A Spatial Authentication Method and System for Spatiotemporal Data Services
By grid division and efficient matching algorithms for administrative area spatial element areas, the problems of complex data organization and large amount of calculation in spatiotemporal data services are solved, and efficient and accurate spatial authentication and access control are achieved.
Patent Information
- Application Number
- CN202510604452.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-12
AI Technical Summary
In the prior art, the spatial authentication method of spatiotemporal data services has cumbersome data organization process and large calculations, making it difficult to efficiently and accurately control user access rights.
By dividing the spatial element areas of administrative districts at all levels, a time-space grid model is formed. The client obtains the user's administrative district code and access scope, and combines the efficient grid matching algorithm to determine whether the user has access rights. The server only processes hit grid requests.
It realizes efficient and accurate spatial scope authentication, simplifies the data organization process, reduces the amount of calculation, and improves the efficiency and accuracy of access control.
Smart Images

Figure CN120110816B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data access control, and more specifically, to a spatial authentication method and system for spatio-temporal data services. Background Art
[0002] With the rapid development of 3S technology, spatio-temporal data has been deeply applied in all walks of life, such as traffic navigation data, spatio-temporal positioning data, river water area data, administrative division range data, three zones and three lines data, real estate data, etc., affecting all aspects of people's lives. The storage, visualization, and application of spatio-temporal data are generally carried by spatio-temporal data services, which are very basic and important usage forms. However, since most spatio-temporal data is confidential data with high data security requirements, and the data within the spatial range that can be used by personnel with different levels and role permissions is different, this requires that the use of spatio-temporal data services must have the ability of spatial authentication. How to efficiently and accurately solve the problem of spatial authentication, so as to improve the access control requirements of spatial services, is the core problem to be solved.
[0003] Currently, the main method for controlling user access permissions is to store spatial elements of different administrative regions as different layers. When a user accesses, according to the administrative division code where the user is located, only the data layer of the administrative region where the user is located is pushed. Although this method can effectively control the user's access to data permissions, the process of organizing spatial data is complex and the data redundancy is relatively high. Summary of the Invention
[0004] The present invention aims at the technical problems existing in the prior art, and provides a spatial authentication method and system for spatio-temporal data services, which overcome the problems of cumbersome data organization process and large amount of calculation in the existing solutions.
[0005] According to a first aspect of the present invention, there is provided a spatial authentication method for spatio-temporal data services, including:
[0006] Step 1, dividing the spatial element regions of each level of administrative region into grids to obtain a grid set corresponding to each spatial element region of the administrative region, wherein the spatial element regions of each level of administrative region are irregular regions;
[0007] Step 2, obtaining a user access request, where the user access request includes the administrative division code where the user is located and the range that the user requests to access;
[0008] Step 3, according to the administrative division code where the user is located, finding the grid set of the administrative region where the user is located;
[0009] Step 4: Determine whether there is a grid in the grid set of the administrative division where the user is located whose distance from the user's requested access range is less than the first set threshold. If so, the user has access permission; otherwise, the user does not have access permission.
[0010] According to the second aspect of the present invention, there is provided a spatial authentication system for spatio-temporal data services, including:
[0011] A grid division module, configured to divide the spatial element areas of each level of administrative division into grids to obtain a grid set corresponding to the spatial element area of each administrative division, where the spatial element areas of each level of administrative division are irregular areas;
[0012] An acquisition module, configured to acquire the administrative division code where the user is located and the user's requested access range;
[0013] A search module, configured to search for the grid set of the administrative division where the user is located according to the administrative division code where the user is located;
[0014] A judgment module, configured to determine whether there is a grid in the grid set of the administrative division where the user is located whose distance from the user's requested access range is less than the first set threshold. If so, the user has access permission; otherwise, the user does not have access permission.
[0015] According to the third aspect of the present invention, there is provided an electronic device, including a memory and a processor. When the processor executes a computer management program stored in the memory, the steps of the spatial authentication method for spatio-temporal data services are implemented.
[0016] According to the fourth aspect of the present invention, there is provided a computer-readable storage medium, on which a computer management program is stored. When the computer management program is executed by a processor, the steps of the spatial authentication method for spatio-temporal data services are implemented.
