Data asset ownership management method and device, terminal equipment and storage medium
By generating and updating knowledge graphs to manage ownership relationships of data assets, the problem that existing technology cannot adapt to data diversity and dynamics is solved, automated permission management and compliance inspections are realized, and the effectiveness of ownership management of data assets is improved.
Patent Information
- Application Number
- CN202510209804.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-06
AI Technical Summary
The existing data asset ownership management methods mainly rely on static rules, manual recording or decentralized permission management systems, and cannot adapt to the characteristics of data diversification and dynamics, resulting in poor results in data asset ownership management.
By obtaining the metadata of the data assets to be managed, a first knowledge graph is generated; determining the ownership relationship between the data assets and the owner, and a second knowledge graph is generated; recording data operations and updating the knowledge graph is realized to realize dynamic management of ownership of data assets.
By building a ownership relationship map associated with data assets, we can realize automated processing permission management, compliance inspection and risk assessment, adapt to the characteristics of data diversification and dynamics, and improve the effectiveness of ownership management of data assets.
Smart Images

Figure CN120106790A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a data asset ownership management method, device, terminal equipment and storage medium. Background Art
[0002] Data assets have become an important resource in modern enterprises. As the value of data assets increases, how to effectively protect data ownership during the data life cycle becomes increasingly important. However, due to the complexity, circulation, and cross-organizational sharing of data, data ownership, usage rights, and protection issues have become extremely complex. Existing data asset ownership management methods mainly rely on static rules, manual records, or decentralized permission management systems, which cannot adapt to the diverse and dynamic characteristics of data, resulting in poor data asset ownership management results. Summary of the invention
[0003] The present invention provides a data asset ownership management method, apparatus, terminal device and storage medium to solve the technical problem that the existing data asset ownership management method mainly relies on static rules, manual records or decentralized authority management systems, cannot adapt to the characteristics of data diversification and dynamism, and leads to poor data asset ownership management results.
[0004] The present invention provides a data asset ownership management method, comprising:
[0005] Acquire the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata;
[0006] Determine the ownership relationship between the data asset to be managed and the owner, and generate a second knowledge graph based on the ownership relationship and the first knowledge graph;
[0007] Record the data operations in the second knowledge graph, and update the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operations.
[0008] Furthermore, generating a first knowledge graph based on the metadata includes:
[0009] Extracting basic attributes of the metadata, and generating initial knowledge graph nodes according to the basic attributes;
[0010] Annotating data sensitivity according to data content of the metadata, and generating graph attributes according to the data sensitivity;
[0011] Based on the initial knowledge graph nodes and the graph attributes, a first knowledge graph is generated.
[0012] Furthermore, after determining the ownership relationship between the data assets to be managed and the owner, it also includes:
[0013] Different ownership relationships are represented by using specific semantic descriptions, wherein the specific semantic descriptions include ownership and creation.
[0014] Furthermore, after generating the second knowledge graph, the following steps are also included:
[0015] A hierarchical definition of data operation permissions for the data assets in the second knowledge graph is performed, wherein the hierarchical definition of permissions includes read permission, write permission, share permission, and delete permission;
[0016] When performing data operations on data assets in the second knowledge graph, the original permission hierarchical definition of the data assets is propagated to the new knowledge graph nodes formed by the data operations.
[0017] Furthermore, after recording the data operation in the second knowledge graph and updating the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operation, the method further includes:
[0018] Periodically scan the data asset usage records in the updated second knowledge graph, and determine the current data assets according to the data asset usage records;
[0019] Determine usage scenarios and regulatory requirements for current data assets based on data relationships in the updated second knowledge graph;
[0020] Based on the usage scenario and regulatory requirements, a compliance assessment is performed on the usage record of the current data asset to obtain a compliance assessment result.
