Data resource scheduling management system and method based on directory chain
Through the data resource scheduling and management system based on the directory chain, the problem of permission conflict detection and processing in a multi-user and multi-platform environment is solved, the stability and data security of the permission system are realized, and the efficiency and security of data resource management and data sharing are improved.
Patent Information
- Application Number
- CN202510440186.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology is difficult to effectively detect and handle permission conflicts in a complex environment of multiple users and multiple platforms, resulting in data leakage and chaos in transaction processes, and reducing system security and stability.
The data resource scheduling management system based on the directory chain is adopted, and the data resources are cataloged and constructed through the directory chain management module. The permission management module monitors permission conflicts in real time and automatically adjusts permission priority. The approval module and the data sharing scheduling module cooperate to conduct approval and data sharing scheduling applications for data call.
Real-time monitoring and automated processing of permission conflicts is realized, the stability of the permission system and data security are ensured, and the efficiency and security of data resource management and data sharing are improved.
Smart Images

Figure CN119941195A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data resource management and scheduling, and in particular to a data resource scheduling management system and method based on a directory chain. Background Art
[0002] With the booming development of information technology, data has become the core element to promote the progress of various industries. It is crucial to build an efficient data resource management and scheduling system; In a complex environment with multiple users and multiple platforms, the permission system is extremely complex. Different users are given various permission combinations based on their respective responsibilities and business needs. Different platforms also set different permission rules based on their own functions and security policies. In this case, adding new permissions, modifying or deleting existing permissions can easily trigger permission conflicts.
[0003] The traditional permission conflict detection mechanism has obvious drawbacks; most existing systems rely on a static permission matrix, which can only pre-set fixed permission conflict relationships, making it difficult to keep up with the frequent adjustments to business rules and the emergence of new business scenarios; the traditional static permission matrix may not be able to detect conflicts between new permissions and existing permissions in a timely manner, leading to customer data leakage, chaotic transaction processes and other problems, greatly reducing the security and stability of the system.
[0004] In terms of handling permission conflicts, existing methods have many shortcomings; some systems only handle conflicts based on simple role priorities or fixed rules, lacking comprehensive consideration of multi-dimensional factors such as business processes, data sensitivity, and user behavior. This approach may cause the processing results to be out of touch with actual business needs, which not only affects work efficiency, but may also cause data security risks.
[0005] Based on the above problems, the present invention proposes a data resource scheduling management system and method based on directory chain to solve one or more of the above problems. Summary of the invention
[0006] The purpose of the present invention is to provide a data resource scheduling management system and method based on directory chain to solve the problems raised in the prior art.
[0007] To achieve the above object, the present invention provides the following technical solutions: A data resource scheduling and management system based on a directory chain comprises a directory chain management module, a rights management module, an approval module and a data sharing scheduling module; the directory chain management module is responsible for uniformly cataloging resources in a data lake and a data pool, establishing a resource directory chain, and maintaining the update and synchronization of the directory chain; the rights management module is used to receive information related to rights of various platforms and users in the system, perform basic rights setting and allocation, monitor rights conflicts in real time, reasonably determine rights priorities when conflicts occur based on pre-set factors, and automatically adjust conflicting rights; the approval module is responsible for reviewing user data call applications, referring to rights, historical records and resource availability, deciding whether to approve, and transferring to the rights management module for processing before approval when rights conflicts are involved; the data sharing scheduling module is used to receive user call applications, find data locations based on the directory chain, coordinate data sharing between platforms in combination with rights judgment results, and dispatch data according to the principle of proximity to deliver data to users.
[0008] The directory chain management module includes a resource cataloging unit, a directory chain building unit and an information updating unit; The resource cataloging unit performs unified cataloging tasks on resources in the data lake and data pool, generates a globally unique identifier for each resource, and uses a data structure algorithm to integrate the resource name, type, storage location, and creation time into structured data, and stores it in a resource cataloging database table. The table establishes a primary key index through a unique identifier to facilitate retrieval and storage of resource cataloging information; The directory chain building unit builds a directory chain structure based on the internal logical connection between resources and the demand for resources by the business process; specifically, the topological sorting algorithm in graph theory is used, combined with pre-defined resource logical relationship rules and business demand weights, to build a directory chain in the form of a directed acyclic graph according to the hierarchical structure and association relationship of different resource nodes; during the construction process, corresponding parent node and child node pointers are allocated to each resource node, and the traversal and positioning of resources in the directory chain are realized through the pointer pointing relationship; The information update unit is responsible for continuously monitoring the dynamic changes of resource status in the data lake and data pool, and synchronously updating the resource information in the directory chain to maintain the consistency between the directory chain information and the actual resource status; specifically, a database trigger mechanism and real-time message queue technology are adopted; insert, delete, and update triggers are set for resource tables in the databases corresponding to the data lake and data pool. When the resource status changes, the trigger is triggered and the change event information is sent to the real-time message queue. The information update unit subscribes to the message queue, obtains resource change events in real time, and performs corresponding update operations in the resource catalog database table and the directory chain structure.
[0009] The authority management module includes a historical data recording unit, an authority conflict detection unit, a priority determination unit and a conflict adjustment unit; The historical data recording unit is used to record the granting, change, use and conflict processing process and results of each permission during the operation of the system. The unit will store these records, which include the user, data resource, operation type, time of occurrence, and the status of each permission when the conflict occurs, priority determination results and adjustment measures involved in the permission change; The permission conflict detection unit is responsible for real-time monitoring of changes in the permission coordination matrix, including but not limited to permission conflicts caused by the addition of new permissions and the modification and deletion of existing permissions; ensuring that permission changes do not cause permission conflicts in the system; The priority determination unit, when detecting a permission conflict, determines the priority of the conflicting permissions according to the multi-dimensional factor determination rules, including the department to which the data belongs, the importance of the platform, the user role, and the operation type, to provide a basis for conflict adjustment; The conflict adjustment unit automatically adjusts the conflicting permissions according to the result of the priority determination unit to eliminate the permission conflict.
