A grid-based global longitudinal area authority control method
By processing gridded zoning data and publishing templated services across the entire domain, the problem of large workload and high hardware consumption in the existing technology of vertical regional access control across the entire domain has been solved, achieving efficient and convenient technical results.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JIUJIANG MUNICIPAL NATURAL RESOURCES BUREAU
- Filing Date
- 2022-10-24
- Publication Date
- 2026-04-28
AI Technical Summary
Existing full-domain vertical area access control technology suffers from problems such as heavy pre-processing workload, high hardware consumption, and high server pressure.
The original administrative division spatial data is spatially segmented at the smallest division level using a global grid-based zoning data processing tool to form domain cell grid groups, which are then published through a template service, and an authorization mechanism is established to achieve access control.
It significantly reduced the workload of preliminary data processing, lowered hardware resource consumption, optimized server load, and improved application control.
Smart Images

Figure CN115758440B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of GIS technology, and in particular relates to a grid-based method for controlling vertical regional access permissions across the entire domain. Background Technology
[0002] Under the background of the "14th Five-Year Plan", in order to "accelerate digital development and build a digital China" and "adhere to the priority development of agriculture and rural areas and comprehensively promote rural revitalization", the land and space planning industry will shoulder important social responsibilities, adopt advanced high technology and scientific information technology, accelerate digital development, promote rural revitalization, integrate multi-disciplinary, multi-physical quantity, multi-scale, and multi-probability data simulation processes, and jointly build digital twins.
[0003] Vertical access control across the entire domain is primarily applied to control access permissions for various types of natural resource status data, planning data, management data, and socio-economic data at multiple administrative levels, including provinces, cities, counties, townships, villages, towns, streets, and groups. To achieve this, the GIS industry typically employs a preprocessing approach. Specifically, before application, each existing dataset needs to be regionalized, a step requiring significant manpower for cropping and subsequent updates. Then, each dataset is divided into multiple regions and published as independent services, necessitating the deployment of numerous services. Even with a minimum resource consumption of 100MB per service, this requires substantial hardware resources. Once the large-scale service deployment is complete, the access control application for regional roles can be satisfied. However, the multi-threaded, high-concurrency pressure during use not only continuously consumes service hardware resources but also significantly impacts the effectiveness of the access control application.
[0004] Based on the analysis of the existing technology processing procedures, its shortcomings are threefold:
[0005] Firstly, since each piece of data needs to be cropped according to the smallest division level, the workload of data cropping in the early stage and maintenance and updates in the later stage will be very heavy.
[0006] Secondly, in the existing technology, after processing each piece of data by region, it is published as a service (MapServer) one by one, which will require a lot of hardware resources to support the normal use of the service.
[0007] Third, in existing technologies, after each piece of data is cut and published, it will be deployed in a multi-instance, high-concurrency mode, which will put enormous pressure on the server and greatly affect the application control effect under overload conditions. Summary of the Invention
[0008] In view of the above problems, the purpose of this invention is to provide a grid-based global vertical area access control method, which aims to solve the technical problems of heavy workload, high hardware consumption, and high server pressure in the preprocessing of existing global vertical area access control methods.
[0009] The present invention adopts the following technical solution:
[0010] Step S1: Using the global gridded zoning data processing tool, the original administrative division spatial data is spatially segmented at the smallest zoning level, and each segmented spatial range is taken as the smallest domain unit. By standardizing the space and attributes of each domain unit, domain cell grid groups are formed. All domain cell grid groups are merged to obtain global gridded zoning data, i.e., domain grid result data.
[0011] Step S2: Publish the domain grid results data using the service publishing template and following the template specifications, in the form of a service address;
[0012] Step S3: Establish an authorization mechanism. When an authorization request is received, output the cached graph of the graph range that needs to be authorized based on the authorization parameters and service address passed in the authorization request.