[0021] The present invention also provides a data asset ownership management device, comprising:
[0022] A first knowledge graph generation module, used to obtain the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata;
[0023] A second knowledge graph generation module, used to determine the ownership relationship between the data asset to be managed and the owner, and generate a second knowledge graph based on the ownership relationship and the first knowledge graph;
[0024] The second knowledge graph updating module is used to record data operations in the second knowledge graph and update the second knowledge graph according to new knowledge graph nodes and new edges generated by the data operations.
[0025] Furthermore, the data asset ownership management device also includes a permission propagation module, which is used to define the data operation permissions of the data assets in the second knowledge graph in a hierarchical manner, and the permission hierarchy definition includes read permission, write permission, sharing permission and deletion permission; when performing data operations on the data assets in the second knowledge graph, the original permission hierarchy definition of the data assets is propagated to the new knowledge graph node formed by the data operation.
[0026] Furthermore, the data asset ownership management device also includes a compliance assessment module, which is used to periodically scan the data asset usage records in the updated second knowledge graph, and determine the current data assets based on the data asset usage records; determine the usage scenarios and regulatory requirements of the current data assets based on the data relationships in the updated second knowledge graph; and perform a compliance assessment on the usage records of the current data assets based on the usage scenarios and regulatory requirements to obtain a compliance assessment result.
[0027] The present invention also provides a terminal device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, the data asset ownership management method as described above is implemented.
[0028] The present invention also provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the data asset ownership management method as described above.
[0029] The present invention determines the ownership relationship between the data assets to be managed and the owners, generates a second knowledge graph based on the ownership relationship and the first knowledge graph, wherein the ownership relationship includes a permission relationship and a usage relationship. The second knowledge graph constructed based on the ownership relationship between the data assets and the owners associates the data assets in the second knowledge graph with the ownership relationship, which is beneficial to manage and track the ownership information of the data assets according to the second knowledge graph, thereby realizing automated processing of permission management, compliance checking and risk assessment, etc., to adapt to the diversified and dynamic characteristics of data, and further effectively improve the effect of data asset ownership management. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a flowchart of a data asset ownership management method provided by an embodiment of the present invention;
[0031] Figure 2 It is a structural diagram of a data asset ownership management device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0032] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0033] In the description of this application, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the feature. In the description of this application, unless otherwise specified, "plurality" means two or more.
[0034] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0035] See also Figure 1 The present invention provides a data asset ownership management method, comprising:
[0036] S1. Acquire the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata;
[0037] In the embodiment of the present invention, metadata includes data source, data type, data sensitivity and data usage frequency. Among them, data source includes database, API and data file, data type includes structured data, unstructured data and time series data, data sensitivity can be automatically classified according to content, including personal privacy data, financial data and corporate confidential data, etc., and data usage frequency can be based on historical usage records to analyze the usage frequency and importance of data.
[0038] In an embodiment of the present invention, data scanning and metadata management tools can be used to automatically parse the data set of the data assets to be managed, thereby extracting the capital attributes of the data assets and generating initial knowledge graph nodes to generate a first knowledge graph.
[0039] S2. Determine the ownership relationship between the data assets to be managed and the owner, and generate a second knowledge graph based on the ownership relationship and the first knowledge graph; wherein the ownership relationship includes the permission relationship and the usage relationship;
[0040] In an embodiment of the present invention, the ownership relationship between the data assets to be managed and the owners is: an association relationship is established between each data asset and its owner (such as a company, department, individual), wherein the ownership relationship between all these nodes and data asset nodes can be clearly expressed through specific semantic descriptions, such as "own", "create", etc.
[0041] For example, [Data Asset A] --owned by --> [Owner Company A].
[0042] The permission relationship and usage relationship between data assets and users can be: Based on the permission model, the data assets are linked to the usage rights of different users (such as employees, partners, and systems). The permission information includes fine-grained operations such as read, write, and share.
[0043] Example: [Data Asset B]--Read Permission-->[User B Department].
[0044] Permission attributes: Each relationship carries permission levels and usage rules, indicating which users can access, edit, or transfer data under what conditions.