[0010] The permission conflict detection unit further includes the following contents: The authority conflict detection unit is responsible for real-time monitoring of the changes in the authority coordination matrix. The authority coordination matrix M is an n×n matrix. The matrix element M i,j Represents the relationship between permissions i and j. Permissions i and j are integer indexes ranging from 1 to n, where n is the total number of permissions in the system and each index value corresponds to a permission in the system. i,j =1 indicates that permissions i and j conflict; M i,j =0 means that there is no conflict between permission i and permission j, and the initial state of the matrix is generated by the permission configuration loaded when the system is initialized; When permissions change, the system uses an incremental conflict detection method to perform local detection M only on the affected permission set S. i,j In this process, the historical data recording unit provides data for the entire detection process; the rules for determining the affected permission set S are as follows: New PermissionsP new The relationship between itself and all existing permissions needs to be checked, so S={P new}∪{P j ∣P j ∈ existing permission set}; the system locates the detailed information of all existing permissions by querying the historical permission operation records, including the granting object of the permission, the associated data resources and the operation type; the permission information in these historical records constitutes the set {P j ∣P j ∈ the specific content of the existing permission set}; Modified permissions Pmodified and its relationship with all existing permissions need to be rechecked, so S={P modified}∪{P j ∣P j ∈ existing permission set}; historical permission operations record the historical trajectory of permission modification. Based on these records, the system obtains relevant information about the permission before modification and its interaction with other permissions. At the same time, combined with the status of all existing permissions in the current system, the system determines the set S={P modified}∪{P j ∣P j ∈ existing permission set}; Delete permission P deleted After that, we need to detect all deleted Related permission relations, so S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; the historical permission operation record records in detail the relationship between the deleted permission Pdeleted and other permissions. According to the element information related to Pdeleted in the permission coordination matrix recorded in the historical records, the affected permission set S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; For each permission i in the set S, recalculate its relationship with all other permissions j as follows: For each permission i∈S, traverse all permissions j, including j=i; then call the conflict detection formula function to calculate M i,j ; The conflict detection formula is as follows: , Among them, Conflict (P i ,P j ) is a Boolean function used to determine the permission P i and permission P j Whether there is a conflict; Finally, the system generates a conflict alarm for the detected conflict results and transmits it to the priority determination unit for priority determination.
[0011] The priority determination unit further includes the following contents: The priority determination unit receives the conflict result transmitted by the permission conflict detection unit, and assigns weights to each dimension according to the multi-dimensional determination rules preset by the system. The dimensions include the department D to which the data belongs, the importance of the platform I, the user role R, and the operation type T; the weight of each dimension W kIndicates the importance of this dimension in the priority calculation. The weight set is defined as: ; Then calculate the score of each conflicting permission P in each dimension. The calculation rules are as follows: For the department D to which the data belongs, during the system operation, the historical data recording unit will record the data resources and departments involved in each permission operation. By analyzing these records, the criticality of each department's data in the business is determined; specifically, the evaluation is conducted from the following two quantifiable aspects: Business relevance H: Count the frequency of the department data being used in various business processes. Within a set time period, there are n business processes in total, of which m involve the department data. The business relevance H = n / m. Data update frequency U: measured by the number of updates of the department's data in historical data records; within the same time period, the department's data was updated q times, and a benchmark update number q0 was set, and the data update frequency U=q / q0, if q>q0, then U=1; According to the above, the score of department D to which the data belongs is I D The calculation formula is: ; According to I D Determine S D The value of I D When greater than or equal to 0.5, S D 10 points, classified as a core department; D When it is less than 0.5, S D 5 points, classified as general sector; represents the weights of H and U; For platform importance I, the system records the data access frequency and the criticality of business functions of each platform, and uses these two aspects to evaluate the platform importance; Data access frequency B: Based on historical data records, count the total number of times platform data is accessed within a set time period (b), as well as the total number of times all platform data is accessed (B) total , data access frequency B = b / B total ; Business function criticality F: Calculate the contribution ratio of the business functions carried by the platform to the achievement of the overall business goals, and determine the ratio of the number of key business functions x supported by the platform to the total number of key business functions y, then F=y / x; Based on the above, the score of platform importance I is I I The calculation formula is: ; According to II Determine S I When the value is greater than or equal to 0.5, it is 10 points and is classified as a core platform; when it is less than 0.5, it is 5 points and is classified as a common platform; represents the weights of B and F; For user role R, score S R , the system settings are divided into administrator users and ordinary users. The default value of the administrator user score is 10 points, and the default value of the ordinary user is 5 points; The score ST for operation type T is divided into two types: write operation and read operation. The default value of the write operation score is 10 points, and the default value of the read operation score is 5 points. The score set of permission P in each dimension is: ; For each conflicting permission P, the priority determination unit determines the priority of each conflicting permission according to its score S. P and weight W, calculate its comprehensive priority score Q P , the calculation formula is as follows: ; Finally, for all conflicting permissions, the priority determination unit calculates the priority score Q according to its comprehensive priority score. P The permissions are sorted from high to low according to the priority scores, and the priority sorting results are output to the conflict adjustment unit.
[0012] The conflict adjustment unit further includes the following contents: The conflict adjustment unit obtains conflicting permission priority ranking data presented in a structured form from the priority determination unit, and divides the permission set into a high priority permission set and a low priority permission set according to the received priority ranking data. The division standard is based on a preset priority threshold, and the division standard is defined as a permission conflict handling rule; when the priority value is greater than or equal to the threshold, the corresponding permission is classified into the high priority permission set, and the permission less than the threshold is classified into the low priority permission set; For permissions in the high-priority permission set, the conflict adjustment unit maintains the existing records in the permission table unchanged through transaction operations of the permission management database; in database transaction processing, the relevant permission record rows are locked to prevent other processes from modifying them during processing, ensuring that the operating permissions of high-priority permissions are not affected in conflict situations; for permissions in the low-priority permission set, the conflict adjustment unit generates permission adjustment strategies and performs adjustment operations according to the permission type and real-time data of system operation. Specifically, when a permission conflict occurs, the system obtains the type information of the conflicting permission in real time; if the low-priority permission is a modification type and conflicts with the high-priority permission, the system adjusts it to a read-only permission by parsing the permission type field in the permission record; the permission adjustment strategy is stored in the system policy library in the form of a script language, and the script is written according to the permission type and data resource category factors; when executing the adjustment, the system reads the permission record, parses its permission type and corresponding data resource category, matches the corresponding script instructions, modifies and updates the records in the permission table, and completes the permission adjustment.
[0013] The approval module includes an application receiving unit, a permission review unit, a resource availability unit, a history query unit and an approval decision unit; The application receiving unit is responsible for receiving the data call application submitted by the user, extracting key information from the received application data, including user identification, characteristics of the data resource called by the application, and the application operation type, and then passing the processed application information to the authority review unit; The permission review unit obtains the user's permission information from the permission management module, and checks whether the user has the permission to access the requested data in combination with the application information transmitted by the application receiving unit; when a permission conflict is found, the permission is re-evaluated according to the conflict handling rules of the conflict adjustment unit, and then the permission review result is transmitted to the resource availability check unit; The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module, and the status is divided into accessible and inaccessible; when the resource is unavailable, the relevant information is recorded and the result is fed back to the approval decision unit; when the resource is available, the resource availability information is passed to the historical record query unit; The history query unit queries the user's previous data call records from the system's history database, retrieves the user's call frequency and the corresponding call data type, and transmits the result to the approval decision unit; The approval decision unit comprehensively considers the information from the authority review unit, the resource availability check unit and the historical record query unit to make an approval decision; when the user authority is compliant, the resources are available and there are no abnormalities in the historical call records, the application is approved and the approval information is sent to the data sharing scheduling module; but if the application has insufficient authority, unavailable resources and abnormal historical records, the application is rejected and the reason for rejection is fed back to the user.
