0023] Step 101, construct a data dictionary connector and a basic connector.
[0024] Among them, the data dictionary connector includes: a global ontology and a rule library; the basic connector includes: a data source, a local ontology, and a policy library.
[0025] Exemplarily, the basic connector is an interface or component that connects different data sources and systems, supports the transmission and interaction of data between systems, and is usually used to integrate the data and resources in a local system with the global ontology, ensuring the access, sharing, and synchronization of different resources and systems within the data space.
[0026] The data dictionary connector is a tool for connecting and mapping data dictionaries (i.e., data structures, terms, definitions, etc.) in different data sources. It can standardize the data structures in different systems and map them to the global or global-local ontology, ensuring interoperability between different systems.
[0027] The global ontology is a knowledge framework that is used to describe the unanimously recognized knowledge between different systems in the data space, and it contains the definitions of concepts, relationships, and rules.
[0028] The local ontology is a knowledge representation for a specific domain or system, focusing on specific knowledge and data structures. The local ontology can be developed and updated independently of the global ontology, allowing the system to be flexibly adjusted according to its own needs.
[0029] In this application, the rule library contains Rule, which defines the usage permissions, obligations, or prohibitions of digital assets. The rules include three subclasses: Permission, Prohibition, and Duty.
[0030] The Policy attributes contained in the policy library are: hasPolicy, which is used to associate with a specific rule (Rule); inheritFrom, which is used to represent the inheritance relationship between policies.
[0031] Asset is the object to which the policy applies, usually digital resources such as data, media files, etc. Its attribute is part0f, which is used to indicate that the asset belongs to an AssetCollection, that is, an asset collection, and the asset collection is a collection of multiple assets used to manage and group related digital assets.
[0032] Regarding the rule execution restrictions, Constraint describes the conditions that limit the rule execution, such as time, quantity, etc. Constraints have logical constraints (LogicalConstraint) and other condition types, and logical constraints are a special type of constraint that represents logical conditions and is used for more complex rule judgments.
[0033] An Action is a specific operation defined by a rule, and its attributes include includedIn and implies. Among them, includedIn indicates that the action belongs to a certain rule, and implies indicates that a certain action implies other rules or actions.
[0034] In addition, for the data space in this application, it also includes: Operator, Party, PartyCollection, Permission, Prohibition, Duty, and ConflictTerm.
[0035] Step 102: Establish a mapping relationship between the global ontology and the local ontology to obtain a first access mapping.
[0036] Exemplarily, as a basic component for the distribution of the data space, the basic connector has a local ontology and establishes a mapping with the global ontology.
[0037] Specifically, establishing a mapping relationship between the global ontology and the local ontology to obtain a first access mapping includes: configuring the role access fields in the rule library to obtain access rule data; based on the access rule data, determining the access mapping strategy through mapping strategy analysis; obtaining the mapping execution requirements, and according to the mapping execution requirements and the access mapping strategy, constructing the first access mapping through the mapping relationship.
[0038] In a specific embodiment, the mapping objective between the global ontology and the local ontology is information access control, and the rule library in the data dictionary connector is constructed by allocating fields according to the identity of the access role. The role access fields are used to control the access permissions of the role and the access content restrictions, and thus determine the access rule data.
[0039] As a core component in the data space, the data dictionary connector defines the global ontology and the rule library of this data space. The rule library contains data on which fields various roles in the data space can access. At the same time, the rule library corresponds to the ontology in the global ontology and can perform reasoning based on semantics.
[0040] This application is based on the functional architecture in supply chain logistics, and the roles in the data space are explained through Table 1 below.
[0041]
[0042] Table 1
[0043] Step 103: Establish a field mapping between the data source and the local ontology to obtain a second access mapping.
[0044] Exemplarily, the second access mapping is the mapping relationship established between the data source and the local ontology. When the data owner wants to share data using the basic connector, a policy is established and directly inserted into the local ontology as an instance in the ontology, which solves the problem that the centralized access control policy is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner.
[0045] Specifically, establishing a field mapping between the data source and the local ontology to obtain the second access mapping includes: obtaining the data requirements of the data owner and establishing a global policy in the policy library for the data requirements to obtain local ontology instances; wherein, the global policy establishment is based on the SWAR rule library; based on the local ontology instances, determining the second access mapping through the construction of the virtual mapping between the data source and the local ontology.