[0045] In the embodiment of the present invention, the ownership relationship may also include a data flow path and authorization management, and the data flow path includes:
[0046] The knowledge graph records the path of data from generation to use, sharing, and transmission, and defines the role of each node in the data flow (such as sender, receiver, storage node, etc.).
[0047] Example: [Data Asset C] -- Transfer to --> [System D].
[0048] Authorization management includes:
[0049] Assign corresponding authorization information to each data flow path to ensure that only authorized paths can perform specific data transmission or sharing operations.
[0050] Example: [Data Asset C]--Shared-->[Partner E] (authorization validity period: 3 months).
[0051] S3. Record the data operations in the second knowledge graph, and update the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operations.
[0052] The embodiment of the present invention determines the ownership relationship between the data assets to be managed and the owners, and generates a second knowledge graph based on the ownership relationship and the first knowledge graph; wherein the ownership relationship includes a permission relationship and a usage relationship. The second knowledge graph constructed based on the ownership relationship between the data assets and the owners associates the data assets in the second knowledge graph with the ownership relationship, which is conducive to managing and tracking the ownership information of the data assets according to the second knowledge graph, thereby realizing automated processing of permission management, compliance checking and risk assessment, etc., to adapt to the diversified and dynamic characteristics of data, and thus can effectively improve the effect of data asset ownership management.
[0053] Furthermore, the embodiments of the present invention record data operations in the second knowledge graph and update the second knowledge graph according to the data operations. By recording data operations and updating the knowledge graph in real time, it can ensure that the information in the knowledge graph is always consistent with the actual status of the data assets, so that managers can understand the latest status of data assets at any time, such as the frequency of data use, access records, etc., which can effectively improve the efficiency of data asset ownership management.
[0054] In one embodiment, S1, generating a first knowledge graph based on metadata, includes:
[0055] S11, extracting basic attributes of metadata and generating initial knowledge graph nodes according to the basic attributes;
[0056] In the embodiment of the present invention, the basic attributes include data name, data structure, data size, data period, etc. The embodiment of the present invention can convert the basic attributes and data relationships of the metadata into initial nodes and initial edges in the knowledge graph to subsequently generate the first knowledge graph, i.e., the initial knowledge graph.
[0057] S12. Label the data sensitivity according to the data content of the metadata, and generate graph attributes according to the data sensitivity;
[0058] In the embodiment of the present invention, the sensitivity of data can also be automatically marked according to preset classification standards, such as privacy data and business secrets, for example, privacy data and business secrets have high sensitivity.
[0059] S13. Generate a first knowledge graph based on the initial knowledge graph nodes and graph attributes.
[0060] In the embodiment of the present invention, the graph attributes include data sensitivity attributes, and the graph attributes are added to the initial graph nodes, and the data sensitivity attributes are associated with the data nodes to generate the first knowledge graph. In the embodiment of the present invention, other related attributes may also be associated with the data nodes, such as data source, storage location, access rights, etc.
[0061] The embodiment of the present invention combines the initial knowledge graph nodes and graph attributes to generate a first knowledge graph. By distinguishing data assets of different sensitivities such as privacy data and commercial secrets, corresponding security protection measures and compliance management strategies can be formulated and implemented in a targeted manner, thereby effectively improving the efficiency of data asset ownership management.
[0062] In one embodiment, step S2, after determining the ownership relationship between the data asset to be managed and the owner, further includes:
[0063] Different ownership relationships are represented using specific semantic descriptions, where the specific semantic descriptions include ownership and creation.
[0064] In the embodiment of the present invention, the semantic description of "own" is used to indicate the ownership of data assets. For example, in the knowledge graph, an edge of an "own" relationship can be established to connect the data asset node and the owner node to clearly indicate the ownership of the data asset. This relationship can be further subdivided into different forms such as full ownership and partial ownership to adapt to different ownership situations.