[0014] The data sharing and scheduling module includes a data positioning unit, a secondary authority verification unit, a scheduling coordination unit and a data transmission unit; After the data location unit obtains the information from the approval module, it searches for the data location based on the resource directory chain established by the directory chain management module. Through the index structure of the directory chain, the resource unique identifier and feature description are used to locate the storage location of the data resource matching the user request in the data lake and data pool. After completing the location, the data location information and the user request information are sent to the secondary authority verification unit. The secondary permission verification unit receives data location information and user request information from the data location unit, and verifies the user's permission to access the requested data in combination with the permission judgment result provided by the permission management module; the verification process is as follows: the permission verification unit first parses the data location and user request information received from the data location unit, as well as the user permission information obtained from the permission management module, checks the permission range through range matching, performs static and dynamic permission type checks, and then resolves conflicts according to permission conflict handling rules to determine whether the user permission has passed the verification; if the verification is passed, the relevant information is passed to the scheduling coordination unit; if the verification is not passed, a prompt message indicating insufficient permission is returned to the user; After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; according to the principle of proximity, the nearest platform is selected as the data source, and a corresponding data scheduling plan is formulated, and the selected platform is communicated to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and the target user information are sent to the data transmission unit; The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, acquires data from the selected platform, and transmits the data to the target user according to the data transmission protocol specified by the system.
[0015] A data resource scheduling management method based on directory chain includes the following steps: S1. The user submits a data call application to the system, and the application receiving unit of the approval module is responsible for receiving the application; the unit extracts key information from the application, including but not limited to the user ID, the characteristics of the data resource to be called, and the type of application operation, and passes the processed application information to the permission review unit; S2. The permission review unit obtains user permission information from the permission management module and checks the user's permission to access the request data in combination with the application information; if a permission conflict is found, the permission is re-evaluated according to the established conflict handling rules with the help of the permission conflict detection unit, priority determination unit and conflict adjustment unit in the permission management module; then, the permission review result is passed to the resource availability check unit; S3. The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module; if the resource is not available, the relevant information is recorded and the result is fed back to the approval decision unit; if the resource is available, the resource availability information is passed to the historical record query unit; S4, the history query unit queries the user's previous data call records from the system's history database, obtains the user's call frequency and the corresponding call data type, and then passes the result to the approval decision unit; S5. The approval decision unit makes an approval decision based on the information from the authority review unit, resource availability check unit, and history query unit. If the user's authority is in compliance, resources are available, and there is no abnormality in the historical call record, the application is approved and the approval information is sent to the data sharing scheduling module. If there is insufficient authority, unavailable resources, or abnormal historical records, the application is rejected and the rejection reason is fed back to the user. S6. After receiving the approval information from the approval module, the data location unit of the data sharing scheduling module locates the storage location of the data resource matching the user request in the data lake and data pool based on the resource directory chain established by the directory chain management module, through the index structure of the directory chain, and using the resource unique identifier and feature description; after completing the location, the data location information and the user request information are sent to the secondary authority verification unit; S7, the secondary authority verification unit receives the data location information and the user request information from the data location unit, and performs authority verification in combination with the authority judgment result provided by the authority management module; if the verification is successful, the relevant information is passed to the scheduling coordination unit; if the verification is unsuccessful, a prompt message indicating insufficient authority is returned to the user; S8. After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; selects the nearest platform as the data source according to the proximity principle, formulates a corresponding data scheduling plan, and communicates with the selected platform to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and target user information are sent to the data transmission unit; S9. The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, obtains data from the selected platform, and transmits the data to the target user in accordance with the data transmission protocol specified by the system, thus completing the user data call application process.
[0016] Compared with the prior art, the present invention has the following beneficial effects: Permission conflict management: The permission conflict detection unit monitors the permission coordination matrix in real time and promptly discovers potential conflicts. Multi-dimensional judgment rules determine the priority of conflicting permissions, and the conflict adjustment unit divides the permission set accordingly. High-priority permissions remain unchanged, while low-priority permissions are adjusted according to permission type and data resource category to ensure the stability of the permission system and data security.
[0017] 2. Data resource management: The directory chain management module uniformly catalogs data lake and data pool resources, generates unique identifiers to store information, and uses topological sorting algorithms to build directory chains to facilitate resource positioning; the information update unit uses database triggers and real-time message queue technology to synchronize directory chains with actual resource status to improve resource management efficiency.
[0018] 3. Data sharing scheduling: The approval module comprehensively reviews applications based on multiple factors to ensure that data calls are reasonable. The data sharing scheduling module locates data based on the directory chain, coordinates sharing based on authority judgment, and schedules based on the principle of proximity. All links work closely together to improve the security and efficiency of data sharing and ensure that data is accurately delivered to users. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 A schematic diagram of the organizational structure of a data resource scheduling and management system based on a directory chain according to the present invention; Figure 2 The present invention is a method flow chart of a data resource scheduling management method based on directory chain. DETAILED DESCRIPTION
[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] Example: Figure 1-Figure 2 As shown, the present invention provides a technical solution. A data resource scheduling and management system based on a directory chain comprises a directory chain management module, a rights management module, an approval module and a data sharing scheduling module; the directory chain management module is responsible for uniformly cataloging resources in a data lake and a data pool, establishing a resource directory chain, and maintaining the update and synchronization of the directory chain; the rights management module is used to receive information related to rights of various platforms and users in the system, perform basic rights setting and allocation, monitor rights conflicts in real time, reasonably determine rights priorities when conflicts occur based on pre-set factors, and automatically adjust conflicting rights; the approval module is responsible for reviewing user data call applications, referring to rights, historical records and resource availability, deciding whether to approve, and transferring to the rights management module for processing before approval when rights conflicts are involved; the data sharing scheduling module is used to receive user call applications, find data locations based on the directory chain, coordinate data sharing between platforms in combination with rights judgment results, and dispatch data according to the principle of proximity to deliver data to users.
