Data element management method and device based on industrial internet identification analysis system
By binding data identifiers and data ownership information in the industrial Internet identity resolution system and querying access control policies based on data identifiers, the problem of unclear data ownership in the industrial machinery collaborative manufacturing ecosystem is solved, cross-supply chain data traceability and authorized access control are realized, and data security is ensured.
Patent Information
- Application Number
- CN202510312177.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-06-20
AI Technical Summary
In the industrial Internet identification resolution system, in the complex industrial machinery collaborative manufacturing ecosystem, data ownership is unclear, which makes it difficult to achieve cross-supply chain data traceability and authorized access control, and needs to be implemented under the premise of limited IT resources and high IT investment.
By registering the data identifier of the data in the industrial Internet identification resolution system and associating it with the data ownership information, the binding of the data identifier and the data ownership information is realized. During the data access process, access control policies are queried based on the data identifier, permission judgment and access control are performed, and data access channel is provided and access logs are recorded.
In the industrial machinery collaborative manufacturing ecosystem, effectively manage data elements, solve the problems of unclear data ownership and access control, realize cross-supply chain data traceability and authorized access control, and ensure data security.
Smart Images

Figure CN120181618A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of industrial Internet, and in particular to a data element management method and device based on the industrial Internet identification and resolution system. Background Art
[0002] In the collaborative manufacturing ecosystem of complex industrial machinery, multiple enterprises jointly participate in the production of components and the assembly of final products. Each enterprise generates data in its production process, including process parameters, component information, etc. These data are managed through the industrial Internet identification and resolution system. However, due to long-term cooperation relationships and evolving contract agreements, the definition of ownership of process data and component specifications has become unclear, and there are disputes among the participating parties regarding data ownership. These small and medium-sized enterprises usually have limited IT budgets and rely on existing, often heterogeneous, IT infrastructures. For quality traceability and process optimization, they need to achieve cross-supply chain data traceability in the case of unclear data ownership, and at the same time ensure that sensitive data is only securely accessible to authorized partners, all of which need to be achieved without relying on complex emerging technologies and high IT investment.
[0003] In the collaborative manufacturing scenario of industrial small and medium-sized enterprises where data ownership is unclear and the existing IT infrastructure is heterogeneous, designing a data element management method under the industrial Internet identification and resolution system to effectively achieve cross-supply chain data traceability and authorized access control with limited IT resources and ensure data security has become an urgent technical problem to be solved. Summary of the Invention
[0004] In view of the deficiencies of the above-mentioned prior art, the data element management method and device provided by this application, which are applied in the technical field of industrial Internet, have the advantages of effectively achieving cross-supply chain data traceability and authorized access control with limited IT resources and ensuring data security.
[0005] In a first aspect, a data element management method based on the industrial Internet identification and resolution system is provided. This method is applied to an industrial machinery collaborative manufacturing ecosystem, and the ecosystem includes multiple enterprises participating in component production and product assembly. The method includes the following steps: S1: In response to a data registration request from an enterprise, register a data identifier of the data in the industrial Internet identification and resolution system, and when registering, associate the data identifier with data ownership information, where the data ownership information includes an enterprise identifier; S2: Receive a data access request, where the data access request includes the data identifier of the data to be accessed and the enterprise identifier of the requester; S3: Verify the enterprise identifier for the access request, and query the access control policy associated with the data identifier according to the data identifier; S4: Based on the queried access control policy, determine whether the enterprise requesting access has the access right to the data; S5: If it is determined that the enterprise has the access right, provide an access channel for the data, record the data access log, and associate the data access log with the data identifier.
[0006] A data element management method based on the industrial Internet identifier resolution system provided by this application realizes the binding of the data identifier and the data ownership information through the industrial Internet identifier resolution system. During the data access process, the access control policy is queried based on the data identifier for permission judgment and access control, and finally an access channel for the data is provided and the access log is recorded. This method can effectively manage data elements in the industrial machinery collaborative manufacturing ecosystem, solve the problems of unclear data ownership and access control requirements. Each step is closely linked to jointly realize the effective management and secure access control of data elements under the industrial Internet identifier resolution system. Therefore, the method provided by this application has the advantages of effectively realizing cross - supply - chain data traceability and authorized access control and ensuring data security under the premise of limited IT resources.
