Distributed multi-level organization data space construction method and device based on tree structure
By adopting a distributed multi-level organizational data space construction method based on tree structure in complex organizational structures, the problem of data sharing and integration is solved, efficient data circulation and collaborative management is realized, and data security and compliance are ensured.
Patent Information
- Application Number
- CN202510345205.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-13
AI Technical Summary
It is difficult for the existing technology to achieve efficient sharing and integration of data under a complex organizational structure, and there is a contradiction between data standardization and innovation needs, and it is difficult to maintain data unity and consistency while ensuring organizational autonomy.
A distributed multi-level organizational data space construction method based on a tree structure is adopted. By constructing a tree topological structure, the separation of data control rights, management rights and usage rights is achieved, cross-domain data sharing is supported, and data management needs are met under complex organizational structures.
It realizes efficient circulation and collaborative management of data among multiple levels among organizations, meets the needs of complex organizational structures, ensures the security and compliance of data management, supports cross-domain data sharing, and improves data utilization efficiency.
Smart Images

Figure CN120151208A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data space sharing, and in particular to a method and device for constructing a distributed multi-level organizational data space based on a tree structure. Background Art
[0002] With the deepening of the national big data strategy, big data has become a key strategic resource for enterprises to enhance their core competitiveness. However, in enterprises of a certain size, the problem of data islands is seriously affecting the efficiency of data resource utilization.
[0003] The data island problem refers to the lack of effective connection and interaction between data due to the complexity of the organizational structure of an enterprise after it has developed to a certain stage, such as the establishment of multiple branches and business units, and the independent storage and definition of data by each organizational unit. This phenomenon makes the data of each organizational unit like isolated islands, making it difficult to achieve efficient sharing and collaborative application within the enterprise, thus hindering the integration of data resources and the release of value.
[0004] Currently, the mainstream strategy to solve the problem of data silos is to aggregate scattered data into a unified data warehouse or data lake through a data integration platform, and rely on the data governance framework and group master data management.
[0005] The current mainstream strategy can greatly improve data consistency and collaboration efficiency, but the following problems still exist:
[0006] 1. The development levels of the branches within the group vary greatly, and the business lines are complex and have their own characteristics. There is a significant contradiction between the common data centralized by the group and the individual data of the branches during interaction and collaboration, making it difficult to achieve efficient data sharing and integration.
[0007] 2. There is a contradiction between the data standardization requirements at the group level and the branch's demand for data agility and innovation. Standardization may limit the branch's innovation flexibility, while over-emphasizing innovation will weaken the consistency and coordination of data.
[0008] 3. Some organizations require a high degree of autonomy to achieve their business goals, which conflicts with the group's requirement for unified data management.
[0009] How to maintain the unity and consistency of data while ensuring organizational autonomy. Currently, there are two main modes for data space sharing:
[0010] One is a completely decentralized flat structure, which is difficult to adapt to the modular management model of internal data in complex organizations. The other is a completely centralized model, in which control and management rights are not effectively separated, resulting in a prominent contradiction between centralized management and autonomy needs.
[0011] Neither of these two modes can effectively promote data sharing among government, public security, and internal organizational units of large enterprises. Summary of the Invention
[0012] To solve the above problems, the object of the present invention is to propose a method for constructing a distributed multi-level organizational data space based on a tree structure, which can achieve efficient construction and secure communication of a distributed data space and is applicable to data management and interaction scenarios under a multi-level organizational structure.
[0013] Another object of the present invention is to provide a device for constructing a distributed multi-level organizational data space based on a tree structure. By constructing a tree topology structure, the separation of powers of data control, management, and use rights is achieved, cross-domain data sharing is supported, and the data management requirements under a complex organizational structure are met.
[0014] The object of the present invention and the solution to its technical problems are achieved by adopting the following technical solutions. A method for constructing a distributed multi-level organizational data space based on a tree structure according to the present invention includes the following steps:
[0015] 1) Construct data space nodes with autonomous management capabilities. The data space nodes have independent operating capabilities and data autonomy characteristics and have native control rights over the data in their respective data spaces.