[0022] The directory chain management module includes a resource cataloging unit, a directory chain building unit and an information updating unit; The resource cataloging unit performs unified cataloging tasks on resources in the data lake and data pool, generates a globally unique identifier for each resource, and uses a data structure algorithm to integrate the resource name, type, storage location, and creation time into structured data, and stores it in a resource cataloging database table. The table establishes a primary key index through a unique identifier to facilitate retrieval and storage of resource cataloging information; The directory chain building unit builds a directory chain structure based on the internal logical connection between resources and the demand for resources by the business process; specifically, the topological sorting algorithm in graph theory is used, combined with pre-defined resource logical relationship rules and business demand weights, to build a directory chain in the form of a directed acyclic graph according to the hierarchical structure and association relationship of different resource nodes; during the construction process, corresponding parent node and child node pointers are allocated to each resource node, and the traversal and positioning of resources in the directory chain are realized through the pointer pointing relationship; The information update unit is responsible for continuously monitoring the dynamic changes of resource status in the data lake and data pool, and synchronously updating the resource information in the directory chain to maintain the consistency between the directory chain information and the actual resource status; specifically, a database trigger mechanism and real-time message queue technology are adopted; insert, delete, and update triggers are set for resource tables in the databases corresponding to the data lake and data pool. When the resource status changes, the trigger is triggered and the change event information is sent to the real-time message queue. The information update unit subscribes to the message queue, obtains resource change events in real time, and performs corresponding update operations in the resource catalog database table and the directory chain structure.
[0023] The authority management module includes a historical data recording unit, an authority conflict detection unit, a priority determination unit and a conflict adjustment unit; The historical data recording unit is used to record the granting, change, use and conflict processing process and results of each permission during the operation of the system. The unit will store these records, which include the user, data resource, operation type, time of occurrence, and the status of each permission when the conflict occurs, priority determination results and adjustment measures involved in the permission change; The permission conflict detection unit is responsible for real-time monitoring of changes in the permission coordination matrix, including but not limited to permission conflicts caused by the addition of new permissions and the modification and deletion of existing permissions; ensuring that permission changes do not cause permission conflicts in the system; The priority determination unit, when detecting a permission conflict, determines the priority of the conflicting permissions according to the multi-dimensional factor determination rules, including the department to which the data belongs, the importance of the platform, the user role, and the operation type, to provide a basis for conflict adjustment; The conflict adjustment unit automatically adjusts the conflicting permissions according to the result of the priority determination unit to eliminate the permission conflict.
[0024] The permission conflict detection unit further includes the following contents: The authority conflict detection unit is responsible for real-time monitoring of the changes in the authority coordination matrix. The authority coordination matrix M is an n×n matrix. The matrix element M i,j Represents the relationship between permissions i and j. Permissions i and j are integer indexes ranging from 1 to n, where n is the total number of permissions in the system and each index value corresponds to a permission in the system. i,j =1 indicates that permissions i and j conflict; M i,j =0 means that there is no conflict between permission i and permission j, and the initial state of the matrix is generated by the permission configuration loaded when the system is initialized; When permissions change, the system uses an incremental conflict detection method to perform local detection M only on the affected permission set S. i,j In this process, the historical data recording unit provides data for the entire detection process; the rules for determining the affected permission set S are as follows: New PermissionsP new The relationship between itself and all existing permissions needs to be checked, so S={P new}∪{P j ∣P j ∈ existing permission set}; the system locates the detailed information of all existing permissions by querying the historical permission operation records, including the granting object of the permission, the associated data resources and the operation type; the permission information in these historical records constitutes the set {P j ∣P j ∈ the specific content of the existing permission set}; Modified permissions Pmodified and its relationship with all existing permissions need to be rechecked, so S={P modified}∪{P j ∣P j ∈ existing permission set}; historical permission operations record the historical trajectory of permission modification. Based on these records, the system obtains relevant information about the permission before modification and its interaction with other permissions. At the same time, combined with the status of all existing permissions in the current system, the system determines the set S={P modified}∪{P j ∣P j ∈ existing permission set}; Delete permission P deleted After that, we need to detect all deleted Related permission relations, so S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; the historical permission operation record records in detail the relationship between the deleted permission Pdeleted and other permissions. According to the element information related to Pdeleted in the permission coordination matrix recorded in the historical records, the affected permission set S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; For each permission i in the set S, recalculate its relationship with all other permissions j as follows: For each permission i∈S, traverse all permissions j, including j=i; then call the conflict detection formula function to calculate M i,j ; The conflict detection formula is as follows: , Among them, Conflict (P i ,P j ) is a Boolean function used to determine the permission P i and permission P j Whether there is a conflict; Finally, the system generates a conflict alarm for the detected conflict results and transmits it to the priority determination unit for priority determination.
[0025] The priority determination unit further includes the following contents: The priority determination unit receives the conflict result transmitted by the permission conflict detection unit, and assigns weights to each dimension according to the multi-dimensional determination rules preset by the system. The dimensions include the department D to which the data belongs, the importance of the platform I, the user role R, and the operation type T; the weight of each dimension W kIndicates the importance of this dimension in the priority calculation. The weight set is defined as: ; Then calculate the score of each conflicting permission P in each dimension. The calculation rules are as follows: For the department D to which the data belongs, during the system operation, the historical data recording unit will record the data resources and departments involved in each permission operation. By analyzing these records, the criticality of each department's data in the business is determined; specifically, the evaluation is conducted from the following two quantifiable aspects: Business relevance H: Count the frequency of the department data being used in various business processes. Within a set time period, there are n business processes in total, of which m involve the department data. The business relevance H = n / m. Data update frequency U: measured by the number of updates of the department's data in historical data records; within the same time period, the department's data was updated q times, and a benchmark update number q0 was set, and the data update frequency U=q / q0, if q>q0, then U=1; According to the above, the score of department D to which the data belongs is I D The calculation formula is: ; According to I D Determine S D The value of I D When greater than or equal to 0.5, S D 10 points, classified as a core department; D When it is less than 0.5, S D 5 points, classified as general sector; represents the weights of H and U; For platform importance I, the system records the data access frequency and the criticality of business functions of each platform, and uses these two aspects to evaluate the platform importance; Data access frequency B: Based on historical data records, count the total number of times platform data is accessed within a set time period (b), as well as the total number of times all platform data is accessed (B) total , data access frequency B = b / B total ; Business function criticality F: Calculate the contribution ratio of the business functions carried by the platform to the achievement of the overall business goals, and determine the ratio of the number of key business functions x supported by the platform to the total number of key business functions y, then F=y / x; Based on the above, the score of platform importance I is I I The calculation formula is: ; According to II Determine S I When the value is greater than or equal to 0.5, it is 10 points and is classified as a core platform; when it is less than 0.5, it is 5 points and is classified as a common platform; represents the weights of B and F; For user role R, score S R , the system settings are divided into administrator users and ordinary users. The default value of the administrator user score is 10 points, and the default value of the ordinary user is 5 points; The score ST for operation type T is divided into two types: write operation and read operation. The default value of the write operation score is 10 points, and the default value of the read operation score is 5 points. The score set of permission P in each dimension is: ; For each conflicting permission P, the priority determination unit determines the priority of each conflicting permission according to its score S. P and weight W, calculate its comprehensive priority score Q P , the calculation formula is as follows: ; Finally, for all conflicting permissions, the priority determination unit calculates the priority score Q according to its comprehensive priority score. P The permissions are sorted from high to low according to the priority scores, and the priority sorting results are output to the conflict adjustment unit.