[0017] A spatial authentication method and system for spatio-temporal data services provided by the present invention form a spatio-temporal grid model by dividing grids of different scales of spatial elements. When the client accesses the spatial service, it acquires the user's administrative region code and access range, inputs them into the model, and combines with the efficient grid matching algorithm of the present invention to obtain the access range hit situation. The server only processes the requests for the hit grids, and finally realizes spatial range authentication. Description of the Drawings
[0018] Figure 1 It is a flowchart of a spatial authentication method for spatio-temporal data services provided by the present invention;
[0019] Figure 2 It is a schematic diagram of the spatial element area of the administrative division and the circumscribed rectangle;
[0020] Figure 3Structural block diagram of a spatial authentication system for spatio-temporal data services provided by the present invention;
[0021] Figure 4 Schematic diagram of the hardware structure of a possible electronic device provided by the present invention;
[0022] Figure 5 Schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed implementation manners
[0023] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. In addition, the technical features in the various embodiments or individual embodiments provided by the present invention can be arbitrarily combined with each other to form a feasible technical solution. Such combination is not restricted by the order of steps and / or the pattern of structural composition, but must be based on the fact that those of ordinary skill in the art can implement it. When the combination of technical solutions appears to be contradictory or unable to be implemented, it should be considered that such combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0024] Figure 1 Flowchart of a spatial authentication method for spatio-temporal data services provided by the present invention, as Figure 1 shown, the method includes:
[0025] Step 1, divide the spatial element regions of each administrative region level into grids to obtain a grid set corresponding to each administrative region spatial element region, where the spatial element regions of each administrative region level are irregular regions.
[0026] It can be understood that, first, collect the spatial element region data of each administrative region level of provinces, cities, counties, townships, and villages, and then divide the spatial element regions of each administrative region level into grids. For example, for the map spatial elements of a certain city, including the spatial elements of each administrative region, divide the spatial element regions of each administrative region into multiple small grids for subsequent accurate retrieval and search.
[0027] In a possible embodiment manner of the present invention, the step 1 of dividing the spatial element regions of each administrative region level into grids to obtain a grid set corresponding to each administrative region spatial element region includes:
[0028] Step 11, obtain the circumscribed rectangle of each administrative region spatial element region as the initial grid.
[0029] Among them, in step 11, obtaining the circumscribed rectangle of the spatial element area of each administrative region as the initial grid includes:
[0030]
[0031]
[0032]
[0033]
[0034]
[0035] Among them, is the geographical coordinate of the i-th data in the spatial element area of the administrative region, is the abscissa, is the ordinate, , , , are the border ranges of the spatial element area of the administrative region, and a circumscribed rectangle is formed according to the border ranges of the spatial element area of the administrative region.
[0036] It can be understood that referring to Figure 2 , the quadrilateral inside is the spatial element area of the administrative region, and the outer rectangular frame is the circumscribed rectangle of the spatial element area of the administrative region, serving as the initial grid containing the spatial element area of the administrative region. The boundary lines of this initial grid can be represented by , , , to represent, and the four boundary lines can form a rectangle.
[0037] Step 12, calculating the intersection-over-union ratio of the initial grid and the spatial element area of the administrative region.
[0038] It can be understood that when calculating the intersection-over-union ratio of the initial grid and the spatial element area of the administrative region, the specific calculation formula is:
[0039]
[0040] Among them, represents the intersection area of the j-th grid and the spatial element area of the administrative region, represents the grid area.
[0041] Step 13, if the intersection-over-union ratio is greater than or equal to the second set threshold, stop grid division; if the intersection-over-union ratio is less than the second set threshold, divide the initial grid into four equal parts along the x-direction and y-direction to form four grids, and execute step 14.
[0042] It is understandable that in the above step 12, the intersection - union ratio of the initial grid and the administrative region spatial element area is calculated. If the intersection - union ratio is greater than or equal to the second set threshold (intersection - union ratio threshold), then this grid is used as a leaf node and further division is stopped. On the contrary, if the intersection - union ratio is less than the second set threshold, then the initial grid needs to be further recursively divided. Specifically, the initial grid is equally divided into four small grids in the x - direction and y - direction.
[0043] Among them, the intersection - union ratio threshold is determined according to the trade - off point between security and performance. If the security requirement is high, the threshold of the intersection - union ratio can be adjusted to refine the grid. On the contrary, if the security requirement is not high but the performance requirement is high, it can also be controlled by adjusting the intersection - union ratio threshold.