[0016] 2) Use a space network coordination node device to deploy space network coordination nodes.
[0017] 3) Register the data space nodes to the space network coordination nodes to construct a distributed space communication network.
[0018] 4) Based on the organizational hierarchy relationship, construct a multi-level data space tree topology to form a tree-structured space management network.
[0019] 5) Based on the tree-structured management network, implement a separation of powers control mechanism for data control, management, and use rights and support cross-domain data sharing.
[0020] Furthermore, the data space nodes include the following core functional modules:
[0021] A space network connection unit configured to establish a physical communication link with a space network coordination node through digital certificate authentication. The digital certificate is authorized and issued by the space network coordination node.
[0022] A space management unit configured to maintain the parent-child hierarchical relationship topology between data spaces.
[0023] A space execution unit configured to implement a data three-power control strategy and execute cross-domain data sharing operations.
[0024] Furthermore, the spatial network coordination node includes:
[0025] A security verification unit configured to implement node access security verification and connection auditing through a digital certificate issuance mechanism;
[0026] A spatial network connection unit configured to establish and maintain a communication topology network among distributed spatial nodes.
[0027] Furthermore, the specific steps for establishing a hierarchical connection among the data space nodes include:
[0028] Data space A applies to register as a subspace of data space B;
[0029] Data space A sends an application work order to the spatial network connection unit of the spatial network coordination node through the spatial network connection unit;
[0030] The spatial network connection unit forwards the work order to the data space B node according to the work order information;
[0031] After the data space B node approves and agrees, a parent-child hierarchical relationship is established between data space A and data space B;
[0032] Through the spatial network coordination node, the new relationship is broadcast to the relevant data nodes;
[0033] Repeat the above steps to establish a data space network with a multi-level organization;
[0034] The hierarchical relationship of the network is represented as a directed tree, T = (V, E), where V is the set of nodes representing all data space nodes, and E is the set of edges representing the parent-child hierarchical relationship; each node vi ∈ V represents a data space node, and each edge (vi, vj) ∈ E represents that node vi is the parent node of node vj, and vj is the child node of vi.
[0035] In addition, the present invention also discloses a distributed multi-level organization data space construction device based on a tree structure, including:
[0036] A spatial communication network, a distributed network topology structure based on a centralized coordination mechanism;
[0037] A spatial network connection unit that implements verification of the online status of nodes through a heartbeat detection protocol;
[0038] A node management unit that supports node disabling, enabling, and topology removal management operations.
[0039] Furthermore, in the above-mentioned distributed multi-level organization data space construction device, it further includes:
[0040] Map the segmented data management model of the complex organizational structure in the real world to a tree - type topological structure;
[0041] Implement a work order approval mechanism for the parent space to the sub - space. The data sharing operation in the sub - space needs to submit an operation work order to the parent space and be executed after approval;
[0042] The parent space has the data access right within the sub - space;
[0043] Support establishing a data usage right authorization relationship between space nodes through digital contracts;
[0044] Support dynamically reconstructing the space hierarchy relationship according to actual business needs.
[0045] Furthermore, in the above - mentioned distributed multi - level organizational data space construction device, the separation of powers control mechanism for data control right, management right and usage right includes:
[0046] Data control right: The data space node has the native control right over the data in its own data space;
[0047] Data management right: The parent space has the approval right for the data sharing operation in the sub - space;
[0048] Data usage right: Establish a data usage right authorization relationship through digital contracts to support cross - domain data sharing.
[0049] Furthermore, in the above - mentioned distributed multi - level organizational data space construction device, the digital certificate authentication method includes:
[0050] The space network coordination node issues digital certificates to data space nodes for node access security verification and communication link establishment;
[0051] Implement identity authentication and communication encryption between nodes through digital certificates.
[0052] Furthermore, in the above - mentioned distributed multi - level organizational data space construction device, the cross - domain data sharing includes:
[0053] The sub - space submits a data sharing operation work order to the parent space;
[0054] After the parent space approves, execute the cross - domain data sharing operation;
[0055] Define the data usage right authorization relationship through digital contracts to ensure the compliance and security of data sharing.