[0026] The conflict adjustment unit further includes the following contents: The conflict adjustment unit obtains conflicting permission priority ranking data presented in a structured form from the priority determination unit, and divides the permission set into a high priority permission set and a low priority permission set according to the received priority ranking data. The division standard is based on a preset priority threshold, and the division standard is defined as a permission conflict handling rule; when the priority value is greater than or equal to the threshold, the corresponding permission is classified into the high priority permission set, and the permission less than the threshold is classified into the low priority permission set; For permissions in the high-priority permission set, the conflict adjustment unit maintains the existing records in the permission table unchanged through transaction operations of the permission management database; in database transaction processing, the relevant permission record rows are locked to prevent other processes from modifying them during processing, ensuring that the operating permissions of high-priority permissions are not affected in conflict situations; for permissions in the low-priority permission set, the conflict adjustment unit generates permission adjustment strategies and performs adjustment operations according to the permission type and real-time data of system operation. Specifically, when a permission conflict occurs, the system obtains the type information of the conflicting permission in real time; if the low-priority permission is a modification type and conflicts with the high-priority permission, the system adjusts it to a read-only permission by parsing the permission type field in the permission record; the permission adjustment strategy is stored in the system policy library in the form of a script language, and the script is written according to the permission type and data resource category factors; when executing the adjustment, the system reads the permission record, parses its permission type and corresponding data resource category, matches the corresponding script instructions, modifies and updates the records in the permission table, and completes the permission adjustment.
[0027] The approval module includes an application receiving unit, a permission review unit, a resource availability unit, a history query unit and an approval decision unit; The application receiving unit is responsible for receiving the data call application submitted by the user, extracting key information from the received application data, including user identification, characteristics of the data resource called by the application, and the application operation type, and then passing the processed application information to the authority review unit; The permission review unit obtains the user's permission information from the permission management module, and checks whether the user has the permission to access the requested data in combination with the application information transmitted by the application receiving unit; when a permission conflict is found, the permission is re-evaluated according to the conflict handling rules of the conflict adjustment unit, and then the permission review result is transmitted to the resource availability check unit; The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module, and the status is divided into accessible and inaccessible; when the resource is unavailable, the relevant information is recorded and the result is fed back to the approval decision unit; when the resource is available, the resource availability information is passed to the historical record query unit; The history query unit queries the user's previous data call records from the system's history database, retrieves the user's call frequency and the corresponding call data type, and transmits the result to the approval decision unit; The approval decision unit comprehensively considers the information from the authority review unit, the resource availability check unit and the historical record query unit to make an approval decision; when the user authority is compliant, the resources are available and there are no abnormalities in the historical call records, the application is approved and the approval information is sent to the data sharing scheduling module; but if the application has insufficient authority, unavailable resources and abnormal historical records, the application is rejected and the reason for rejection is fed back to the user.
[0028] The data sharing and scheduling module includes a data positioning unit, a secondary authority verification unit, a scheduling coordination unit and a data transmission unit; After the data location unit obtains the information from the approval module, it searches for the data location based on the resource directory chain established by the directory chain management module. Through the index structure of the directory chain, the resource unique identifier and feature description are used to locate the storage location of the data resource matching the user request in the data lake and data pool. After completing the location, the data location information and the user request information are sent to the secondary authority verification unit. The secondary permission verification unit receives data location information and user request information from the data location unit, and verifies the user's permission to access the requested data in combination with the permission judgment result provided by the permission management module; the verification process is as follows: the permission verification unit first parses the data location and user request information received from the data location unit, as well as the user permission information obtained from the permission management module, checks the permission range through range matching, performs static and dynamic permission type checks, and then resolves conflicts according to permission conflict handling rules to determine whether the user permission has passed the verification; if the verification is passed, the relevant information is passed to the scheduling coordination unit; if the verification is not passed, a prompt message indicating insufficient permission is returned to the user; After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; according to the principle of proximity, the nearest platform is selected as the data source, and a corresponding data scheduling plan is formulated, and the selected platform is communicated to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and the target user information are sent to the data transmission unit; The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, acquires data from the selected platform, and transmits the data to the target user according to the data transmission protocol specified by the system.
[0029] A data resource scheduling management method based on directory chain includes the following steps: S1. The user submits a data call application to the system, and the application receiving unit of the approval module is responsible for receiving the application; the unit extracts key information from the application, including but not limited to the user ID, the characteristics of the data resource to be called, and the type of application operation, and passes the processed application information to the permission review unit; S2. The permission review unit obtains user permission information from the permission management module and checks the user's permission to access the request data in combination with the application information; if a permission conflict is found, the permission is re-evaluated according to the established conflict handling rules with the help of the permission conflict detection unit, priority determination unit and conflict adjustment unit in the permission management module; then, the permission review result is passed to the resource availability check unit; S3. The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module; if the resource is not available, the relevant information is recorded and the result is fed back to the approval decision unit; if the resource is available, the resource availability information is passed to the historical record query unit; S4, the history query unit queries the user's previous data call records from the system's history database, obtains the user's call frequency and the corresponding call data type, and then passes the result to the approval decision unit; S5. The approval decision unit makes an approval decision based on the information from the authority review unit, resource availability check unit, and history query unit. If the user's authority is in compliance, resources are available, and there is no abnormality in the historical call record, the application is approved and the approval information is sent to the data sharing scheduling module. If there is insufficient authority, unavailable resources, or abnormal historical records, the application is rejected and the rejection reason is fed back to the user. S6. After receiving the approval information from the approval module, the data location unit of the data sharing scheduling module locates the storage location of the data resource matching the user request in the data lake and data pool based on the resource directory chain established by the directory chain management module, through the index structure of the directory chain, and using the resource unique identifier and feature description; after completing the location, the data location information and the user request information are sent to the secondary authority verification unit; S7, the secondary authority verification unit receives the data location information and the user request information from the data location unit, and performs authority verification in combination with the authority judgment result provided by the authority management module; if the verification is successful, the relevant information is passed to the scheduling coordination unit; if the verification is unsuccessful, a prompt message indicating insufficient authority is returned to the user; S8. After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; selects the nearest platform as the data source according to the proximity principle, formulates a corresponding data scheduling plan, and communicates with the selected platform to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and target user information are sent to the data transmission unit; S9. The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, obtains data from the selected platform, and transmits the data to the target user in accordance with the data transmission protocol specified by the system, thus completing the user data call application process.