[0044] In the embodiment of the present invention, the positive direction of the x - axis is eastward, the negative direction is westward, the positive direction of the y - axis is northward, and the negative direction is southward. The four small grids are represented as:
[0045]
[0046]
[0047]
[0048]
[0049] Among them, 、 、 、 are the grids after quartering respectively, is half of the width of the grid before quartering, is half of the height of the grid before quartering.
[0050] Step 14: Repeat steps 12 and 13 until the intersection - union ratio of each grid and the administrative region spatial element area is greater than or equal to the second set threshold, and obtain the grid set corresponding to each administrative region spatial element area.
[0051] It is understandable that after the grid is divided into four equal parts, continue to calculate the intersection - union ratio of each grid and the administrative region spatial element area, and then determine whether the intersection - union ratio is greater than or equal to the second set threshold. If the intersection - union ratio of all the grids after division and the administrative region spatial element area is greater than the second set threshold, then stop further division and obtain the grid set corresponding to each administrative region element area.
[0052] It should be noted that the present invention does not store the administrative region spatial elements in layers. Multiple administrative region spatial elements are stored in one layer, and the situation of complex data organization will not occur.
[0053] Step 2: Obtain a user access request, where the user access request includes the administrative division code where the user is located and the scope of access requested by the user.
[0054] It can be understood that when a user accesses the spatial element area of an administrative region, the user can only access the spatial elements of the administrative division where the user is located and cannot access the spatial elements of other administrative divisions. Therefore, when receiving a user access request, obtain the administrative division code where the user is located and the scope of access requested by the user. Among them, the administrative division code where the user is located can be obtained according to the user number.
[0055] Step 3: According to the administrative division code where the user is located, find the grid set of the administrative division where the user is located.
[0056] It can be understood that in Step 1, the grid sets of the spatial element areas of each administrative division are obtained. In this step, according to the administrative division code where the user is located, obtain the grid set of the administrative division where the user is located.
[0057] A fast and relatively accurate range matching algorithm is also the key of the present invention. Through Step 1, the corresponding relationship between the administrative division code and the grid has been obtained:
[0058]
[0059] In the formula: represents the grid set generated in Step 1, key is the administrative division code, is the administrative division code where the user is located.
[0060] Step 4: Determine whether there is a grid in the grid set of the administrative division where the user is located whose distance from the scope of access requested by the user is less than a first set threshold. If so, the user has the access right; otherwise, the user does not have the access right.
[0061] It can be understood that after obtaining the scope of access requested by the user and the grid set of the administrative division where the user is located, determine whether the scope of access requested by the user is in the grid set of the administrative division where the user is located. If so, the user has the access right, and the spatial elements within the scope of access requested by the user can be retrieved and pushed to the user. If the scope of access requested by the user is not in the grid set of the administrative division where the user is located, the user does not have the access right, and the user is not allowed to access the spatial elements within the scope of access requested.
[0062] When determining whether the scope of access requested by the user is in the grid set of the administrative division where the user is located, it is actually a process of matching the scope of access requested by the user with the grids in the grid set of the administrative division where the user is located.
[0063] In a possible embodiment of the present invention, step 4, which determines whether there is a grid in the grid set of the administrative region where the user is located whose distance from the user's requested access range is less than a first set threshold. If there is, the user has access rights; otherwise, the user does not have access rights, includes:
[0064] Step 41, calculate the center point coordinates of the user's requested access range and the center point coordinates of each grid in the grid set of the administrative region where the user is located, respectively.
[0065] It can be understood that by calculating the center point coordinates of the user's requested access range and the center point coordinates of each grid in the grid set respectively, the center point coordinates can be expressed as:
[0066]
[0067] where x and y are the abscissa and ordinate of the center point of the user's requested access range or grid, 、 、 、 are the border ranges of the user's requested access range or grid.
[0068] Step 42, based on each center point coordinate, sort the user's requested access range and all grids.
[0069] It can be understood that according to the x-axis coordinates of the center points of the user's requested access range and the grids, the user's requested access range and all grids are sorted according to the x coordinates. For example, the user's requested access range and all grids are sorted in ascending order according to the x coordinates.
[0070]
[0071] where, is the order of the ordered spatial grids, including the arrangement order of the user's requested access range and all grids, and a and b are grid objects.