[0056] Furthermore, in the above - mentioned distributed multi - level organizational data space construction device, the tree - type topological structure supports dynamic adjustment, including:
[0057] Dynamically add or delete data space nodes according to actual business requirements;
[0058] Dynamically adjust the hierarchical relationship between data space nodes;
[0059] Through the space network, coordinate node broadcasts of hierarchical relationship change information to ensure the consistency of the network topology.
[0060] By means of the above technical solution, the method and device for constructing a distributed multi-level organization data space based on a tree structure according to the present invention have the following advantages:
[0061] 1) The present invention maps the complex block management of data in a huge and complex organization in the real world into a tree structure, and realizes the control of management rights, control rights, and usage rights based on the tree structure; according to the organizational hierarchical structure, this method deconstructs the big data monolithic architecture into a distributed data collaboration network system with distinct levels, which can be coordinated and collaborated, so as to realize the efficient circulation and collaborative management of data among multi-level organizations.
[0062] 2) The present invention realizes the efficient management of multi-level organization data space through a tree topology structure, meeting the requirements of complex organizational structures; adopts a separation-of-powers mechanism for data control rights, management rights, and usage rights to ensure the security and compliance of data management; supports cross-domain data sharing to improve data utilization efficiency; through dynamic adjustment functions, it can flexibly adapt to business changes and enhance the scalability and adaptability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 It is a flowchart of the method for constructing a distributed multi-level organization data space based on a tree structure in an embodiment of the present invention;
[0064] Figure 2 It is a schematic structural diagram of a data space node in an embodiment of the present invention;
[0065] Figure 3 It is a schematic structural diagram of a space network coordination node in an embodiment of the present invention;
[0066] Figure 4 It is a schematic diagram of the tree topology structure in an embodiment of the present invention;
[0067] Figure 5 It is a schematic diagram of data power and responsibility management based on the tree topology structure provided by the present invention;
[0068] Figure 6 It is a schematic diagram of a data space node being connected to a space network coordination node in an application embodiment of the present invention;
[0069] Figure 7 It is a schematic diagram of establishing a hierarchical connection between data space nodes in an application embodiment of the present invention;
[0070] Figure 8 It shows a schematic diagram of the data space connection coordination relationship between the spatial network coordination node and the tree-shaped multi-level organization in the embodiment of the present invention;
[0071] Figure 9 It shows an operation logic diagram of data control right, management right, and usage right based on the multi-level data space system in the embodiment of the present invention.
[0072] Figure 10 It shows a schematic diagram of data permission sharing provided based on the multi-level data space system in the embodiment of the present invention;
[0073] Figure 11 It shows an example diagram of data circulation of the multi-level organization data space based on the tree structure in the embodiment of the present invention. Detailed implementation manners
[0074] The present invention will be further described in detail below through specific preferred embodiments in conjunction with the accompanying drawings, but the present invention is not limited to the following embodiments.
[0075] The present invention discloses a method and device for constructing a distributed multi-level organization data space based on a tree structure.
[0076] As Figure 1 shown, the method for constructing a distributed multi-level organization data space based on a tree structure includes the following steps:
[0077] S101: Construct a data space node with autonomous management ability, which has independent operation ability and data autonomy characteristics, and has native control right over the data in the affiliated data space;
[0078] S102: Register the data space node to the spatial network coordination node to construct a distributed spatial communication network;
[0079] S103: Construct a multi-level data space tree topology based on the organizational hierarchy relationship to form a spatial management network with a tree structure;
[0080] S104: Based on the management network with a tree structure, implement a three-way separation control mechanism for data control right, management right, and usage right, and support cross-domain data sharing.
[0081] The present invention maps the data complex block management of extremely complex organizations in the real world into a tree structure, and realizes the control of management right, control right, and usage right based on the tree structure, so as to realize the efficient circulation and collaborative management of data among multi-level organizations.
[0082] Among them, as Figure 2As shown in the figure, the data space node includes a space network connection unit 201, a space management unit 202, and a space execution unit 203, which are responsible for communication link establishment, hierarchical relationship maintenance, and data sharing operation execution respectively.
