File management method and system based on global analysis architecture

Through a file management method based on the global parsing architecture, the security and privacy issues caused by the storage of institutional files to the shared storage path in the prior art are solved, local file storage and secure access control are realized, and data security and privacy are improved.

CN120030584APending Publication Date: 2025-05-23BEIJING CDI CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411914211.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing technology stores institutional files in a shared storage path, obtains external network addresses through port mapping, and directly allows external network users to access them, resulting in threats to the ownership of institutional files and data security, posing a network security risk, and reducing the privacy of data.

Method used

The file management method based on the global parsing architecture is adopted, and the user's organizational identity authentication information is used to set the unique network identity information and permission parameters on the entire network, configure the local file repository and administrator rights, perform identity verification and business requirements acquisition, and retrieve relevant permission files according to the secure access policy.

Benefits of technology

It realizes local storage of institutional files, avoids leakage and file ownership loss, improves file security and data privacy, ensures permission control of external personnel access, and reduces network security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030584A_ABST
    Figure CN120030584A_ABST
Patent Text Reader

Abstract

The invention discloses a file management method and system based on a global analysis architecture. The method comprises the following steps: setting whole-network unique network identity information and authority parameters of a user according to mechanism identity authentication information of the user; configuring a local file storage library and administrator allocation parameters and authority parameters of each mechanism through a file system, and storing local files of the mechanisms; performing identity verification on the user according to the whole-network unique network identity information and the authority parameter of the user, and obtaining a service demand of the user after the verification is passed; and determining a file access scene parameter of the user according to the service requirement, and calling the related permission file according to the file access scene parameter and the security access strategy. According to the method, local storage of the institution files can be realized, leakage and file loss due to file ownership are avoided, file security and data privacy are improved, security risk factors such as network viruses which are maliciously carried by external personnel are avoided, and security, practicability and stability are improved.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A file management method based on a global resolution architecture, characterized in that: The following steps are involved: Set the user's unique network identity information and permission parameters based on the user's institutional identity authentication information; Configure each institution's local file repository and administrators to assign parameters and permission parameters and perform institution local file storage through the file system; Perform identity authentication based on the user's unique network identity information and permission parameters, and obtain the user's business needs after the authentication is passed; Determine the user's file access scenario parameters based on business needs, and retrieve relevant permission files based on the file access scenario parameters and security access policies.

2. The file management method based on the global resolution architecture according to claim 1, characterized in that: The setting of the user's unique network identity information and permission parameters for the entire network according to the user's institutional identity authentication information includes: Obtain the user's organization staff structure information, determine the user's current position level based on the organization staff structure information, and obtain the organization certification template corresponding to the current position level; The institution authentication information uploaded by the user is evaluated for qualification through the institution authentication template. If the verification is qualified, the size of the user's institution is determined through the official website of the institution; Set the institutional account base according to the size of the user's institution and generate the user's internal institutional account based on the account base and the user's current position level; The user's unique network identity information and permission parameters are set based on the internal institutional account and the institutional node color of the user's institution.

3. The file management method based on the global resolution architecture according to claim 1, characterized in that: The method of configuring each institution's local file repository and administrator allocation parameters and permission parameters through the file system and performing institution local file storage includes: Obtain the department configuration of each organization, determine the work status of each department based on the department configuration, and determine the file aggregation volume of each department based on the work status; Determine the local shared folder configuration memory of each department according to the file aggregation volume of each department, and call system resources to configure the local file repository of each institution through the file system supported by the parsing architecture based on the configuration memory; Allocate super administrator and department administrator quotas based on each organization's staff structure and department personnel information; Set up the creation, modification and deletion of department shared folders and member addition and deletion permissions for super administrators, and set up data operation and storage permissions and member addition and deletion permissions for department administrators; Obtain the organization's uploaded files and determine the upload object, determine the file's belonging department based on the upload object, and store the organization's uploaded files in the target local shared folder corresponding to the file's belonging department; Among them, data operation permissions include: data reading, data modification, data addition, data deletion and data download.

4. The file management method based on the global resolution architecture according to claim 1, characterized in that: The identity authentication is performed based on the user's unique network identity information and permission parameters in the entire network, and the user's business needs are obtained after the authentication is passed, including: Retrieve the network architecture of the international root node, obtain the verification rules of the network architecture, and determine the parameters required for verification based on the verification rules; According to the parameters required for verification, the parameter indicators are obtained based on the user's unique network identity information and permission parameters in the entire network, and the network permission control routing protection verification is performed on the user based on the parameter indicators; Determine whether the user's identity is qualified according to the verification result. If so, obtain the user's online request and determine the user's expected operation business according to the online request; Acquire multiple business functions under the expected operation business, determine the user's business functions to be executed, and determine the user's business needs based on the business functions to be executed.