[0013] The beneficial effects of this invention are:
[0014] First, this invention addresses the preprocessing workload by only cutting and updating one type of (administrative division) data, thereby reducing the enormous workload of preliminary data processing. This can improve the efficiency of preliminary data processing by at least a hundred times, and the efficiency will increase stepwise as the data type increases. Second, this invention uses a customized administrative division data format to replace the traditional administrative division data, and through specific processing, it achieves the publication of only one service, thereby reducing the consumption of server hardware resources and reducing the strong dependence on high-performance servers. Third, after the aforementioned simplification process, the application mode is simultaneously adjusted to the regular application of the service. Only the maximum number of service instances needs to be adjusted according to the actual concurrency, so that service resources and service instances are in a relatively balanced state, and the application control effect will also reach the optimal level. Attached Figure Description
[0015] Figure 1 This is a flowchart of a grid-based global vertical region access control method provided in an embodiment of the present invention;
[0016] Figure 2 This is a schematic diagram of the global gridded zoning data processing tool provided in this embodiment of the invention;
[0017] Figure 3 This is a schematic diagram of the principle provided in the embodiment of the present invention;
[0018] Figure 4This is a schematic diagram of the circumscribed rectangle provided in an embodiment of the present invention;
[0019] Figure 5 This is a schematic diagram of forming external data outer_join provided in an embodiment of the present invention;
[0020] Figure 6 This is a schematic diagram of the internal mesh provided in an embodiment of the present invention;
[0021] Figure 7 This is a schematic diagram of the external mesh provided in an embodiment of the present invention;
[0022] Figure 8 This is a service publishing effect diagram provided by an embodiment of the present invention;
[0023] Figure 9 This is a schematic diagram of the authorization process provided in an embodiment of the present invention. Detailed Implementation
[0024] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0025] To illustrate the technical solution described in this invention, specific embodiments are described below.
[0026] Figure 1 The flowchart of the grid-based global vertical area permission control method provided by the embodiment of the present invention is shown. For ease of explanation, only the parts related to the embodiment of the present invention are shown.
[0027] like Figure 1 As shown, the grid-based global vertical area access control method provided in this embodiment includes the following steps:
[0028] Step S1, Domain Grid Result Data Production Steps: Using the whole-domain gridded zoning data processing tool, the original administrative division spatial data is spatially divided at the smallest zoning level, and each divided spatial range is taken as the smallest domain unit. By standardizing the space and attributes of each domain unit, domain cell grid groups are formed. All domain cell grid groups are merged to obtain the whole-domain gridded zoning data, i.e., domain grid result data.
[0029] This embodiment addresses the Ministry of Natural Resources' vertical control over spatial data such as "mountains, rivers, forests, fields, lakes, grasslands, and deserts," aiming to achieve integrated spatial application authorization across provinces, cities, counties, townships, and villages. Based on the unique nature of administrative division codes at all levels nationwide, a series of operations are performed on the original administrative division spatial data. Within the entire region, vertical authorization of usage rights for regional data is granted (province, city, county, township, village, and group levels). GIS tools, specifically a nationwide gridded administrative division data processing tool, are cleverly used to complete data standardization and deeply integrate GIS data to achieve access control.
[0030] This embodiment uses the smallest administrative division level for spatial segmentation, with each segmented spatial range serving as the smallest domain unit. The smallest administrative division level is the county-level administrative region. Specific tools for processing the full-domain gridded regionalization data include bounding rectangle, erasing, spatial fusion, fishnet tools, merging, and feature fusion tools; their specific functions can be found in [reference needed]. Figure 2 As shown. The circumscribed rectangle is the rectangle whose lower boundary is defined by the maximum and minimum x-coordinates, maximum and minimum y-coordinates of each vertex of a given 2D graphic. Erasure removes the overlapping portion of the input graphic and the eraser graphic from the input graphic and automatically closes the remaining graphic after removal. Spatial fusion merges the geographical extent of multiple regions. The fishing net tool divides a region into a grid. Merging combines the attributes of one data point with the attributes of the target data based on spatial relationships, generating new data and the merged attributes. Feature fusion merges the features of different regions.
[0031] Combination Figure 3 As shown, the specific process of this step is as follows:
[0032] S11. Spatial segmentation of the original administrative division data at the county-level administrative division level. For each segmented domain unit, calculate the bounding rectangle of the domain unit. The bounding rectangle consists of two identical first bounding rectangles and second bounding rectangles, wherein the first bounding rectangle is...
[0033] For the segmented domain units, which are county-level administrative region data, the bounding rectangle tool can be used to obtain the bounding rectangle of the domain unit. Here, two bounding rectangles are obtained: the first bounding rectangle sizhi1 and the second bounding rectangle sizhi2. (Refer to...) Figure 4 As shown, the domain unit is region one, the circumscribed rectangles are region one and region two, and region three is the outer region of the circumscribed rectangle.