[0083] The above data space node includes the following core functional modules:
[0084] The space network connection unit 201 is configured to establish a physical communication link with the space network coordination node through digital certificate authentication, and the digital certificate is authorized and issued by the space network coordination node;
[0085] The space management unit 202 is configured to maintain the parent-child hierarchical relationship topology between data spaces;
[0086] The space execution unit 203 is configured to implement the data triple-rights control strategy and execute cross-domain data sharing operations.
[0087] As Figure 3 shown in the figure, the space network coordination node includes a security verification unit 301 and a space network connection unit 302, which are responsible for node access security verification and communication topology maintenance respectively.
[0088] Among them, the space network coordination node includes: a connection security verification unit 301, which is configured to implement node access security verification and connection auditing through a digital certificate issuance mechanism; a space network connection unit 302, which is configured to establish and maintain a communication topology network between distributed space nodes.
[0089] Among them, the specific steps for establishing a hierarchical connection between data space nodes include:
[0090] 1) Data space A applies to register as a subspace of data space B;
[0091] 2) Data space A sends an application work order to the space network connection unit of the space network coordination node through the space network connection unit;
[0092] 3) The space network connection unit forwards the work order to the data space B node according to the work order information;
[0093] 4) After the data space B node approves and agrees, data space A and data space B establish a parent-child hierarchical relationship;
[0094] 5) Through the space network coordination node, broadcast the new relationship to the relevant data nodes; repeat the above steps to establish a multi-level organized data space network.
[0095] As Figure 4 shown in the figure, the tree topology structure is represented as a directed tree, which supports dynamic adjustment of the hierarchical relationship.
[0096] The hierarchical relationship of the network is represented as a directed tree, T = (V, E), where V is the set of nodes representing all data space nodes, and E is the set of edges representing the parent-child hierarchical relationship; each node vi ∈ V represents a data space node, and each edge (vi, vj) ∈ E represents that node vi is the parent node of node vj, and vj is the child node of vi.
[0097] Among them, the separation of powers control mechanism for data control, management, and use rights includes: data control right, the data space node has the original control right over the data in its affiliated data space; data management right, the parent space has the approval authority for data sharing operations in the sub-space; data use right, the authorization relationship of data use rights is established through digital contracts to support cross-domain data sharing.
[0098] As Figure 5 shown, the cross-domain data sharing process includes three steps: work order submission, approval, and execution to ensure the security and compliance of data sharing.
[0099] Among them, the specific process of cross-domain data sharing includes: the sub-space submits a data sharing operation work order to the parent space; after the parent space approves, the cross-domain data sharing operation is executed; the authorization relationship of data use rights is clarified through digital contracts to ensure the compliance and security of data sharing.
[0100] Among them, the tree-shaped topology structure supports dynamic adjustment, including: dynamically adding or deleting data space nodes according to actual business needs; dynamically adjusting the hierarchical relationship between data space nodes; broadcasting hierarchical relationship change information through the space network coordination node to ensure the consistency of the network topology.
[0101] Conclusion: The present invention provides a method and device for constructing a distributed multi-level organizational data space based on a tree structure, which can effectively solve the data management problem under a complex organizational structure and has a wide range of application prospects.
[0102] The present invention proposes a method for constructing a distributed multi-level organizational data space based on a tree structure, which involves two core components: a space network coordination node and a data space node. Among them:
[0103] 1. Space network coordination node, which contains two core units:
[0104] Connection security verification unit: responsible for generating connection security certificates and verifying the security certificates to ensure the security of the connection.
[0105] Space network connection unit: responsible for managing the connection status of each connection unit and coordinating the communication between the connection nodes registered under the coordination node.
[0106] 2. Data space node, which contains three core units:
[0107] Space network connection unit: registers the data space into the space network by using security certificates and is responsible for communication with other data spaces.
[0108] Space management unit: responsible for managing the information of the current data space and establishing hierarchical relationships with other data spaces.
[0109] Space execution unit: mainly responsible for data transmission and processing.
[0110] The present invention maps the complex data block management of huge and complex organizations in the real world into a tree structure, and realizes the control of management rights, control rights and usage rights based on the tree structure.