[0065] In the embodiment of the present invention, the semantic description of "create" is used to represent the relationship between the creator of a data asset and the data asset. For example, in a knowledge graph, a creator node can be connected to a data asset node through a "create" relationship edge, indicating that the creator has contributed to the generation or development of the data asset. This relationship helps to track the source and history of data assets and provides a basis for tracing and dividing responsibilities for data assets.
[0066] In one embodiment, after generating the second knowledge graph, the method further includes:
[0067] The data operation permissions of the data assets in the second knowledge graph are defined in a hierarchical manner, and the hierarchical definition of permissions includes read permission, write permission, share permission, and delete permission;
[0068] When performing data operations on data assets in the second knowledge graph, the original permission hierarchical definition of the data assets is propagated to the new knowledge graph nodes formed by the data operations.
[0069] In an embodiment of the present invention, the permission hierarchy definition is propagated to the new knowledge graph node, including: data obtained by a department has "read-only" permission, and the permission remains unchanged when the data is transferred to another department.
[0070] In the embodiment of the present invention, permission conflict detection is also included. For example, if a data asset has multiple users performing conflicting operations on it (such as one user has deletion permission and another user only has read-only permission), the system will detect it and issue a warning.
[0071] In one embodiment, after step S3, recording the data operation in the second knowledge graph, and updating the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operation, the method further includes:
[0072] S4. Regularly scan the data asset usage records in the updated second knowledge graph, and determine the current data assets based on the data asset usage records;
[0073] In an embodiment of the present invention, after updating the second knowledge graph, the path information in the knowledge graph can also be scanned regularly to monitor the data flow in real time, including the storage location, transmission path and recipient of the data, to ensure that the data can be processed on schedule.
[0074] In the embodiment of the present invention, the usage record includes the records of usage operations, transmission operations and modification operations. By recording the usage records of all data, subsequent audits and compliance checks are facilitated. After each operation on a data asset, the generated data asset or relationship edge is added to the existing knowledge graph as a new knowledge graph node and new edge to update the current knowledge graph. For example:
[0075] Example: Detailed record of a data operation [Data Asset F]--Accessed-->[User G] (timestamp: 2023-09-01 10:00).
[0076] S5. Determine the usage scenarios and regulatory requirements of the current data assets based on the data relationships in the updated second knowledge graph;
[0077] S6. Conduct compliance assessment on the usage records of current data assets based on usage scenarios and regulatory requirements to obtain compliance assessment results.
[0078] In an embodiment of the present invention, compliance assessment also includes: automatically checking compliance with laws and regulations such as GDPR and CCPA through rule nodes in the knowledge graph, such as whether the data is accessed by unauthorized third parties and whether it is properly destroyed.
[0079] In an embodiment of the present invention, natural language processing technology (NLP) can be used to parse legal documents and contract texts, etc. to automatically extract ownership and compliance information related to data assets, and regularly generate compliance reports on data asset ownership and usage to facilitate self-inspection and external audits.
[0080] In one embodiment, when a new data asset is created, its ownership information can be registered in a constructed knowledge graph, and its owner and user can be specified. Data access permissions can also be automatically adjusted based on business needs and permission decisions, and permission management can be defined as permission management at different granularities through the knowledge graph, including data rows, columns, and fields.
[0081] The implementation of the embodiments of the present invention has the following beneficial effects:
[0082] The embodiment of the present invention determines the ownership relationship between the data assets to be managed and the owners, and generates a second knowledge graph based on the ownership relationship and the first knowledge graph; wherein the ownership relationship includes a permission relationship and a usage relationship. The second knowledge graph constructed based on the ownership relationship between the data assets and the owners is conducive to managing and tracking the ownership information of the data assets according to the second knowledge graph, thereby realizing automated processing of permission management, compliance checking and risk assessment, etc., to adapt to the diversified and dynamic characteristics of data, and thus can effectively improve the effect of data asset ownership management.