[0072] Step 43, according to the x coordinate of the center point of the user's requested access range and the x coordinates of each grid in the grid set of the administrative region where the user is located, retrieve grids from the grid set of the administrative region where the user is located whose distance from the x coordinate of the center point of the user's requested access range meets the first condition, and obtain a plurality of candidate grids.
[0073] In a possible embodiment of the present invention, step 43 includes:
[0074] Step 431: Based on the x coordinate of the center point of the user-requested access range and the x coordinates of each grid in the grid set of the administrative region where the user is located, use the binary search method to locate the grid near the user-requested access range.
[0075] It can be understood that based on the X coordinate of the center point of the user-requested access range, quickly locate the nearby grid index through binary search:
[0076]
[0077] In the formula, is the result of binary search, is the encapsulated binary search function.
[0078] Among them, the binary search method is an existing search method and will not be elaborated here. Specifically, based on the x coordinate of the center point of the user-requested access range, use the binary search method to find the grid in the grid set whose distance from the x coordinate of the center point of the user-requested access range is within the set threshold, which is called the nearby grid.
[0079] Step 432: Starting from the nearby grid, retrieve all grids that meet the first condition with respect to the distance from the nearby grid along the positive and negative directions of the x-axis respectively, and use the nearby grid and all retrieved grids that meet the first condition as candidate grids.
[0080] Among them, starting from the nearby index, retrieve the grids whose x coordinates meet the conditions westward and eastward respectively:
[0081]
[0082]
[0083] In the formula, and are the index sets explored in the west and east directions respectively, index is the starting index of binary search, w is the width of the range grid, and are the encapsulated retrieval functions.
[0084] It can be understood that starting from the grid near the user-requested access range found in Step 431 as the retrieval starting position, perform binary search along the positive and negative directions of the x-axis respectively, find all grids that meet the first condition with respect to the distance from the nearby grid in both directions, and use the nearby grid and all retrieved grids that meet the first condition as candidate grids. The first condition mentioned above can be a set distance.
[0085] Step 44: According to the y coordinate of the center point of the user-requested access range and the y coordinates of each of the candidate grids, determine whether there is a candidate grid among the multiple candidate grids whose distance from the y coordinate of the center point of the user-requested access range satisfies the second condition. If there is, the user has access permission; otherwise, the user does not have access permission.
[0086] It can be understood that in step 43, grids that are relatively close to the x coordinate of the user-requested range are found in the grid set. At this time, it is also necessary to verify whether the y-axis coordinates of these grids are also relatively close to the y coordinate of the user-requested access range. Only when both the x coordinate and the y coordinate of the grid are relatively close to the x coordinate and the y coordinate of the user-requested access range, are they considered to match.
[0087] When verifying the y coordinates of the candidate grids, if there is a candidate grid that satisfies , then the user has access permission; otherwise, the user does not have access permission.
[0088] Among them, is the distance between the y coordinate of the center point of the th candidate grid and the y coordinate of the center point of the user-requested access range, is the height of the user-requested access range.
[0089] Among them, when the user needs to access the administrative region spatial element area, an access request can be sent to the Ngnix server. The user access request includes the administrative division code where the user is located and the user-requested access range. When the Ngnix server receives the user's access request, it jumps to the spatial service through the permission verification API. The spatial service determines whether the user-requested access range is in the grid set corresponding to the administrative division code where the user is located. If it is, it indicates that the user has access permission, and the spatial element data within the access range is pushed to the user through the Ngnix server. If the user-requested access range is not in the grid set corresponding to the administrative division where the user is located, it means that the user does not have access permission, and a notification of access rejection is sent to the user through the Ngnix server, achieving the purpose of authenticating the user access request.
[0090] See Figure 3 , a spatial authentication system for spatio-temporal data services provided by the present invention, includes:
[0091] A grid division module 301, configured to divide the spatial element areas of each administrative region into grids to obtain a grid set corresponding to each administrative region spatial element area;
[0092] An acquisition module 302, configured to acquire the administrative division code where the user is located and the user-requested access range;
[0093] A search module 303, configured to search for a grid set of the administrative division where the user is located according to the administrative division code of the user's location;
[0094] A judgment module 304, configured to judge whether there is a grid in the grid set of the administrative division where the user is located whose distance from the access range requested by the user is less than a first set threshold. If so, the user has access permission; otherwise, the user does not have access permission.