[0111] Based on the organizational hierarchy, this method deconstructs the big data monomer architecture into a hierarchical, coordinated and collaborative distributed data collaborative network system, thereby achieving efficient circulation and collaborative management of data among multi-level organizations.
[0112] The data space node provided by the present invention is connected to the space network coordination node, and the function includes the following steps:
[0113] 1) The connection security verification unit in the space network coordination node issues a security key containing connection IP, port, key and other information to the data space node.
[0114] 2) The space network connection unit of the data space node reads the key information and uses the key information to initiate a connection request to the space network connection unit.
[0115] 3) The spatial network coordination node verifies the key information from the data space node and verifies whether the connection is allowed. If the connection is allowed, the network coordination node broadcasts the newly registered data space to other data spaces.
[0116] 4) Repeating the above steps can establish a connected distributed physical space network. The hierarchical relationship of the network can be expressed as S=M(R1, R2,...Rn), where S is the data space physical connection network; M is the space connection coordination node, responsible for verifying, managing and broadcasting connection information; Rn represents the nth data space node, and each node joins the network in turn through the above steps.
[0117] The data space nodes provided by the present invention establish hierarchical connections with each other, and the function includes the following steps:
[0118] 1) Data space A applies to be registered as a subspace of data space B.
[0119] 2) The data space A sends the application work order to the space network connection unit of the space network coordination node through the space network connection unit.
[0120] 3) The space network connection unit forwards the work order to the data space B node according to the work order information.
[0121] 4) After the data space B node approves and agrees, a parent-child hierarchical relationship is established between spaces A and B.
[0122] 5) Through the space network coordination node, the new relationship is broadcast to the relevant data nodes.
[0123] Repeating the above steps can establish a data space network with a multi-level organization. The hierarchical relationship of this network can be represented as a directed tree, T = (V, E), where V is the set of nodes, representing all data space nodes, and E is the set of edges, representing the parent-child hierarchical relationship; each node vi ∈ V represents a data space node, and each edge (vi, vj) ∈ E represents that node vi is the parent node of node vj, and vj is the child node of vi.
[0124] The data sharing and circulation based on the multi-level data space system provided by the present invention includes the following steps:
[0125] 1) The sub-sub space initiates a data sharing request to the parent space.
[0126] 2) After the data sharing request management work order is approved by the sub space, it enters the parent space for approval.
[0127] 3) When the relevant organization approval between organizations is completed, the work order will trigger the data cascade service, and the data will be directly transmitted from the sub-sub space to the parent space through the data stream.
[0128] The operation logic of data control right, management right, and use right based on the multi-level data space system provided by the present invention includes the following logic:
[0129] 1) This space has absolute control over the data belonging to this space.
[0130] 2) The parent space has management rights over the sub space nodes. For operation work orders related to data sharing in the sub space, they need to be transferred to the parent space and can only be executed after being approved by the parent space. The parent space has the right to view the data in the sub space.
[0131] 3) Between data spaces, the right to use the data can be granted to other data spaces through an authorization mechanism.
[0132] The following are the relevant contents of specific application embodiments of the method and device for constructing a distributed multi-level organization data space based on a tree structure according to the present invention.