[0083] Furthermore, the embodiments of the present invention record data operations in the second knowledge graph and update the second knowledge graph according to the data operations. By recording data operations and updating the knowledge graph in real time, it can ensure that the information in the knowledge graph is always consistent with the actual status of the data assets, so that managers can understand the latest status of data assets at any time, such as the frequency of data use, access records, etc., which can effectively improve the efficiency of data asset ownership management.
[0084] See also Figure 2 Based on the same inventive concept as the above embodiment, the present invention also provides a data asset ownership management device, including:
[0085] A first knowledge graph generation module 10, used to obtain the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata;
[0086] The second knowledge graph generation module 20 is used to determine the ownership relationship between the data assets to be managed and the owner, and generate the second knowledge graph according to the ownership relationship and the first knowledge graph;
[0087] The second knowledge graph updating module 30 is used to record data operations in the second knowledge graph and update the second knowledge graph according to new knowledge graph nodes and new edges generated by the data operations.
[0088] In one embodiment, the first knowledge graph generating module 10 is further used to:
[0089] Extract the basic attributes of metadata and generate initial knowledge graph nodes based on the basic attributes;
[0090] Label the data sensitivity according to the data content of the metadata, and generate graph attributes based on the data sensitivity;
[0091] Based on the initial knowledge graph nodes and graph attributes, a first knowledge graph is generated.
[0092] In one embodiment, after determining the ownership relationship between the data asset to be managed and the owner, the method further includes:
[0093] Different ownership relationships are represented using specific semantic descriptions, where the specific semantic descriptions include ownership and creation.
[0094] In one embodiment, the data asset ownership management device also includes a permission propagation module, which is used to define the data operation permissions of the data assets in the second knowledge graph in a hierarchical manner, and the permission hierarchy definition includes read permission, write permission, sharing permission and deletion permission; when performing data operations on the data assets in the second knowledge graph, the original permission hierarchy definition of the data assets is propagated to the new knowledge graph node formed by the data operation.
[0095] In one embodiment, the data asset ownership management device also includes a compliance assessment module, which is used to periodically scan the data asset usage records in the updated second knowledge graph, determine the current data assets based on the data asset usage records; determine the usage scenarios and regulatory requirements of the current data assets based on the data relationships in the updated second knowledge graph; and perform a compliance assessment on the usage records of the current data assets based on the usage scenarios and regulatory requirements to obtain a compliance assessment result.
[0096] The present invention also provides a terminal device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, the data asset ownership management method as described above is implemented.
[0097] The present invention also provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the data asset ownership management method as described above.
[0098] Correspondingly, an embodiment of the present invention also provides a terminal device, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the data asset ownership management method of any one of the above embodiments.
[0099] The terminal device of this embodiment includes: a processor, a memory, and a computer program and computer instructions stored in the memory and executable on the processor. When the processor executes the computer program, each step in the above embodiment 1 is implemented, for example Figure 1 Alternatively, when the processor executes the computer program, the functions of each module / unit in the above-mentioned device embodiment are implemented, such as the second knowledge graph generation module 20.
[0100] Exemplarily, the computer program can be divided into one or more modules / units, one or more modules / units are stored in a memory and executed by a processor to complete the present invention. One or more modules / units can be a series of computer program instruction segments that can perform specific functions, and the instruction segments are used to describe the execution process of the computer program in a terminal device. For example, the second knowledge graph generation module 20 is used to determine the ownership relationship between the data assets to be managed and the owner, and generate the second knowledge graph based on the ownership relationship and the first knowledge graph.
[0101] The terminal device may be a computing device such as a desktop computer, a notebook, a PDA, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory. Those skilled in the art will appreciate that the schematic diagram is merely an example of a terminal device and does not constitute a limitation on the terminal device. The terminal device may include more or fewer components than shown in the diagram, or may combine certain components, or different components. For example, the terminal device may also include an input / output device, a network access device, a bus, etc.
[0102] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, and uses various interfaces and lines to connect various parts of the entire terminal device.