[0007] Further, step S1 includes: S11: Determine the data type of the data to be registered; S12: According to the data type, select the corresponding data identifier registration method; S13: According to the selected data identifier registration method, register the data identifier of the data in the industrial Internet identifier resolution system, and when registering, associate the data identifier with the data ownership information, where the data ownership information includes the owner enterprise identifier.
[0008] A data element management method based on the industrial Internet identifier resolution system provided by this application reflects the flexibility and intelligence of the solution by determining the data type of the data to be registered and selecting the corresponding data identifier registration method according to the data type; associating the data identifier with the data ownership information ensures the management and traceability of data ownership; through the above steps, the solution conducts refined processing for the data type, improves the efficiency of data registration and resource utilization rate, and is more adaptable to the management requirements of complex and diverse industrial data elements.
[0009] Further, in step S12, the data types include structured data and unstructured data; the data identifier registration methods include: Standard registration process, where the standard registration process includes: receiving data description information, verifying data format, and allocating standard data identifiers; Simplified registration process, where the simplified registration process includes: receiving data summary information and quickly allocating simplified data identifiers; Step S12 includes: S123: Real-time monitor the load status of the industrial Internet identification resolution system, and select the corresponding data identifier registration method according to the load status and the data type; Step S123 includes: S124: Compare the load status with a preset load threshold; S125: If the load status exceeds the preset load threshold, when the data type is structured data or the unstructured data, execute the simplified registration process; S126: If the load status does not exceed the preset load threshold, when the data type is structured data, execute the standard registration process; when the data type is unstructured data, execute the simplified registration process.
[0010] A data element management method based on the industrial Internet identification resolution system provided by this application. This technical solution increases the consideration of the load status of the industrial Internet identification resolution system and dynamically selects the data identifier registration method according to the load status. When the system is under low load, it ensures the quality of data registration; when the system is under high load, it ensures the efficiency of data registration, realizing the optimization of the performance of the data element management system.
[0011] Further, step S3 includes: S31: Preprocess the access control policy set and construct a policy index based on the data identifier pattern and the enterprise identifier pattern; S32: After receiving a data access request, query the policy index according to the data identifier included in the data access request and the enterprise identifier for which access is requested, and filter out the access control policies related to the data access request.
[0012] A data element management method based on the industrial Internet identification resolution system provided by this application, through pre-data organization and processing, establishes an efficient data structure for subsequent policy queries, reducing the time complexity of query operations. Querying through the policy index optimizes the policy query from a possible full-set search to an index lookup, significantly improving the query efficiency, reducing system resource consumption, and thus enhancing the response speed and processing capacity of the entire data element management method. This method effectively solves the problem of low access control policy query efficiency when the scale of the policy set is large, providing technical guarantee for quickly and efficiently performing data access permission verification.
[0013] Further, step S31 includes: S311: Monitor changes in the access control policy set, and identify policy changes such as newly added, modified, or deleted policies in the policy set; S312: For the identified policy changes, extract the changed data of the data identifier pattern and enterprise identifier pattern in the control policy set; S313: According to the changed data, perform incremental updates on the data identifier pattern index and enterprise identifier pattern index in the policy index, so that the policy index is synchronized with the updated control policy set.
[0014] Further, step S4 includes: S41: Based on the queried access control policy, evaluate whether there is a deny policy that matches the enterprise identifier and data identifier requested for access. If so, determine that the enterprise requesting access does not have the access right to the data; S42: If there is no deny policy that matches the enterprise identifier and data identifier requested for access, continue to evaluate whether there is an allow policy that matches the enterprise identifier and data identifier requested for access. If so, determine that the enterprise requesting access has the access right to the data; S43: If there is neither a deny policy that matches the enterprise identifier and data identifier requested for access nor an allow policy that matches the enterprise identifier and data identifier requested for access, determine that the enterprise requesting access does not have the access right to the data.
