A method, device, equipment and medium for identifying access of private data
By adding specified data items and specific addresses to the identifier registration data template, the problem of cumbersome methods for obtaining private data is solved, enabling convenient and secure access control to private data and enhancing the business value of enterprises.
Patent Information
- Application Number
- CN202211606903.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-14
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2042-12-14
AI Technical Summary
In existing technologies, enterprises have diverse and cumbersome ways of obtaining private data in the industrial internet identifier resolution system, which is difficult to unify and poses a risk of private data leakage.
By adding specified data items to the identification registration data template and completing the registration using a specific address to obtain access permissions, combined with permission levels and time limits, access control for private data can be achieved.
It enables a unified way to obtain private data, enhances the convenience and security of access, and at the same time gives enterprises multi-level business value.
Smart Images

Figure CN116032558B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for accessing private data. Background Technology
[0002] With the promotion and development of the Industrial Internet Identifier Resolution System in my country, the domestic identifier resolution system now encompasses various identifier systems, such as Handle, VAA, OID, and MA. These identifier systems have gradually established their own identifier resolution system architectures, and the number of identifier registrations and resolutions for each system is growing rapidly. For enterprises, the Industrial Internet Identifier Resolution System is a key to solving the problem of "information silos." Enterprises can publicly disclose data through the identifier resolution system, but they also have private data associated with that identifier that is not convenient to disclose on the internet. Users have various needs to access this private data, but obtaining this private data involves diverse acquisition methods and cumbersome processes. Summary of the Invention
[0003] This specification provides one or more embodiments of a method, apparatus, device, and medium for accessing and identifying private data, in order to solve the technical problems raised in the background art.
[0004] One or more embodiments of this specification employ the following technical solutions:
[0005] This specification provides one or more embodiments of a method for accessing private data, including:
[0006] If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item;
[0007] When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions.
[0008] If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0009] Furthermore, the identifier registration data template is a metadata template used during identifier registration in the Industrial Internet Identifier Resolution System. The identifier registration data template includes one or more of the following: data item name, meaning, unit, data type, data field length, and whether it is required.
[0010] Furthermore, the specific address is the unified address provided by the designated enterprise to the private data.
[0011] Furthermore, the access permissions include the data user's access license and permission level;
[0012] The determination that the access permission conforms to the permission of the specific data specifically includes:
[0013] Based on the data user's permission level in the access permissions and the permission level required for the specific data, it is determined whether the data user has the permission to obtain the specific data;
[0014] If the data user's permission level matches the permission level required for the specific data, then the access permission is determined to match the permission of the specific data.
[0015] Furthermore, before determining that the access permission conforms to the permission of the specific data, the method further includes:
[0016] The private data is set into multiple dimensions, and corresponding permission levels are set according to the private data in each dimension.
[0017] Furthermore, the access permission has a pre-set data acquisition time limit;
[0018] Before sending the specific data to the data user, the method further includes:
[0019] Determine whether the data acquisition time limit has been exceeded;
[0020] If so, register again through the specific address to regain access permissions.
[0021] Furthermore, the specific address is a URL address.
[0022] This specification provides one or more embodiments of an access device for identifying private data, the device comprising:
[0023] The data item adding unit, if it is determined that there is private data in the identification data of a specified enterprise, and the private data requires access control, adds a specified data item in the identification registration data template through the specified enterprise, and adds a specific address for accessing the private data in the specified data item;
[0024] The registration unit allows a user to register via the specific address when accessing specific data within the private data, thereby obtaining access permissions.
[0025] If the data access unit determines that the access permission matches the permission of the specific data, it will send the specific data to the data user.
[0026] This specification provides one or more embodiments of an access device for identifying private data, comprising:
[0027] At least one processor; and,
[0028] A memory communicatively connected to the at least one processor; wherein,
[0029] The memory stores instructions that can be executed by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0030] If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item;
[0031] When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions.