[0046] In one embodiment, the data owner configures the data source information and establishes a virtual mapping with the local ontology. Establishing the mapping does not directly add the data source information to the local ontology, but establishes a mapping between the fields in its own data source and the local ontology. If querying the resource fields in the database, the corresponding records in the local ontology are the corresponding fields. After establishing the second access mapping, when the data requester searches for resource A, it can directly query the fields from the data source.
[0047] Step 104, constructing a policy relationship for the second access mapping to establish the policy relationship between the data source and the local ontology.
[0048] Exemplarily, the second access mapping is the mapping relationship established between the data source and the local ontology. When the data owner wants to share data using the basic connector, a policy is established and directly inserted into the local ontology as an instance in the ontology, which solves the problem that the centralized access control policy is difficult to respond to the permission change requirements in multi-organization collaboration in a timely manner.
[0049] Specifically, the method includes: obtaining the data owner's policy based on the ORDL policy library and setting the data owner's policy as a data selection instance; inserting the data selection instance into the local ontology to establish the policy relationship between the data source and the local ontology.
[0050] In one embodiment, after establishing a virtual mapping in the supply chain logistics data space, the data owner selects a policy, inserts the policy as an instance into the local ontology, and establishes the policy relationship between the data source and the local ontology with the previous policy. Based on the SWAR rule library, the defined rules are for the entire data space. The global policy is equivalent to the definition under an authoritative institution, and all data exchanges must satisfy the global policy. The ODRL policy library is the policy defined by the user himself.
[0051] The functional architecture of collaborative logistics processes uses the semantic web rule language SWRL to describe custom access control rules. SWRL is based on a combination of OWL and RuleML. Its primary goal is to allow users to define rules and derive new knowledge from existing knowledge through logical reasoning. This application uses the SWRL rule language to describe access control rules. The specific formalization of the SWRL rule language is as follows:
[0052] Rule=B1^B2^B3^B4^......Bi......^Bn→A, where 1≤i≤n.
[0053] The SWRL-based access policy set includes:
[0054] Rule1=Subject(?x)^Object(?y)^Shipper(?a)^hasRole(?x,?a)^Receive_address(?y)^Worksite(?b)^WorkingHour(?c)^hasTime(?x,?c)^hasLocation(?x,?b)
[0055] →permit(?x,?y)
[0056] Rule2=Subject(?x)^Object(?y)^Carrier(?a)^hasRole(?x,?a)^Receive_address(?y)^Worksite(?b)^WorkingHour(?c)^hasTime(?x,?c)^hasLocation(?x,?b)
[0057] →permit(?x,?y)
[0058] Rule 1 indicates that if subject x is a shipper and initiates an access request to delivery address y through the intranet during working hours, then subject x is allowed to access delivery address y.
[0059] Rule 2 indicates that if the role of subject x is a carrier and the access request to delivery address y is initiated through the intranet during working hours, then it is judged that subject x is allowed to access delivery address y.
[0060] Step 105: Obtain a data request, and based on the data request, determine the accessible fields corresponding to the requester's identity through data access control.
[0061] Exemplarily, the requested data negotiates a deal with the data owner and a data exchange application is reached. After receiving the data exchange application, according to access control, the acquisition permission of the data acquirer (i.e., the data owner) is judged, which improves the rationality of policy deployment.
[0062] Specifically, based on the data request and the first access mapping, through data access control, the accessible fields corresponding to the identity of the requester are determined, including: converting the data request into a SPARQL query statement and inputting the SPARQL query statement into the data dictionary connector; querying and reasoning the SPARQL query statement through the rule base of the digital dictionary connector to obtain the accessible fields; wherein, the query reasoning is to query the instances associated with resources and policies under the preset data negotiation.
[0063] In one embodiment, when the data owner requests a certain piece of data, first convert the data request into a SPARQL query statement, input the query statement converted into SPARQL into the data dictionary connector, and perform access control through the reasoning of the rule base to find the fields that the data requester himself is allowed to search, that is, the accessible fields.
[0064] Step 106: Analyze the policy relationship of the accessible fields to obtain an access query statement.
[0065] This application analyzes the policy relationship of the accessible fields to obtain an access query statement, which meets the requirements of distributed management and improves data security.
[0066] Specifically, analyzing the policy relationship of the accessible fields to obtain an access query statement includes: based on the accessible fields, performing a local ontology query through the basic connector to obtain the associated instances in the local ontology; according to the associated instances, rewriting the SPARQL query statement to obtain the access query statement.