[0133] Application Example 1
[0134] Taking the construction of an integrated big data platform in the government affairs industry as an example, the method flow for constructing a distributed multi-level organizational data space based on a tree structure is as follows Figure 6 shown
[0135] Step 1: City A constructs a data space with self-management capabilities. City A applies to the provincial data space to join the provincial platform to construct a distributed data connection
[0136] Step 2: The provincial data space issues a connection certificate to the data space of City A through the space network coordination node
[0137] Step 3: The data space of City A reads the connection information and security key in the connection certificate and registers itself to the space network coordination node of the provincial platform
[0138] Step 4: The space network coordination node of the provincial platform broadcasts the newly registered space information of City A to other already registered data spaces
[0139] Based on the above steps, the connection of the distributed data space is completed. The method flow for City A to register as a sub-node component of the provincial data space is as follows Figure 7 shown
[0140] Step 1: The data space of City A initiates a work order to apply to become a sub-node of the provincial data space through the space network coordination node
[0141] Step 2: The data space of City A sends the work order to the space of the provincial data platform through the space network coordination node
[0142] Step 3: The space of the provincial data platform approves the work order. After approving the work order, the work order status information is synchronized to the data space of City A through the space network. If the provincial data platform agrees that the data space of City A becomes its sub-node, the logical connection information is synchronized to the data space of City A through the network data space, completing the establishment of the parent-child management relationship between the provincial and city data spaces
[0143] Step 4: The data spaces of other cities repeat the above steps to complete the construction of a distributed multi-level organizational data space based on a tree structure at the provincial and city levels. Counties and districts can continue to complete the construction of a distributed multi-level organizational data space with a three-level tree structure of province, city, county, and district according to the above steps
[0144] After the above steps are completed, as shown Figure 8 shown
[0145] Application Example 2
[0146] Taking the government affairs industry as an example, a data management method under a distributed multi-level organizational data space based on a tree structure is as follows Figure 9 as shown
[0147] 1) Each level of space at the provincial, city, and county levels has absolute control over the data belonging to this space and can perform operations such as querying, editing, arithmetic analysis, application, sharing, and deletion on the data
[0148] 2) The parent space has management authority over the child space. For example, the provincial data space has management authority over the city data space, and the city data space has management authority over the county data space. The parent space can view the metadata under the child data space and manage the cross-space data sharing approval of the child space
[0149] 3) Spaces can grant the right of use across spaces based on the tree-level management network. For example, the b county space grants the right to use data to the B city space
[0150] Application Example 3
[0151] Taking the government affairs industry as an example, a data permission granting method under a distributed multi-level organizational data space based on a tree structure is as follows Figure 10 as shown
[0152] Step 1, the a county space authorizes a certain data of its own for the B city data space to access. The authorization work order is synchronized to the B city data space based on the distributed multi-level organizational data space management network
[0153] Step 2, the authorization work order will also be transferred to the A city space, the parent space of the a county space. The A city space approves the work order. If the approval is passed, it will be transferred to the provincial space, the common parent space, for approval
[0154] Step 3, after the approval is passed, the space network coordination node will write a permission to the a county space and the B city space
[0155] Step 4, the B city space can access the data of the a county space through the use interface, realizing cross-space data permission sharing
[0156] Application Example 4
[0157] Taking the government affairs industry as an example, a data circulation method under a distributed multi-level organizational data space based on a tree structure is as follows Figure 11 as shown
[0158] Step 1, the a county space applies to push its own data to the provincial data space. The application work order is synchronized to the provincial data space based on the distributed multi-level organizational data space management network
[0159] In step 2, the work order application will also be transferred to the parent space of the a district / county space, i.e., the A city space. The A city space approves the work order. If the approval is passed, it will be transferred to the provincial space, the common parent space, for approval.
[0160] In step 3, after the provincial space agrees to receive, it sends the connection information of the received data to the data transmission channel through the space network coordination node. The data transmission channel obtains the data information of the initiating space and the connection information of the receiving end from the work order to establish a data stream transmission task and initiate data transfer.
[0161] As described above, it is only a preferred embodiment of the present invention, and there is no any formal limitation to the present invention. Therefore, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present invention without departing from the content of the technical solution of the present invention still fall within the scope of the technical solution of the present invention.
Claims
1. A method for constructing a distributed multi-level organizational data space based on a tree structure, characterized in that: The following steps are involved: 1) Construct data space nodes with autonomous management capabilities. The data space nodes have independent operation capabilities and data autonomy characteristics, and have native control over the data in the data space to which they belong; 2) deploying a space network coordination node using a space network coordination node device; 3) registering the data space node to the space network coordination node to build a distributed space communication network; 4) Construct a multi-level data space tree topology based on the organizational hierarchy to form a tree-structured space management network; 5) Based on the tree-structured management network, a separation control mechanism of data control rights, management rights and usage rights is implemented, and cross-domain data sharing is supported.