[0032] If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0033] This specification provides one or more embodiments of a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0034] If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item;
[0035] When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions.
[0036] If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0037] The above-described at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects:
[0038] The embodiments in this specification aim to unify the acquisition methods for identifier data by simultaneously resolving and obtaining publicly available identifier data, and by acquiring private identifier data. This unified acquisition method for private identifier data ensures convenient access for users when they need it. Furthermore, enterprises can grant access permissions to private identifier data on their self-built data access platforms, imbuing it with multi-layered commercial value, thus satisfying user data needs while generating commercial value from the data. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0040] Figure 1 A flowchart illustrating a method for accessing private data provided in one or more embodiments of this specification;
[0041] Figure 2 A schematic diagram of an industrial internet identification private data access control method provided in one or more embodiments of this specification;
[0042] Figure 3 A schematic diagram of an access device for identifying private data provided in one or more embodiments of this specification;
[0043] Figure 4 This is a schematic diagram of the structure of an access device for identifying private data, provided for one or more embodiments of this specification. Detailed Implementation
[0044] This specification provides an embodiment of a method, apparatus, device, and medium for accessing and identifying private data.
[0045] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0046] Figure 1This diagram illustrates a process for accessing private data, provided in one or more embodiments of this specification. This process can be executed by a system for accessing private data, making the acquisition of private data faster and more convenient. Certain input parameters or intermediate results in the process can be manually adjusted to help improve accuracy.
[0047] The method flow steps of the embodiments in this specification are as follows:
[0048] S102, if it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item.
[0049] In the embodiments of this specification, the identifier registration data template can be a metadata template used during identifier registration in the Industrial Internet Identifier Resolution System. The identifier registration data template may include one or more of the following: data item name, meaning, unit, data type, data field length, and whether it is mandatory. The specific address can be a unified address used by the designated enterprise to provide the private data. Specifically, the specific address can be a URL address.
[0050] Furthermore, the specific address points to a pre-created data open platform. Data users can then register through this platform, and access permissions can also be granted to them.
[0051] S104, when a data user accesses specific data in the private data, they complete the registration through the specific address to obtain access permission.
[0052] In the embodiments described in this specification, a data user may access the specific address on a data open platform to complete registration and thereby obtain access permissions. It should be noted that accessing the specific address on a specific data open platform provides a secure environment, enhancing the security of the access permission acquisition process and better preventing the leakage of private data.
[0053] S106, if it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0054] In the embodiments of this specification, access permissions may include the access license and permission level of the data user; when determining that the access permission conforms to the permission of the specific data, it can be verified first that the access license conforms, and then, based on the permission level of the data user in the access permission and the permission level required by the specific data, it can be determined whether the data user has the permission to obtain the specific data; if the permission level of the data user conforms to the permission level required by the specific data, it is determined that the access permission conforms to the permission of the specific data.
[0055] Furthermore, in the embodiments of this specification, before determining that the access permission conforms to the permission of the specific data, the private data can be set as multiple dimensions, and corresponding permission levels can be set according to the private data of each dimension. Thus, enterprise users can assign multi-layered commercial value to the access permissions and permission levels of private data.
[0056] Furthermore, in the embodiments of this specification, the access permission may also have a pre-set data acquisition time limit. Before sending the specific data to the data user, it can be determined whether the data acquisition time limit has been exceeded; if so, registration can be performed again through the specific address to re-acquire access permission. This can prevent the same data user from obtaining private data without restriction after a single registration, even if the data user's access permission does not meet the requirements.
[0057] It should be noted that this specification discloses an access control method for private industrial internet identifier data. This method allows for selective disclosure of certain private industrial internet data to specific users based on access permissions. Currently, identifier data registered through the identifier resolution system in the industrial internet industry is public data, which users can access at any time through the resolution interface. However, some product data is not suitable for public disclosure. This specification embodiment allows adding a data item named "More Data" to the identifier registration data template. The value of this data item can be a URL address. This URL address points to a data open platform built by the identifier's owner. Customers can access this URL address to complete registration, obtain access permission, determine their permission level, and retrieve the corresponding private data within the identifier data based on the access permission, data template, and the identifier code of the data to be accessed. The identifier private data refers to the private data within the identifier data.