5. The file management method based on the global resolution architecture according to claim 1, characterized in that: Determining the user's file access scenario parameters according to business requirements, and retrieving relevant authority files according to the file access scenario parameters and security access policies, includes: Determine the user's business object according to business needs, the business object includes: single-point object, point-to-point object and distributed multi-point object; Determine the user's file access scenario parameters according to the business object, determine the user's file access object based on the file access scenario parameters, determine whether the user is an internal user of the file access object, and if not, obtain the external user access security policy under the file access scenario; Determine the file description parameters within the user's access permission range according to the external user access security policy; Retrieve the relevant permission file from the file storage repository of the file access object according to the file description parameters and the type of the file to be retrieved by the user.

6. A file management system based on a global resolution architecture, characterized in that: The system includes: The setting module is used to set the user's unique network identity information and permission parameters based on the user's institutional identity authentication information; A configuration module, used to configure each institution's local file repository and administrator allocation parameters and permission parameters through the file system and perform institution local file storage; The verification module is used to authenticate the user based on the user's unique network identity information and permission parameters, and obtain the user's business needs after the verification; The retrieval module is used to determine the user's file access scenario parameters according to business needs, and to retrieve relevant permission files according to the file access scenario parameters and security access policies.

7. The file management system based on the global resolution architecture according to claim 6, characterized in that: The setting module includes: The acquisition submodule is used to obtain the user's institutional staff structure information, determine the user's current position level based on the institutional staff structure information, and obtain the institutional certification template corresponding to the current position level; The evaluation submodule is used to conduct a qualification evaluation on the institutional identity authentication information uploaded by the user through the institutional authentication template. If the verification is qualified, the scale of the user's institution is determined through the official website information of the institution; A generation submodule is used to set the institutional account base according to the size of the user's institution and generate the user's internal institutional account according to the account base and the user's current position level; The first setting submodule is used to set the user's network-wide unique network identity information and permission parameters based on the internal organization account and the organization node color of the user's organization.

8. The file management system based on the global resolution architecture according to claim 6, characterized in that: The configuration module includes: The first determination submodule is used to obtain the department configuration of each institution, determine the work status of each department according to the department configuration, and determine the file aggregation amount of each department based on the work status; A configuration submodule is used to determine the local shared folder configuration memory of each department according to the file aggregation volume of each department, and to call system resources to configure the local file repository of each institution through the file system supported by the parsing architecture based on the configuration memory; The allocation submodule is used to allocate super administrator quotas and department administrator quotas based on the employee structure and department personnel information of each organization; The second setting submodule is used to set the creation, modification and deletion of department shared folders and member addition and deletion permissions for super administrators, and to set data operation and storage permissions and member addition and deletion permissions for department administrators; The storage submodule is used to obtain the files uploaded by the organization and determine the upload object, determine the department to which the files belong according to the upload object, and store the files uploaded by the organization in the target local shared folder corresponding to the department to which the files belong; Among them, data operation permissions include: data reading, data modification, data addition, data deletion and data download.

9. The file management system based on the global resolution architecture according to claim 6, characterized in that: The verification module comprises: The second determination submodule is used to retrieve the network architecture of the international root node, obtain the verification rules of the network architecture, and determine the parameters required for verification according to the verification rules; The verification submodule is used to obtain parameter indicators according to the user's unique network identity information and permission parameters in the entire network according to the parameters required for verification, and to perform network permission control routing protection verification on the user according to the parameter indicators; The third determination submodule is used to determine whether the user identity is qualified according to the verification result, and if so, obtain the user's online request and determine the user's expected operation business according to the online request; The fourth determination submodule is used to obtain multiple business functions under the expected operation business, determine the business functions to be executed by the user, and determine the business needs of the user based on the business functions to be executed.

10. The file management system based on the global resolution architecture according to claim 6, characterized in that: The calling module includes: A fifth determination submodule is used to determine the user's business object according to the business requirements, wherein the business object includes: a single-point object, a point-to-point object, and a distributed multi-point object; A sixth determination submodule, used to determine a file access scenario parameter of a user according to a business object, determine a file access object of the user based on the file access scenario parameter, determine whether the user is an internal user of the file access object, and if not, obtain an external user access security policy in the file access scenario; A seventh determination submodule is used to determine the file description parameters within the user access permission range according to the external user access security policy; The retrieval submodule is used to retrieve the relevant permission file from the file storage repository of the file access object according to the file description parameters and the type of the file to be retrieved by the user.