[0015] Further, step S43 includes: S431: When it is determined that the enterprise requesting access does not have the access right to the data, trigger the generation of a default deny access log; S432: Record the default deny access log, which includes: the data identifier of the data whose access is denied, the enterprise identifier requesting access, and the access request timestamp; S433: Store the default deny access log for security auditing and access control policy optimization.
[0016] Further, step S433 includes: S4331: Aggregate the default deny access logs from the storage medium. The aggregated default deny access logs are based on preset conditions, and the preset conditions include a time range and a data identifier category; S4332: Analyze the aggregated default deny access logs to detect abnormal access patterns, where the abnormal access patterns include repeated deny accesses from a specific enterprise identifier or repeated deny accesses for a specific data identifier; S4333: Based on the detected abnormal access patterns, generate suggestions for adjusting the access control policy, where the suggestions include modifying existing policies or adding new policies to address the identified abnormal access patterns.
[0017] Further, step S5 includes: S51: When it is determined that the enterprise requesting access has access rights, the system generates a time-limited temporary access token, which is associated with the current data access request and contains access channel information; S52: The system issues the generated temporary access token to the enterprise requesting access; S53: The enterprise requesting access uses the temporary access token to establish a data access channel with the data storage location to obtain the requested data; S54: While providing the data access channel, the system asynchronously records the data access log, which is associated with the data identifier and the temporary access token.
[0018] In a second aspect, a data element management device based on the industrial Internet identification resolution system, the device is applied to the steps of any of the above methods, and the device includes: Data registration module: In response to an enterprise's data registration request, register the data identifier of the data in the industrial Internet identification resolution system, and when registering, associate the data identifier with data ownership information, where the data ownership information includes an enterprise identifier; Request access module: Receive a data access request, where the data access request includes the data identifier of the data to be accessed and the enterprise identifier of the requesting access; Access verification module: Verify the enterprise identifier of the requesting access, and query the access control policy associated with the data identifier according to the data identifier; Permission judgment module: Based on the queried access control policy, judge whether the enterprise requesting access has access rights to the data; Data access module: If it is determined that there are access rights, provide an access channel for the data, record the data access log, and associate the data access log with the data identifier.
[0019] Beneficial effects: The data element management method and device based on the industrial Internet identification and resolution system proposed in this application realize the binding of data identifiers and data ownership information through the industrial Internet identification and resolution system. During the data access process, the access control policy is queried based on the data identifier, and permission judgment and access control are performed. Finally, a data access channel is provided and the access log is recorded. This method can effectively manage data elements in the industrial machinery collaborative manufacturing ecosystem, and solve the problems of unclear data ownership and the need for access control. Each step is closely linked, jointly realizing the effective management and secure access control of data elements under the industrial Internet identification and resolution system. Therefore, the method provided in this application has the advantages of effectively realizing cross-supply chain data traceability and authorized access control and ensuring data security under the premise of limited IT resources. Description of the Drawings
[0020] Figure 1 It is a flowchart of a data element management method based on the industrial Internet identification and resolution system proposed in this application.
[0021] Figure 2 It is a structural diagram of a data element management device based on the industrial Internet identification and resolution system proposed in this application.
[0022] Label description: 201, data registration module; 202, request access module; 203, access verification module; 204, permission judgment module; 205, data access module. Detailed Embodiments
[0023] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and marked in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0024] It should be noted that: Similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions, and cannot be understood as indicating or implying relative importance.