[0030] Example: Assume that there is a data resource scheduling management scenario of an enterprise, the enterprise has multiple business departments, and uses the data resource scheduling management system based on directory chain of the present invention to manage data resources; The data lake and data pool of an enterprise store various data resources. The resource cataloging unit generates a unique identifier for each resource. Assume that the identifier of resource A is "001" and the identifier of resource B is "002". The resource name, type, storage location and creation time are integrated into structured data. For example, resource A is customer transaction data, the type is a database table, stored in "Server 1 / Database 1 / Table 1", the creation time is "2024-01-01", and stored in the resource catalog database table. The directory chain building unit uses the topological sorting algorithm to build a directory chain based on the inherent logical connection between resources and the demand for resources in the business process. Assume that in the business process, resource A is associated with resource B, resource A is the parent node, and resource B is the child node. The traversal and positioning of resources in the directory chain are realized through the pointer pointing relationship. The information update unit uses the database trigger mechanism and real-time message queue technology to monitor and synchronize the dynamic changes of resource status in the data lake and data pool.
[0031] There are different user roles in the system, such as administrators and ordinary employees. Users from different departments have different permission requirements for data. The permission management module sets basic permissions for each user and platform. Assume that the administrator has read and write permissions for all data resources, and ordinary employees have specific data access permissions based on their departments. The permission conflict detection unit monitors the changes in the permission coordination matrix in real time. For example, if a new ordinary employee's permission P is added, new , the system uses an incremental conflict detection method to determine the affected permission set S={P new}∪{P j ∣P j ∈ existing permission set}, for each permission i in the set S, recalculate its relationship with all other permissions j. Assume that the permission conflict detection unit detects that the read permission of ordinary employee A conflicts with the modification permission of ordinary employee B. After receiving the conflict result, the priority determination unit determines the priority of the conflicting permissions according to the pre-set multi-dimensional determination rules. Assume that the weight of the department to which the data belongs is W D = 0.3, platform importance weight W I = 0.2, user role weight W R = 0.3, operation type weight WT = 0.2. The data department of ordinary employee A is a core department, which is 10 points, the platform importance is a non-core platform, which is 5 points, the user role is an ordinary user, which is 5 points, the operation type is a read operation, which is 5 points, and the comprehensive priority score is Q P1 = 0.3×10 + 0.2×5 + 0.3×5 + 0.2×5 = 6.5 points; the department to which the data of ordinary employee B belongs is a non-core department, which is 5 points; the platform importance is a core platform, which is 10 points; the user role is an ordinary user, which is 5 points; the operation type is a write operation, which is 10 points; the comprehensive priority score is Q P2 = 0.3×5 + 0.2×10 + 0.3×5 +0.2×10 = 7 points. Based on the priority sorting result, the conflict adjustment unit classifies B's permission into the high-priority permission set and A's permission into the low-priority permission set. A's low-priority modification permission is adjusted to read-only permission.
[0032] Ordinary employee C submits a data call application to the system. The application receiving unit receives the application and extracts key information, such as the user ID is "003", the data resource feature of the application call is resource A, and the application operation type is read. The permission review unit obtains the permission information of employee C from the permission management module, checks whether he has the permission to access the requested data, and finds that the permission is compliant, and passes the permission review result to the resource availability check unit. The resource availability check unit checks the status of resource A as accessible based on the resource directory chain information provided by the directory chain management module, and passes the resource availability information to the history query unit. The history query unit queries employee C's previous data call records from the system's history database, finds that the call frequency is normal, and passes the result to the approval decision unit. The approval decision unit integrates the information from each unit, approves the application, and sends the approval information to the data sharing scheduling module.
[0033] After receiving the approval information from the approval module, the data location unit of the data sharing scheduling module locates the storage location of resource A in the data lake based on the resource directory chain established by the directory chain management module, through the unique identifier "001" and feature description of resource A. The secondary permission verification unit receives the data location information and user request information from the data location unit, and verifies the permission of employee C in combination with the permission judgment result provided by the permission management module. After the verification, the relevant information is passed to the scheduling coordination unit. The scheduling coordination unit determines the distance between each data storage platform and employee C based on the distance measurement standard set by the system, selects the closest platform as the data source, formulates a data scheduling plan, and communicates with the selected platform to coordinate data sharing. After the coordination work is completed, the data acquisition instruction and target user information are sent to the data transmission unit. The data transmission unit obtains data from the selected platform, and transmits the data of resource A to employee C in accordance with the data transmission protocol specified by the system, completing the data call application process.
[0034] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.
Claims
1. A data resource scheduling and management system based on directory chain, characterized in that: It includes a directory chain management module, a rights management module, an approval module and a data sharing scheduling module; the directory chain management module is responsible for uniformly cataloging the resources in the data lake and data pool, establishing a resource directory chain, and maintaining the update and synchronization of the directory chain; The permission management module is used to receive information related to the permissions of each platform and user in the system, perform basic permission settings and allocations, monitor permission conflicts in real time, reasonably determine permission priorities when conflicts occur based on pre-set factors, and automatically adjust conflicting permissions; The approval module is responsible for reviewing user data call applications, referring to permissions, historical records and resource availability to decide whether to approve them. When there is a permission conflict, it will be transferred to the permission management module for processing before approval; the data sharing scheduling module is used to receive user call applications, find the data location based on the directory chain, combine the permission judgment results, coordinate data sharing between platforms, and schedule according to the proximity principle to deliver the data to the user.
2. The data resource scheduling and management system based on directory chain according to claim 1 is characterized by: The directory chain management module includes a resource cataloging unit, a directory chain building unit and an information updating unit; The resource cataloging unit performs unified cataloging tasks on resources in the data lake and data pool, generates a globally unique identifier for each resource, and uses a data structure algorithm to integrate the resource name, type, storage location, and creation time into structured data, and stores it in a resource cataloging database table. The table establishes a primary key index through a unique identifier to facilitate retrieval and storage of resource cataloging information; The directory chain building unit builds a directory chain structure according to the inherent logical connection between resources and the demand for resources by the business process; specifically, the topological sorting algorithm in graph theory is used, combined with pre-defined resource logical relationship rules and business demand weights, to build different resource nodes into a directory chain in the form of a directed acyclic graph according to the hierarchical structure and association relationship; During the construction process, each resource node is assigned a corresponding parent node and child node pointer, and the traversal and positioning of resources in the directory chain are achieved through the pointer pointing relationship; The information update unit is responsible for continuously monitoring the dynamic changes of resource status in the data lake and data pool, and synchronously updating the resource information in the directory chain to maintain the consistency between the directory chain information and the actual resource status; specifically, a database trigger mechanism and real-time message queue technology are adopted; insert, delete, and update triggers are set for resource tables in the databases corresponding to the data lake and data pool. When the resource status changes, the trigger is triggered and the change event information is sent to the real-time message queue. The information update unit subscribes to the message queue, obtains resource change events in real time, and performs corresponding update operations in the resource catalog database table and the directory chain structure.