[0034] S12. The first circumscribed rectangle is meshed using a fishing net tool to obtain a circumscribed rectangular fishing net.
[0035] The fishing net tool can perform gridding of the outer rectangle, which will not be elaborated here, resulting in an outer rectangular fishing net.
[0036] S13. Simultaneously, the first outer rectangle is used to generate spatial data inside and outside the domain cell using erase, merge, and spatial blending tools.
[0037] The first outer rectangle sizhi1 and the domain cell are erased to obtain region 2. Region 1 and region 2 are merged. The spatial fusion tool produces the internal and external spatial data of the domain cell (including region 1 and region 2).
[0038] S14. Use the erase and merge tools to erase the internal space of the domain cell of the second outer rectangle to obtain the external data.
[0039] The second bounding rectangle sizhi2 and the global outer spatial data convex_hull are erased to obtain the outer data outer_* of all domain cells. Then, the feature attributes are merged into outer_* using a merging tool to form the global outer data outer_join, which stores the spatial range outside the bounding rectangle. The processing effect is as follows: Figure 5 As shown.
[0040] The global gridded zoning data processing tool also includes an attribute aggregation tool and a minimum boundary geometry tool. The method for generating the global outer spatial extent is as follows:
[0041] The county-level administrative region data xzqh is used to generate a full-domain spatial graph of the county-level administrative regions using the attribute aggregation tool dissolve. Then, the aggregated graph is used to generate the full-domain outer spatial range convex_hull, i.e., the outer data of the domain grid, using the minimum boundary geometry tool Minibounding.
[0042] S15. The external rectangular fishing net is fused with the internal and external spatial data to form a set of external rectangular fishing net graphics of domain units.
[0043] The bounding rectangular fishing net (fish) is merged with the internal and external spatial data of the domain cells to perform feature fusion, forming a set of bounding rectangular fishing net graphics (fish_iden) for the domain cells. The processing result is as follows. Figure 6 , 7 As shown, the mesh located within the domain cell is the internal mesh, and the mesh located outside the domain cell and within the circumscribed rectangle is the external mesh.
[0044] S16. Merge the circumscribed rectangular fishing net graphic and the corresponding external data to obtain a set of domain cell net groups. Then, spatially merge all domain cell net groups to form the domain grid result data.
[0045] Finally, the inner and outer fishing net patterns (fish_iden) are merged with the external data (outer_join) to obtain a set of domain cell grids. All domain cell grids are spatially fused to form the domain grid result data.
[0046] Step S2, Templated Service Publishing Step: Publish the domain grid results data using the service publishing template and following the template specifications, in the form of a service address;
[0047] Templated service publishing involves publishing grid data (grids) as a map service (mapserver) based on a service publishing template (MXD file) and following specifications, and then providing it as a service address for subsequent use.
[0048] Step S3, Authorization and Operation Steps: Establish an authorization mechanism. When an authorization request is received, output the cached graph of the graph range that needs to be authorized based on the authorization parameters and service address passed in the authorization request.
[0049] During the operation of the web application, a mask request is first created on the web front end. This requires passing authorization parameters (i.e., XZQDM = '-420115000000') and the service address to the map server on the GIS server. The map server customizes the mask service based on the set expression and generates the address of the cached map image for that area in real time. Then, the cached image is used to generate a mask and embed it into the top layer of the web application's data list, so that it can cover all the data in the data list, thus achieving service authorization capability and application authorization effect.
[0050] In this embodiment of the web application, the system will determine the user's organizational affiliation (i.e., the county-level administrative division to which they belong) based on the currently logged-in user's organization. Figure 9 The process involves sending a request to the map service (mapserver) and transmitting authorization parameters (such as xzqdm="-420115000000") to the GIS server (GISServer) in real time. The GIS server (GISServer) then parses the transmitted parameters, filters and expresses the grid data, generates an authorized cached graphic of the current administrative division, stores it on the GIS server (GISServer), and returns the address of this cached graphic to the web application. This process is repeated continuously to respond to authorization requests in real time.