[0025] Under the premise of limited IT resources, small and medium-sized enterprises in the prior art effectively achieve cross-supply chain data traceability and authorized access control, and ensure data security. To solve this problem, the present application provides a data element management method and device based on the industrial Internet identification and resolution system, specifically: Please refer to Figure 1 , in the first aspect, a data element management method based on the industrial Internet identification and resolution system, which is applied to an industrial machinery collaborative manufacturing ecosystem. The ecosystem includes multiple enterprises participating in component production and product assembly. The method includes the following steps: S1: In response to a data registration request from an enterprise, register the data identifier of the data in the industrial Internet identification and resolution system, and when registering, associate the data identifier with the data ownership information, where the data ownership information includes the owner enterprise identifier; S2: Receive a data access request, where the data access request includes the data identifier of the data to be accessed and the enterprise identifier; S3: Verify the enterprise identifier of the requesting access, and query the data ownership information and access control policy associated with the data identifier according to the data identifier; S4: Based on the queried access control policy, determine whether the enterprise requesting access has the access right to the data; S5: If it is determined that there is an access right, provide an access channel for the data, record the data access log, and associate the data access log with the data identifier.
[0026] Among them, in step S1, when the data generating enterprise initiates a data registration request, the system is configured to create a data identifier in the industrial Internet identification and resolution system. The registration process of the data identifier may include assigning a unique code to the data, and this code follows the specifications of the industrial Internet identification and resolution system. When the data identifier is registered, the system establishes an association relationship between the data identifier and the data ownership information. The data ownership information can be stored in a database and includes the enterprise identifier, such as the unique ID of the enterprise.
[0027] In step S2, the reception of the data access request can be implemented through an API interface, and the API interface is configured to receive a request containing the data identifier and the enterprise identifier of the requesting access.
[0028] In step S3, the verification of the enterprise identifier can adopt technologies such as digital signature or two-way authentication to ensure the authenticity and reliability of the identity of the enterprise requesting access. The access control policy can be pre-configured and stored in the policy library, and the policies in the policy library are associated with the data identifier and the enterprise identifier. A policy index structure can be constructed to optimize the query efficiency.
[0029] In step S4, the logic for permission judgment can be based on a predefined rule set, such as access control list (ACL) or role-based access control (RBAC). The system evaluates whether the enterprise requesting access is in the permitted access list or meets the conditions defined in the access control policy.
[0030] In step S5, the provision of the access channel can include generating a temporary access link or access key that points to the data storage location. The data access log can include information such as access time, accessing enterprise, data access identifier, and access result. The data access log can be stored in a log database and associated with the data identifier to trace the access history of the data.
[0031] Specifically, in the industrial machinery collaborative manufacturing ecosystem, when a parts manufacturing enterprise generates a batch of new parts data, the enterprise first sends a data registration request to the industrial Internet identification resolution system. After receiving the request, the data registration module assigns a unique data identifier to this batch of parts data in the identification resolution system, such as "Part-XXX-Batch-20240726". When registering the data identifier, the data registration module associates the data identifier with the data ownership information, which contains the enterprise identifier of the parts manufacturing enterprise, such as "Enterprise-Part Manufacturer-001".
[0032] When the product assembly enterprise needs to access this batch of parts data, the product assembly enterprise sends a data access request to the system, which contains the data identifier "Part-XXX-Batch-20240726" and the enterprise identifier of the product assembly enterprise, such as "Enterprise-Product Assembler-002". After receiving the request, the access verification module first verifies the validity of the enterprise identifier of "Enterprise-Product Assembler-002". After passing the verification, the access verification module queries the data ownership information and access control policy associated with the data identifier "Part-XXX-Batch-20240726" according to the data identifier.
[0033] Suppose the queried access control policy stipulates that "Enterprise-Part Manufacturer-001" has full access rights to this data, and "Enterprise-Product Assembler-002" has read-only rights. The permission judgment module judges whether "Enterprise-Product Assembler-002" has access rights based on this information. Since the access control policy allows "Enterprise-Product Assembler-002" to perform read-only access to this data, the permission judgment module determines that it has access rights.