[0067] In one embodiment, the accessible fields are sent from the data dictionary connector to the basic connector, and the basic connector finds the instances associated with the resources and policies negotiated by them in the local ontology and rewrites the SPARQL query statement.
[0068] Step 107: According to the access query statement, through virtual knowledge graph mapping, obtain fine-grained access data.
[0069] Specifically, according to the access query statement, through virtual knowledge graph mapping, obtaining fine-grained access data includes: calling the query interface of the preset virtual knowledge graph and sending the access query statement to the virtual knowledge graph; based on the virtual knowledge graph, through data access request mapping analysis, obtaining access demand data; summarizing the access demand data to obtain fine-grained access data.
[0070] In one embodiment, the query interface of the virtual knowledge graph is called to send the query instruction to the virtual knowledge graph based on the query interface, and the data corresponding to the data access request is obtained according to the mapping of the virtual knowledge graph, and the fine-grained data is aggregated and generated. If the policy is restricted or changed, the data obtained by the data requester also changes, protecting data sovereignty.
[0071] After obtaining the fine-grained access data through the mapping of the virtual knowledge graph according to the access query statement, the method further includes: associating the global ontology with the local ontology based on the first access mapping and the second access mapping to obtain a global knowledge graph; constructing a unified query interface according to the global knowledge graph.
[0072] In one embodiment, based on the mapping rule, the global ontology is associated with the local ontology to form a global knowledge graph. In this process, through semantic data integration technology, the data in the distributed data sources is uniformly expressed and associated at the global level, providing support for distributed data access. The local ontology contains its own resource policies, and the constructed data model can support global queries, data relationship analysis, and semantic consistency management of upstream and downstream data.
[0073] Finally, on the basis of realizing data integration, a unified query interface is constructed, enabling users to query and analyze the global data through a unified query language and rules (such as SPARQL). Through fine-grained data query and access optimization, it is ensured that the results queried by users are accurate and meet security requirements. This process effectively improves the security and standardization of data exchange.
[0074] The above is the method embodiment proposed in this application. Based on the same inventive concept, the embodiment of this application also provides an ontology-based dynamic access control device for a data space, and its structure is as Figure 2 shown.
[0075] Figure 2 FIG. is a schematic internal structure diagram of an ontology-based dynamic access control device for a data space provided by an embodiment of this application. As Figure 2 shown, the device includes:
[0076] At least one processor 201;
[0077] And a memory 202 communicatively connected to the at least one processor;
[0078] Wherein, the memory 202 stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor 201 so that the at least one processor 201 can:
[0079] Construct a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; establish a data field mapping between the data source and the local ontology to obtain a second access mapping; construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; obtain a data request, and based on the data request and the first access mapping, through data access control, determine the accessible fields corresponding to the identity of the requester; perform a policy relationship analysis on the accessible fields to obtain an access query statement; according to the access query statement, through virtual knowledge graph mapping, obtain fine-grained access data.
[0080] Some embodiments of the present application provide a Figure 1 non-volatile computer storage medium for dynamic access control of an ontology-based data space, storing computer-executable instructions, and the computer-executable instructions are set as:
[0081] Construct a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; establish a data field mapping between the data source and the local ontology to obtain a second access mapping; construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; obtain a data request, and based on the data request and the first access mapping, through data access control, determine the accessible fields corresponding to the identity of the requester; perform a policy relationship analysis on the accessible fields to obtain an access query statement; according to the access query statement, through virtual knowledge graph mapping, obtain fine-grained access data.
[0082] Each embodiment in the present application is described in a progressive manner. For the same and similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the Internet of Things devices and media, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.
[0083] The systems and media provided by the embodiments of the present application correspond one-to-one with the methods. Therefore, the systems and media also have beneficial technical effects similar to the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be elaborated here.
[0084] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0085] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0086] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0087] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0088] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0089] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0090] A computer-readable medium includes permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory media that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0091] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0092] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A dynamic access control method for an ontology-based data space, characterized in that, The method includes: Constructing a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; Establishing a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; Establishing a data field mapping between the data source and the local ontology to obtain a second access mapping; Constructing a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; Obtaining a data request, and based on the data request and the first access mapping, determining accessible fields corresponding to the identity of the requester through data access control; Performing policy relationship analysis on the accessible fields to obtain an access query statement; According to the access query statement, obtaining fine-grained access data through virtual knowledge graph mapping.