[0095] It can be understood that the spatial authentication system for spatio-temporal data services provided by the present invention corresponds to the spatial authentication method for spatio-temporal data services provided in the foregoing embodiments. The relevant technical features of the spatial authentication system for spatio-temporal data services can refer to the relevant technical features of the spatial authentication method for spatio-temporal data services, which will not be elaborated here.
[0096] Please refer to Figure 4 , Figure 4 , which is a schematic diagram of an embodiment of an electronic device provided by an embodiment of the present invention. As Figure 4 shown, an embodiment of the present invention provides an electronic device 400, including a memory 410, a processor 420, and a computer program 411 stored on the memory 410 and executable on the processor 420. When the processor 420 executes the computer program 411, the steps of the spatial authentication method for spatio-temporal data services are implemented.
[0097] Please refer to Figure 5 , Figure 5 , which is a schematic diagram of an embodiment of a computer-readable storage medium provided by the present invention. As Figure 5 shown, this embodiment provides a computer-readable storage medium 500, on which a computer program 511 is stored. When the computer program 511 is executed by a processor, the steps of the spatial authentication method for spatio-temporal data services are implemented.
[0098] A spatial authentication method and system for spatio-temporal data services provided by the present invention, based on intelligent grid division, grid efficient matching mechanism and technology, controls the access permission of each map access by the user. When the user requests to access the map each time, the administrative division code of the user is extracted, the grid set of the corresponding administrative region is retrieved according to the administrative division code of the user, and then the spatial matching of the access range requested by the user is calculated through a grid fast matching algorithm. Finally, combined with the Nginx server technology, the map service is filtered and intercepted according to the matching. This solution takes into account the trade-off between the security and performance when the user accesses the map. If the security requirement is high, the threshold of the intersection-over-union ratio can be adjusted to refine the grid. On the contrary, if the security requirement is not high and the performance requirement is high, the threshold can also be adjusted to control.
[0099] It should be noted that in the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not described in detail in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0100] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0101] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a system for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks
[0102] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction system that implements the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks
[0103] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks
[0104] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.
[0105] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A spatial authentication method for spatio-temporal data services, characterized in that, Including: Step 1: Divide the spatial element areas of each administrative region level into grids to obtain the grid set corresponding to the spatial element area of each administrative region; Step 2: Obtain a user access request, where the user access request includes the administrative division code where the user is located and the user-requested access range; Step 3: According to the administrative division code where the user is located, find the grid set of the administrative region where the user is located; Step 4: Determine whether there is a grid in the grid set of the administrative region where the user is located whose distance from the user-requested access range is less than a first set threshold. If so, the user has access permission; otherwise, the user does not have access permission; The Step 1, which divides the spatial element areas of each administrative region level into grids to obtain the grid set corresponding to the spatial element area of each administrative region, includes: Step 11: Obtain the circumscribed rectangle of each administrative region spatial element area as the initial grid; Step 12: Calculate the intersection-over-union ratio of the initial grid and the administrative region spatial element area; Step 13: If the intersection-over-union ratio is greater than or equal to a second set threshold, stop grid division; if the intersection-over-union ratio is less than the second set threshold, bisect the initial grid along the x-axis and y-axis respectively to form four grids, and execute Step 14; Step 14: Repeat Step 12 and Step 13 until the intersection-over-union ratio of each grid and the administrative region spatial element area is greater than or equal to the second set threshold, and obtain the grid set corresponding to the spatial element area of each administrative region.
2. The spatial authentication method for spatio-temporal data service according to claim 1, characterized in that The Step 11, which obtains the circumscribed rectangle of each administrative region spatial element area as the initial grid, includes: ; ; ; ; ; Among them, is the geographical coordinate of the i-th data in the administrative region spatial element area, is the abscissa, is the ordinate, , , , are the border ranges of the administrative region spatial element area, and an external rectangle is formed according to the border ranges of the administrative region spatial element area; The Step 12, which calculates the intersection-over-union ratio of the initial grid and the administrative region spatial element area, includes: ; Among them, represents the intersection area between the j-th grid and the administrative region spatial element area, represents the grid area; In step 13, if the intersection over union is less than the second set threshold, the initial grid is bisected along the x-direction and the y-direction respectively to form four grids: ; ; ; Among them, , , , are respectively the grids after being divided into four parts, is half of the width of the grid before being divided into four parts, is half of the height of the grid before being divided into four parts.