3. The data resource scheduling and management system based on directory chain according to claim 1 is characterized by: The authority management module includes a historical data recording unit, an authority conflict detection unit, a priority determination unit and a conflict adjustment unit; The historical data recording unit is used to record the granting, change, use and conflict processing process and results of each permission during the operation of the system. The unit will store these records, which include the user, data resource, operation type, time of occurrence, and the status of each permission when the conflict occurs, priority determination results and adjustment measures involved in the permission change; The permission conflict detection unit is responsible for real-time monitoring of changes in the permission coordination matrix, including but not limited to permission conflicts caused by the addition of new permissions and the modification and deletion of existing permissions; Ensure that changes in permissions do not cause permissions conflicts in the system; The priority determination unit, when detecting a permission conflict, determines the priority of the conflicting permissions according to the multi-dimensional factor determination rules, including the department to which the data belongs, the importance of the platform, the user role, and the operation type, to provide a basis for conflict adjustment; The conflict adjustment unit automatically adjusts the conflicting permissions according to the result of the priority determination unit to eliminate the permission conflict.
4. The data resource scheduling and management system based on directory chain according to claim 3 is characterized by: The permission conflict detection unit further includes the following contents: The authority conflict detection unit is responsible for real-time monitoring of changes in the authority coordination matrix, where the authority coordination matrix M is an n×n matrix; Matrix element M i,j Represents the relationship between permissions i and j. Permissions i and j are integer indexes ranging from 1 to n, where n is the total number of permissions in the system and each index value corresponds to a permission in the system. i,j =1 means there is a conflict between permissions i and j; M i,j =0 means that there is no conflict between permission i and permission j, and the initial state of the matrix is generated by the permission configuration loaded when the system is initialized; When permissions change, the system uses an incremental conflict detection method to perform local detection M only on the affected permission set S. i,j In this process, the historical data recording unit provides data for the entire detection process; the rules for determining the affected permission set S are as follows: New PermissionsP new The relationship between itself and all existing permissions needs to be checked, so S={P new }∪{P j ∣P j ∈ existing permission set}; The system locates the detailed information of all existing permissions by querying the historical permission operation records, including the object to which the permission is granted, the associated data resources, and the operation type; the permission information in these historical records constitutes a collection {P j ∣P j ∈ the specific content of the existing permission set}; Modified permissions P modified and its relationship with all existing permissions need to be rechecked, so S={P modified }∪{P j ∣P j ∈ existing permission set}; historical permission operations record the historical trajectory of permission modification. Based on these records, the system obtains relevant information about the permission before modification and its interaction with other permissions. At the same time, combined with the status of all existing permissions in the current system, the system determines the set S={P modified }∪{P j ∣P j ∈ existing permission set}; Delete permission P deleted After that, we need to detect all deleted Related permission relations, so S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; the historical permission operation record records in detail the relationship between the deleted permission Pdeleted and other permissions. According to the element information related to Pdeleted in the permission coordination matrix recorded in the historical records, the affected permission set S={P j ∣M Pdeleted ,j=1 or M j,Pdeleted =1}; For each permission i in the set S, recalculate its relationship with all other permissions j as follows: For each permission i∈S, traverse all permissions j, including j=i; then call the conflict detection formula function to calculate M i,j ; The conflict detection formula is as follows: , Among them, Conflict (P i ,P j ) is a Boolean function used to determine the permission P i and permission P j Whether there is a conflict; Finally, the system generates a conflict alarm for the detected conflict results and transmits it to the priority determination unit for priority determination.
5. The data resource scheduling and management system based on directory chain according to claim 4 is characterized in that: The priority determination unit further includes the following contents: The priority determination unit receives the conflict result transmitted by the permission conflict detection unit, and assigns weights to each dimension according to the multi-dimensional determination rules preset by the system. The dimensions include the department D to which the data belongs, the importance of the platform I, the user role R, and the operation type T; the weight of each dimension W k Indicates the importance of this dimension in the priority calculation. The weight set is defined as: ; Then calculate the score of each conflicting permission P in each dimension. The calculation rules are as follows: For the department D to which the data belongs, during the system operation, the historical data recording unit will record the data resources and departments involved in each permission operation. By analyzing these records, the criticality of each department's data in the business can be determined; The evaluation is conducted from the following two quantifiable aspects: Business relevance H: Count the frequency of the department data being used in various business processes. Within a set time period, there are n business processes in total, of which m involve the department data. The business relevance H = n / m. Data update frequency U: measured by the number of updates of the department's data in historical data records; within the same time period, the department's data was updated q times, and a benchmark update number q0 was set, and the data update frequency U=q / q0, if q>q0, then U=1; According to the above, the score of department D to which the data belongs is I D The calculation formula is: ; According to I D Determine S D The value of I D When greater than or equal to 0.5, S D 10 points, classified as a core department; D When it is less than 0.5, S D 5 points, classified as general sector; represents the weights of H and U; For platform importance I, the system records the data access frequency and the criticality of business functions of each platform, and uses these two aspects to evaluate the platform importance; Data access frequency B: Based on historical data records, count the total number of times platform data is accessed within a set time period (b), as well as the total number of times all platform data is accessed (B) total , data access frequency B = b / B total ; Business function criticality F: Calculate the contribution ratio of the business functions carried by the platform to the achievement of the overall business goals, and determine the ratio of the number of key business functions x supported by the platform to the total number of key business functions y, then F=y / x; Based on the above, the score of platform importance I is I I The calculation formula is: ; According to I I Determine S I When the value is greater than or equal to 0.5, it is scored 10 points and is classified as a core platform; When it is less than 0.5, it is scored as 5 points and is classified as a normal platform; represents the weights of B and F; For user role R, score S R , the system settings are divided into administrator users and ordinary users. The default value of the administrator user score is 10 points, and the default value of the ordinary user is 5 points; The score ST for operation type T is divided into two types: write operation and read operation. The default value of the write operation score is 10 points, and the default value of the read operation score is 5 points. The score set of permission P in each dimension is: ; For each conflicting permission P, the priority determination unit determines the priority of each conflicting permission according to its score S. P and weight W, calculate its comprehensive priority score Q P , the calculation formula is as follows: ; Finally, for all conflicting permissions, the priority determination unit calculates the priority score Q according to its comprehensive priority score. P The permissions are sorted from high to low according to the priority scores, and the priority sorting results are output to the conflict adjustment unit.