2. The data space dynamic access control method based on ontology according to claim 1, wherein Wherein, The global ontology further includes: a rule library; Establishing a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping, specifically including: Configuring role access fields for the rule library to obtain access rule data; Based on the access rule data, determining an access mapping policy through mapping policy analysis; Obtaining mapping execution requirements, and according to the mapping execution requirements and the access mapping policy, obtaining the first access mapping through semantic mapping relationship construction.
3. A method for dynamically accessing and controlling an ontology-based data space according to claim 1, characterized in that Wherein, The basic connector further includes: a policy library; Establishing a data field mapping between the data source and the local ontology to obtain a second access mapping, specifically including: Obtaining the data requirements of the data owner, and establishing global policies of the policy library for the data requirements to obtain local ontology instances; wherein, the global policy establishment is based on the SWAR rule library; Based on the local ontology instances, determining the second access mapping through virtual mapping construction between the data source and the local ontology.
4. A method for dynamically accessing and controlling an ontology-based data space according to claim 1, characterized in that, Constructing a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology, specifically including: Obtaining a data owner policy based on the ORDL policy library and setting the data owner policy as a data selection instance; Inserting the data selection instance into the local ontology, and based on the second access mapping, establishing a policy relationship between the data source and the local ontology.
5. A method for dynamically accessing and controlling a data space based on an ontology according to claim 1, characterized in that, Based on the data request and the first access mapping, determining accessible fields corresponding to the identity of the requester through data access control, specifically including: Converting the data request into a SPARQL query statement and inputting the SPARQL query statement into the data dictionary connector; Through the rule library of the digital dictionary connector, performing query reasoning on the SPARQL query statement to obtain the accessible fields; wherein, the query reasoning is to query instances associated with resources and policies under a preset data negotiation.
6. The dynamic access control method for data space based on ontology according to claim 5, characterized in that Performing policy relationship analysis on the accessible fields to obtain an access query statement, specifically including: Based on the accessible fields, performing local ontology query through the basic connector to obtain associated instances in the local ontology; Rewrite the SPARQL query statement according to the associated instance to obtain the access query statement.
7. A method for dynamically accessing and controlling a data space based on ontology according to claim 1, characterized in that According to the access query statement, obtain fine-grained access data through virtual knowledge graph mapping, specifically including: Invoke the query interface of the preset virtual knowledge graph and send the access query statement to the virtual knowledge graph; Based on the virtual knowledge graph, obtain access requirement data through data access request mapping analysis; Summarize the access requirement data to obtain the fine-grained access data.
8. A method for dynamically accessing and controlling a data space based on an ontology according to claim 1, characterized in that, After obtaining the fine-grained access data through virtual knowledge graph mapping according to the access query statement, the method further includes: Associate the global ontology and the local ontology based on the first access mapping and the second access mapping to obtain a global knowledge graph; Construct a unified query interface according to the global knowledge graph to implement the access interface for the fine-grained access data.
9. A data space dynamic access control device based on ontology, characterized in that The device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor can: Construct a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; Establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; Establish a data field mapping between the data source and the local ontology to obtain a second access mapping; Construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; Obtain a data request, and based on the data request and the first access mapping, determine the accessible fields corresponding to the identity of the requester through data access control; Conduct a policy relationship analysis on the accessible fields to obtain an access query statement; According to the access query statement, obtain fine-grained access data through virtual knowledge graph mapping.
10. A non-volatile computer storage medium for dynamic access control of an ontology-based data space, storing computer-executable instructions, characterized in that, The computer-executable instructions are set to: Construct a data dictionary connector and a basic connector; wherein, the data dictionary connector includes: a global ontology; the basic connector includes: a data source, a local ontology; Establish a semantic mapping relationship between the global ontology and the local ontology to obtain a first access mapping; Establish a data field mapping between the data source and the local ontology to obtain a second access mapping; Construct a policy relationship for the second access mapping to establish a policy relationship between the data source and the local ontology; Obtain a data request, and based on the data request and the first access mapping, determine the accessible fields corresponding to the identity of the requester through data access control; Conduct a policy relationship analysis on the accessible fields to obtain an access query statement; According to the access query statement, obtain fine-grained access data through virtual knowledge graph mapping.
Citation Information
Cited By
Controlled data sandbox management method based on access connector
CN122241688A
Method for managing controlled data sandbox based on access connector
CN122241688B