3. The spatial authentication method for spatio-temporal data service according to claim 1, characterized in that The Step 4, which determines whether there is a grid in the grid set of the administrative region where the user is located whose distance from the user-requested access range is less than a first set threshold. If so, the user has access permission; otherwise, the user does not have access permission, includes: Calculate the center point coordinates of the user-requested access range and the center point coordinates of each grid in the grid set of the administrative region where the user is located respectively; Sort the user-requested access range and all grids based on each center point coordinate; According to the x coordinate of the center point of the user-requested access range and the x coordinates of each grid in the grid set of the administrative region where the user is located, retrieve grids from the grid set of the administrative region where the user is located whose distance from the x coordinate of the center point of the user-requested access range satisfies a first condition to obtain multiple candidate grids; According to the y coordinate of the center point of the user-requested access range and the y coordinates of each of the candidate grids, determine whether there is a candidate grid in the multiple candidate grids whose distance from the y coordinate of the center point of the user-requested access range satisfies a second condition. If so, the user has access permission; otherwise, the user does not have access permission.
4. The spatial authentication method for spatio-temporal data service according to claim 3, characterized in that, Retrieving, from the grid set of the administrative division where the user is located, grids whose distance from the x-coordinate of the center point of the user-requested access range meets a first condition based on the x-coordinate of the center point of the user-requested access range and the x-coordinate of each grid in the grid set of the administrative division where the user is located, to obtain a plurality of candidate grids, including: Locating the grids near the user-requested access range by means of binary search according to the x-coordinate of the center point of the user-requested access range and the x-coordinate of each grid in the grid set of the administrative division where the user is located; Starting from the nearby grids, retrieving all grids whose distance from the nearby grids meets the first condition along the positive and negative directions of the x-axis respectively, and taking the nearby grids and all the retrieved grids that meet the first condition as candidate grids.
5. The spatial authentication method for spatio-temporal data service according to claim 3, characterized in that, Judging whether there is a candidate grid in the plurality of candidate grids whose distance from the y-coordinate of the center point of the user-requested access range meets a second condition according to the y-coordinate of the center point of the user-requested access range and the y-coordinate of each candidate grid. If so, the user has access permission; otherwise, the user does not have access permission, including: If there exists a candidate grid that satisfies , the user has access rights; otherwise, the user does not have access rights. Wherein, is the distance between the y coordinate of the center point of the th candidate grid and the y coordinate of the center point of the user-requested access range, and is the height of the user-requested access range.
6. A spatial authentication system for spatio-temporal data services, characterized in that, Including: A grid division module for dividing the spatial element area of each administrative division level into grids to obtain a grid set corresponding to each administrative division spatial element area; An acquisition module for acquiring the administrative division code where the user is located and the user-requested access range; A search module for searching for the grid set of the administrative division where the user is located according to the administrative division code where the user is located; A judgment module for judging whether there is a grid in the grid set of the administrative division where the user is located whose distance from the user-requested access range is less than a first set threshold. If so, the user has access permission; otherwise, the user does not have access permission; The grid division module for dividing the spatial element area of each administrative division level into grids to obtain a grid set corresponding to each administrative division spatial element area, including: Obtaining the circumscribed rectangle of each administrative division spatial element area as the initial grid; Calculating the intersection-over-union ratio of the initial grid and the administrative division spatial element area; If the intersection-over-union ratio is greater than or equal to a second set threshold, stop grid division; if the intersection-over-union ratio is less than the second set threshold, bisect the initial grid along the x-direction and y-direction respectively to form four grids, and continue to divide each grid until the intersection-over-union ratio of each grid and the administrative division spatial element area is greater than or equal to the second set threshold, and obtain the grid set corresponding to each administrative division spatial element area.
7. An electronic device, characterized in that, Including a memory and a processor, the processor is used to implement the spatial authentication method of the spatio-temporal data service according to any one of claims 1-5 when executing the computer management program stored in the memory.
8. A computer-readable storage medium, characterized in that, Stored thereon is a computer management program, and when the computer management program is executed by the processor, it implements the spatial authentication method of the spatio-temporal data service according to any one of claims 1-5.
Citation Information
Patent Citations
Dynamic management and access control method for remote sensing image service
CN118520126A