[0103] The memory can be used to store computer programs and / or modules. The processor realizes various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created according to the use of the mobile terminal, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure data (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0104] Among them, if the module / unit integrated in the terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electric carrier signals and telecommunication signals.
[0105] Correspondingly, an embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the data asset ownership management method of any one of the above embodiments.
[0106] The above specific embodiments further illustrate the purpose, technical solutions and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. It is particularly pointed out that for those skilled in the art, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention should be included in the scope of protection of the present invention.
Claims
1. A data asset ownership management method, characterized in that: include: Acquire the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata; Determine the ownership relationship between the data asset to be managed and the owner, and generate a second knowledge graph based on the ownership relationship and the first knowledge graph; Record the data operations in the second knowledge graph, and update the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operations.
2. The data asset ownership management method according to claim 1, characterized in that: The generating a first knowledge graph based on the metadata includes: Extracting basic attributes of the metadata, and generating initial knowledge graph nodes according to the basic attributes; Annotating data sensitivity according to data content of the metadata, and generating graph attributes according to the data sensitivity; Based on the initial knowledge graph nodes and the graph attributes, a first knowledge graph is generated.
3. The data asset ownership management method according to claim 1, characterized in that: After determining the ownership relationship between the data assets to be managed and the owner, the following steps are also included: Different ownership relationships are represented by using specific semantic descriptions, wherein the specific semantic descriptions include ownership and creation.
4. The data asset ownership management method according to claim 1, characterized in that: After generating the second knowledge graph, it also includes: Performing hierarchical definition of data operation permissions for the data assets in the second knowledge graph, wherein the hierarchical definition of permissions includes read permission, write permission, share permission, and delete permission; When performing data operations on data assets in the second knowledge graph, the original permission hierarchical definition of the data assets is propagated to the new knowledge graph nodes formed by the data operations.
5. The data asset ownership management method according to claim 1, characterized in that: After recording the data operation in the second knowledge graph and updating the second knowledge graph according to the new knowledge graph nodes and new edges generated by the data operation, the method further includes: Periodically scan the data asset usage records in the updated second knowledge graph, and determine the current data assets according to the data asset usage records; Determine usage scenarios and regulatory requirements for current data assets based on data relationships in the updated second knowledge graph; Based on the usage scenario and regulatory requirements, a compliance assessment is performed on the usage record of the current data asset to obtain a compliance assessment result.
6. A data asset ownership management device, characterized in that: include: A first knowledge graph generation module, used to obtain the data assets to be managed, extract metadata from the data assets to be managed, and generate a first knowledge graph based on the metadata; A second knowledge graph generation module, used to determine the ownership relationship between the data asset to be managed and the owner, and generate a second knowledge graph based on the ownership relationship and the first knowledge graph; The second knowledge graph updating module is used to record data operations in the second knowledge graph and update the second knowledge graph according to new knowledge graph nodes and new edges generated by the data operations.
7. The data asset ownership management device according to claim 6, characterized in that: It also includes a permission propagation module, which is used to define the data operation permissions of the data assets in the second knowledge graph in a hierarchical manner, and the permission hierarchy definition includes read permission, write permission, share permission and delete permission; when performing data operations on the data assets in the second knowledge graph, the original permission hierarchy definition of the data assets is propagated to the new knowledge graph node formed by the data operation.
8. The data asset ownership management device according to claim 6, characterized in that: It also includes a compliance assessment module, which is used to regularly scan the data asset usage records in the updated second knowledge graph and determine the current data assets based on the data asset usage records; Based on the data relationships in the updated second knowledge graph, the usage scenarios and regulatory requirements of the current data assets are determined; based on the usage scenarios and regulatory requirements, a compliance assessment is performed on the usage records of the current data assets to obtain a compliance assessment result.
9. A terminal device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the data asset ownership management method as described in any one of claims 1 to 5 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the data asset ownership management method according to any one of claims 1 to 5.
Citation Information
Cited By
Method, system and equipment for constructing data resource property graph based on asset management shell and medium
CN121658667A