[0051] This invention is implemented on a PC and relies on the support of a GIS server and a web frontend. The GIS server performs hierarchical parameter-determined thinning of vector data for all levels of administrative regions across the entire area, and then publishes an OGC-standard WFS service. The web frontend handles data application permission partitioning and block processing, enabling automatic filtering of application data when applications of the same category are activated. The PC client, based on the user's administrative level and member role, reads the authorized area range of the data application, and forms a vector grid layer by hierarchically classifying, classifying, and delineating the vector data. It also performs local hidden-spotting operations on the grid within and outside the visible area, thereby controlling the right to use data in designated areas. By fully and rationally planning the responsibilities of the three parties, combined with the corresponding permission management methods, it can provide secure and reliable full-authorization support for a unified network across the entire area, one-click full-authorization management, and one-stop sharing for all users.
[0052] In summary, grid-based full-domain vertical regional access control is mainly applied to the control of data access permissions for various natural resource status data, planning data, management data, and socio-economic data at multiple levels of administrative divisions, such as provinces, cities, counties, townships, villages, towns, streets, and groups. By using "grid indexes" to replace the "one server, one domain" service model, the overload on GIS servers caused by data authorization is greatly reduced, enabling the authorization of data applications at all levels of regions quickly, conveniently, efficiently, and smoothly.
[0053] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A grid-based global vertical region access control method, characterized in that, The method includes the following steps: Step S1: Using the global gridded zoning data processing tool, the original administrative division spatial data is spatially segmented at the smallest zoning level, and each segmented spatial range is taken as the smallest domain unit. By standardizing the space and attributes of each domain unit, domain cell grid groups are formed. All domain cell grid groups are merged to obtain global gridded zoning data, i.e., domain grid result data. Step S2: Publish the domain grid results data using the service publishing template and following the template specifications, in the form of a service address; Step S3: Establish an authorization mechanism. When an authorization request is received, output the cached graph of the graph range that needs to be authorized based on the authorization parameters and service address passed in the authorization request.
2. The grid-based global vertical region access control method as described in claim 1, characterized in that, The global gridded zoning data processing tools include bounding rectangle, erasure, spatial fusion, fishing net tool, merging, and feature fusion tools.
3. The grid-based global vertical region access control method as described in claim 2, characterized in that, The specific process of step S1 is as follows: The original administrative division spatial data is spatially segmented at the county-level administrative division level. For each segmented domain unit, the bounding rectangle of the domain unit is calculated. The bounding rectangle consists of two identical first bounding rectangles and second bounding rectangles. The first bounding rectangle is meshed using a fishing net tool to obtain a bounding rectangular fishing net. Simultaneously, the first outer rectangle is used to generate spatial data inside and outside the domain unit using erase, merge, and spatial blending tools; The second bounding rectangle is used to erase the internal space of the domain cell using the erase and merge tools across the entire outer space range to obtain the external data. By fusing the features of the circumscribed rectangular fishing net with the internal and external spatial data, a set of circumscribed rectangular fishing net graphics of domain units are formed. The circumscribed rectangular fishing net pattern and the corresponding external data are merged to obtain a set of domain cell mesh groups. Then, all domain cell mesh groups are spatially merged to form the domain grid result data.
4. The grid-based global vertical region access control method as described in claim 3, characterized in that, The global gridded zoning data processing tool also includes an attribute aggregation tool and a minimum boundary geometry tool. The method for generating the global outer spatial extent in step S1 is as follows: The county-level administrative region data is used to generate a full-domain spatial map of the county-level administrative regions using the attribute aggregation tool. Then, the aggregated map is used to generate the outer spatial extent of the entire domain using the minimum boundary geometry tool.
5. The grid-based global vertical region access control method as described in claim 4, characterized in that, The specific process of step S3 is as follows: During the operation of the web application, a mask request is first created on the web front end, and the authorization parameters and service address are passed to the map service on the GIS server. The map service customizes the mask service according to the set expression and generates the address of the map cache image corresponding to the authorized parameters and service address in real time. Then, the cached image is used to create a mask and embed it at the top of the web application's data list, allowing the cached image to cover all the data in the list.
Citation Information
Patent Citations
Method for calculating land homogeneity based on open source spatial database PostGIS
CN112487131A
Spatial data authority control method based on spatial range
CN114640661A