[0058] Furthermore, the embodiments in this specification aim to unify the acquisition methods for identifier data by simultaneously resolving and obtaining publicly available identifier data, and by obtaining private identifier data. Enterprises can also utilize this data access control method to create greater commercial value from data.
[0059] To achieve the above objectives, this specification provides an industrial internet method for access control of private identifier data. By adding a data item named "More Data" to the data template used for identifier registration, enterprises can fill in a URL address that allows access to the identifier's private data during registration. This address points to the enterprise's self-built data open platform. Users who need to obtain the identifier's private data access this address to complete registration, obtain an access license, select a data template, and retrieve the identifier's private data based on the access license, data template, and identifier code.
[0060] The identifier registration data template is a metadata template used during identifier registration in the Industrial Internet Identifier Resolution System. It includes data item name, meaning, unit, data type, data field length, and whether it is required. Add a data item named "More Data" to the identifier registration data template.
[0061] In the identifier registration data template, a data item named "More Data" is added. When an identifier has private data and there are access control requirements for the private data, this field is filled in during identifier registration. This field is filled in with a URL address, which is the unified address provided by the identifier's parent company for the identifier's private data.
[0062] This specification describes an embodiment that obtains the URL for the identifier's private data. This URL points to the data open platform built by the enterprise to which the identifier belongs. When a user accesses the enterprise's self-built data open platform for the first time using this URL, the platform's page prompts the user to complete registration. Registration information includes user type (individual or enterprise, etc.), user ID, and user mobile phone number. After registration, the user obtains an access license and selects the permission level for querying private data. This access license can be considered as a credential for obtaining the identifier's private data. This platform may be time-limited and needs to be renewed after expiration. For the same identifier, its private data is also multi-dimensional. Enterprises can create multiple permission levels based on information from various dimensions and combinations of multiple dimensions. Enterprises can assign multi-layered commercial value to the access licenses and permission levels for the identifier's private data.
[0063] Furthermore, the data open platform in this embodiment can provide two access methods: a webpage and an API. The webpage method allows users to query identifier data independently through the enterprise's self-built data open platform's identifier data query page after obtaining an access license and selecting a permission level. The API method allows users to obtain the identifier's private data using an access license, data template, and identifier code.
[0064] The embodiments in this specification aim to unify the acquisition methods for identifier data by simultaneously resolving and obtaining publicly available identifier data, and by acquiring private identifier data. This unified acquisition method for private identifier data ensures convenient access for users when they need it. Furthermore, enterprises can grant access permissions to private identifier data on their self-built data access platforms, imbuing it with multi-layered commercial value, thus satisfying user data needs while generating commercial value from the data.
[0065] Furthermore, Figure 2 This is a schematic diagram of the Industrial Internet identifier private data access control method provided in the embodiments of this specification. The business process is as follows:
[0066] 1) Enterprise users add a data item named "More Data" to the identifier registration data template. When registering an identifier, add a URL for obtaining more information to the identifier registration information where there is a need to expose the identifier's private data.
[0067] 2) Enterprise users have successfully registered at the enterprise node or secondary node of the identifier resolution system;
[0068] 3) Data users obtain identifier data through the recursive parsing interface of the identifier resolution system, using the identifier ID as a parameter;
[0069] 4) The data user successfully obtained the identification data;
[0070] 5) Data users access the enterprise data open platform using the access URL (i.e., the value of "More Data") that identifies private data within the identified data.
[0071] 6) The data user successfully retrieved the identified private data based on the selected data template.
[0072] Figure 3 This is a schematic diagram of the structure of an access device for identifying private data provided in one or more embodiments of this specification. The device includes: a data item adding unit 302, a registration unit 304, and a data access unit 306.