2. The method for constructing a distributed multi-level organizational data space based on a tree structure according to claim 1, characterized in that: The data space node includes the following core functional modules: A space network connection unit, configured to establish a physical communication link with the space network coordination node through a digital certificate authentication method, wherein the digital certificate is authorized and issued by the space network coordination node; A space management unit configured to maintain a parent-child hierarchical relationship topology between data spaces; A spatial execution unit is configured to implement the data three-rights control strategy and perform cross-domain data sharing operations.
3. The method for constructing a distributed multi-level organizational data space based on a tree structure according to claim 1, characterized in that: The spatial network coordination node includes: A security verification unit, configured to implement node access security verification and connection auditing through a digital certificate issuance mechanism; The space network connection unit is configured to establish and maintain a communication topology network among distributed space nodes.
4. The method for constructing a distributed multi-level organizational data space based on a tree structure according to claim 1, characterized in that: The specific steps of establishing hierarchical connections between the data space nodes include: Data space A applies to be registered as a subspace of data space B; Data space A sends the application work order to the space network connection unit of the space network coordination node through the space network connection unit; The space network connection unit forwards the work order to the data space B node according to the work order information; After the data space B node is approved, data space A and data space B establish a parent-child hierarchical relationship; Through the spatial network coordination node, the new relationship is broadcast to the relevant data nodes; Repeat the above steps to build a multi-level organizational data space network; The hierarchical relationship of the network is represented as a directed tree, T = (V, E), where V is a node set representing all data space nodes, and E is an edge set representing the parent-child hierarchical relationship; each node vi∈V represents a data space node, and each edge (vi, vj)∈E represents that node vi is the parent node of node vj, and vj is the child node of vi.
5. A distributed multi-level organizational data space construction device based on a tree structure, characterized in that: include: Space communication network, a distributed network topology based on a centralized coordination mechanism; The space network connection unit verifies the online status of nodes through the heartbeat detection protocol; The node management unit supports node disabling, enabling, and topology removal management operations.
6. The distributed multi-level organizational data space construction device based on tree structure according to claim 5 is characterized in that: Also includes: Map the modular data management model of complex organizational structures in the real world to a tree topology; Implement the work order approval mechanism of the parent space for the child space. The data sharing operation of the child space needs to submit the operation work order to the parent space and execute it after approval; The parent space has the data access permissions in the child space; Support the establishment of data usage authorization relationships between spatial nodes through digital contracts; Supports dynamic reconstruction of spatial hierarchical relationships based on actual business needs.
7. The apparatus for constructing a distributed multi-level organizational data space based on a tree structure according to any one of claims 1 to 6, characterized in that: The three-power separation control mechanism of data control rights, management rights and usage rights includes: Data control rights: Data space nodes have native control over the data in their data space; Data management rights: the parent space has the authority to approve data sharing operations of the child space; Data usage rights, establish data usage rights authorization relationships through digital contracts, and support cross-domain data sharing.
8. The apparatus for constructing a distributed multi-level organizational data space based on a tree structure according to any one of claims 1 to 6, characterized in that: The digital certificate authentication method includes: The space network coordination node issues digital certificates to data space nodes for node access security verification and communication link establishment; Identity authentication and communication encryption between nodes are achieved through digital certificates.
9. The apparatus for constructing a distributed multi-level organizational data space based on a tree structure according to any one of claims 1 to 6, characterized in that: The cross-domain data sharing includes: The child space submits a data sharing operation ticket to the parent space; After the parent space is approved, the cross-domain data sharing operation is performed; Clarify data usage authorization relationships through digital contracts to ensure compliance and security of data sharing.
10. The apparatus for constructing a distributed multi-level organizational data space based on a tree structure according to any one of claims 1 to 6, characterized in that: The tree topology structure supports dynamic adjustment, including: Dynamically add or delete data space nodes according to actual business needs; Dynamically adjust the hierarchical relationship between data space nodes; The spatial network coordinates nodes to broadcast hierarchical relationship change information to ensure the consistency of network topology.
Citation Information
Cited By
Trusted data space security interaction method and system
CN121585346A
Distributed multi-level application system and method based on unified data model
CN121681670A