6. The data resource scheduling and management system based on directory chain according to claim 5 is characterized in that: The conflict adjustment unit further includes the following contents: The conflict adjustment unit obtains conflicting permission priority ranking data presented in a structured form from the priority determination unit, and divides the permission set into a high priority permission set and a low priority permission set according to the received priority ranking data. The division standard is based on a preset priority threshold, and the division standard is defined as a permission conflict handling rule; when the priority value is greater than or equal to the threshold, the corresponding permission is classified into the high priority permission set, and the permission less than the threshold is classified into the low priority permission set; For permissions in the high-priority permission set, the conflict adjustment unit maintains the existing records in the permission table unchanged through transaction operations in the permission management database; In database transaction processing, lock the relevant permission record row to prevent other processes from modifying it during processing, and ensure that the operation permission of the high-priority permission is not affected in the conflict situation; for the permissions in the low-priority permission set, the conflict adjustment unit generates permission adjustment strategies and performs adjustment operations according to the permission type and real-time data of the system operation. Specifically, when a permission conflict occurs, the system obtains the type information of the conflicting permission in real time; if the low-priority permission is a modification type and conflicts with the high-priority permission, the system adjusts it to a read-only permission by parsing the permission type field in the permission record; the permission adjustment strategy is stored in the system policy library in the form of a script language, and the script is written according to the permission type and data resource category factors; When performing adjustments, the system reads the permission record, parses its permission type and corresponding data resource category, matches the corresponding script instructions, modifies and updates the records in the permission table, and completes the permission adjustment.
7. The data resource scheduling and management system based on directory chain according to claim 6 is characterized by: The approval module includes an application receiving unit, a permission review unit, a resource availability unit, a history query unit and an approval decision unit; The application receiving unit is responsible for receiving the data call application submitted by the user, extracting key information from the received application data, including user identification, characteristics of the data resource called by the application, and the application operation type, and then passing the processed application information to the authority review unit; The permission review unit obtains the user's permission information from the permission management module, and checks whether the user has the permission to access the requested data in combination with the application information transmitted by the application receiving unit; when a permission conflict is found, the permission is re-evaluated according to the conflict handling rules of the conflict adjustment unit, and then the permission review result is transmitted to the resource availability check unit; The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module, and the status is divided into accessible and inaccessible; When resources are unavailable, relevant information is recorded and the results are fed back to the approval decision unit; when resources are available, the resource availability information is passed to the historical record query unit; The history query unit queries the user's previous data call records from the system's history database, retrieves the user's call frequency and the corresponding call data type, and transmits the result to the approval decision unit; The approval decision unit comprehensively considers the information from the authority review unit, the resource availability check unit and the historical record query unit to make an approval decision; when the user authority is compliant, the resources are available and there are no abnormalities in the historical call records, the application is approved and the approval information is sent to the data sharing scheduling module; but if the application has insufficient authority, unavailable resources and abnormal historical records, the application is rejected and the reason for rejection is fed back to the user.
8. The data resource scheduling and management system based on directory chain according to claim 7 is characterized in that: The data sharing and scheduling module includes a data positioning unit, a secondary authority verification unit, a scheduling coordination unit and a data transmission unit; After the data location unit obtains the information from the approval module, it searches for the data location based on the resource directory chain established by the directory chain management module. Through the index structure of the directory chain, the resource unique identifier and feature description are used to locate the storage location of the data resource matching the user request in the data lake and data pool. After completing the location, the data location information and the user request information are sent to the secondary authority verification unit. The secondary permission verification unit receives data location information and user request information from the data location unit, and verifies the user's permission to access the requested data in combination with the permission judgment result provided by the permission management module; the verification process is as follows: the permission verification unit first parses the data location and user request information received from the data location unit, as well as the user permission information obtained from the permission management module, checks the permission range through range matching, performs static and dynamic permission type checks, and then resolves conflicts according to permission conflict handling rules to determine whether the user permission has passed the verification; if the verification is passed, the relevant information is passed to the scheduling coordination unit; if the verification is not passed, a prompt message indicating insufficient permission is returned to the user; After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; according to the principle of proximity, the nearest platform is selected as the data source, and a corresponding data scheduling plan is formulated, and the selected platform is communicated to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and the target user information are sent to the data transmission unit; The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, acquires data from the selected platform, and transmits the data to the target user according to the data transmission protocol specified by the system.
9. A data resource scheduling management method based on directory chain, applied to a data resource scheduling management system based on directory chain as claimed in any one of claims 1 to 8, characterized in that: The following steps are involved: S1. The user submits a data call application to the system, and the application receiving unit of the approval module is responsible for receiving the application; the unit extracts key information from the application, including but not limited to the user ID, the characteristics of the data resource to be called, and the type of application operation, and passes the processed application information to the permission review unit; S2. The authority review unit obtains user authority information from the authority management module and checks the user's authority to access the requested data in combination with the application information; If a permission conflict is found, the permission will be re-evaluated according to the established conflict handling rules with the help of the permission conflict detection unit, priority determination unit and conflict adjustment unit in the permission management module; then, the permission review result will be passed to the resource availability check unit; S3. The resource availability checking unit checks the data resource status of the application based on the resource directory chain information provided by the directory chain management module; if the resource is not available, the relevant information is recorded and the result is fed back to the approval decision unit; if the resource is available, the resource availability information is passed to the historical record query unit; S4, the history query unit queries the user's previous data call records from the system's history database, obtains the user's call frequency and the corresponding call data type, and then passes the result to the approval decision unit; S5. The approval decision unit makes an approval decision based on the information from the authority review unit, resource availability check unit, and history query unit. If the user's authority is in compliance, resources are available, and there is no abnormality in the historical call record, the application is approved and the approval information is sent to the data sharing scheduling module. If there is insufficient authority, unavailable resources, or abnormal historical records, the application is rejected and the rejection reason is fed back to the user. S6. After receiving the approval information from the approval module, the data location unit of the data sharing scheduling module locates the storage location of the data resource matching the user request in the data lake and data pool based on the resource directory chain established by the directory chain management module, through the index structure of the directory chain, and using the resource unique identifier and feature description; after completing the location, the data location information and the user request information are sent to the secondary authority verification unit; S7, the secondary authority verification unit receives the data location information and the user request information from the data location unit, and performs authority verification in combination with the authority judgment result provided by the authority management module; If the verification is successful, the relevant information will be passed to the dispatch coordination unit; If the verification fails, a prompt message indicating insufficient permissions will be returned to the user; S8. After receiving the accessible information from the authority verification unit, the scheduling and coordination unit determines the distance between each data storage platform and the user according to the distance measurement standard set by the system; selects the nearest platform as the data source according to the proximity principle, formulates a corresponding data scheduling plan, and communicates with the selected platform to coordinate data sharing; after the coordination work is completed, the data acquisition instruction and target user information are sent to the data transmission unit; S9. The data transmission unit receives the data acquisition instruction and target user information from the scheduling and coordination unit, obtains data from the selected platform, and transmits the data to the target user in accordance with the data transmission protocol specified by the system, thus completing the user data call application process.
Citation Information
Patent Citations
Data resource directory system
CN113886397A
Cited By
Natural resource data dynamic monitoring and tracing method and system
CN120296076A
Information query method based on large model and electronic device
CN122547849A
Information query method based on large model and electronic device
CN122547849B