[0073] The data item adding unit 302, if it is determined that there is private data in the identification data of a specified enterprise, and the private data requires access control, adds a specified data item in the identification registration data template through the specified enterprise, and adds a specific address for accessing the private data in the specified data item;
[0074] Registration unit 304: When a data user accesses specific data in the private data, the user completes registration through the specific address to obtain access permission.
[0075] If the data access unit 306 determines that the access permission matches the permission of the specific data, it sends the specific data to the data user.
[0076] Figure 4 A schematic diagram of an access device for identifying private data, provided for one or more embodiments of this specification, includes:
[0077] At least one processor; and,
[0078] A memory communicatively connected to the at least one processor; wherein,
[0079] The memory stores instructions that can be executed by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0080] If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item;
[0081] When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions.
[0082] If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0083] This specification provides one or more embodiments of a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0084] If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address for accessing the private data in the designated data item;
[0085] When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions.
[0086] If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
[0087] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0088] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0089] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.
Claims
1. A method for accessing private data, characterized in that, The method includes: If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address to the designated data item to access the private data. The specific address is a unified address provided by the designated enterprise for the private data, pointing to a data open platform built by the enterprise to which the identification belongs. When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions. If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
2. The method according to claim 1, characterized in that, The identifier registration data template is a metadata template used during identifier registration in the Industrial Internet Identifier Resolution System. The identifier registration data template includes one or more of the following: data item name, meaning, unit, data type, data field length, and whether it is required.
3. The method according to claim 1, characterized in that, The access permissions include the data user's access license and permission level; The determination that the access permission conforms to the permission of the specific data specifically includes: Based on the data user's permission level in the access permissions and the permission level required for the specific data, it is determined whether the data user has the permission to obtain the specific data; If the data user's permission level matches the permission level required for the specific data, then the access permission is determined to match the permission of the specific data.
4. The method according to claim 3, characterized in that, Before determining that the access permission conforms to the permission of the specific data, the method further includes: The private data is set into multiple dimensions, and corresponding permission levels are set according to the private data in each dimension.
5. The method according to claim 1, characterized in that, The access permission has a pre-set data acquisition time limit; Before sending the specific data to the data user, the method further includes: Determine whether the data acquisition time limit has been exceeded; If so, register again through the specific address to regain access permissions.
6. The method according to claim 1, characterized in that, The specific address is a URL address.
7. An access device for identifying private data, characterized in that, The device includes: The data item adding unit, if it is determined that there is private data in the identification data of a specified enterprise, and the private data requires access control, adds a specified data item in the identification registration data template through the specified enterprise, and adds a specific address to the specified data item to access the private data. The specific address is a unified address provided by the specified enterprise for the private data, pointing to a data open platform built by the enterprise to which the identification belongs. The registration unit allows a user to register via the specific address when accessing specific data within the private data, thereby obtaining access permissions. If the data access unit determines that the access permission matches the permission of the specific data, it will send the specific data to the data user.
8. An access device for identifying private data, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address to the designated data item to access the private data. The specific address is a unified address provided by the designated enterprise for the private data, pointing to a data open platform built by the enterprise to which the identification belongs. When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions. If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
9. A non-volatile computer storage medium, characterized in that, The computer-executable instructions are stored thereon and are configured as follows: If it is determined that there is private data in the identification data of a designated enterprise, and the private data requires access control, the designated enterprise adds a designated data item to the identification registration data template, and adds a specific address to the designated data item to access the private data. The specific address is a unified address provided by the designated enterprise for the private data, pointing to a data open platform built by the enterprise to which the identification belongs. When a data user accesses specific data within the private data, they complete registration through the specific address to obtain access permissions. If it is determined that the access permission matches the permission of the specific data, the specific data is sent to the data user.
Citation Information
Patent Citations
Distributed file system and method for visiting data resource in distributed system
CN102833287A
Metadata processing method, metadata processing device and readable storage medium
CN112732703A