[0034] After determining that the access permission exists, the data access module provides an access channel for "Enterprise - Product Assembler - 002" to access this batch of component data, such as providing a data download link. At the same time, the data access module records a data access log, which contains information such as the access time, the accessing enterprise "Enterprise - Product Assembler - 002", and the access data identifier "Part - XXX - Batch - 20240726", and associates this log with the data identifier "Part - XXX - Batch - 20240726".
[0035] In some specific embodiments, the industrial Internet of Things identification and resolution system may adopt a distributed architecture. The registration and resolution services of data identifiers can be deployed on multiple nodes to improve the scalability and reliability of the system. The access control policy can be stored in a distributed database, such as a NoSQL database, to support high - concurrent access requests. The access control policy can adopt a fine - grained access control model, such as Attribute - Based Access Control (ABAC), to support more flexible and refined permission management. The data access channel can adopt a secure transmission protocol, such as HTTPS or TLS, to ensure the security of data during transmission. The data access log can be managed and analyzed using a centralized log management system for security auditing and anomaly detection. Through the above - mentioned embodiments, under the industrial Internet of Things identification and resolution system, the effective management and secure access control of data elements can be realized, and the requirements of unclear data ownership and secure data access in the industrial machinery collaborative manufacturing ecosystem can be solved.
[0036] Further, step S1 includes: S11: Determine the data type of the data to be registered; S12: Select the corresponding data identifier registration method according to the data type; S13: Register the data identifier of the data in the industrial Internet of Things identification and resolution system according to the selected data identifier registration method, and when registering, associate the data identifier with the data ownership information, where the data ownership information includes the owner enterprise identifier.
[0037] Among them, in step S11, the determination of the data type can be specified by the data - generating enterprise in the data registration request or automatically recognized by the system. For example, the system can determine whether the data type is structured data or unstructured data based on the format of the uploaded data, the file extension, or the characteristics of the data content. For structured data, such as a process parameter data table, it can be recognized as structured data; for unstructured data, such as a design drawing file of a component, it can be recognized as unstructured data.
[0038] In step S12, according to the determined data type, the system executes different selections of data identifier registration methods. When the data type is determined to be structured data, the system selects the standard registration process, which focuses on the standardization and integrity of data, including the detailed reception of data description information and the strict verification of data formats, and assigns standard data identifiers to ensure that structured data can be effectively managed and utilized. When the data type is determined to be unstructured data, the system selects the simplified registration process, which focuses on the efficiency and speed of registration, including the rapid reception of data summary information and the rapid assignment of simplified data identifiers to meet the rapidity requirements of unstructured data registration. In step S13, according to the registration method selected in step S12, the data identifier of the data is registered in the industrial Internet identification and resolution system. During the registration, the data identifier is associated with the data ownership information, which clarifies the ownership of the data and includes at least the enterprise identifier of the owner, providing a basis for subsequent data access control and management.
[0039] In some specific embodiments, assume that a parts manufacturing enterprise needs to register the process parameter data of the parts it produces and the 3D model drawings of the parts in the industrial Internet identification and resolution system. First, the system executes step S11 to identify that the process parameter data is structured data and the 3D model drawings are unstructured data. Then, the system executes step S12. For the process parameter data, it selects the standard registration process, requiring the enterprise to provide detailed data description information and perform data format verification, and assigns standard data identifiers; for the 3D model drawings, it selects the simplified registration process, only requiring the enterprise to provide data summary information and quickly assigns simplified data identifiers. Finally, the system executes step S13 to associate the standard data identifier of the process parameter data and the simplified data identifier of the 3D model drawings with the enterprise identifier of the parts manufacturing enterprise respectively to complete the data registration. In this way, different types of data can adopt appropriate registration processes according to their own characteristics, the system resources are optimized, and the data registration efficiency is improved.
[0040] Furthermore, in step S12, the data type includes structured data and unstructured data; the data identifier registration methods include: The standard registration process, which includes: receiving data description information, verifying data formats, and assigning standard data identifiers; The simplified registration process, which includes: receiving data summary information and quickly assigning simplified data identifiers; Step S12 includes: S123: Real-time monitor the load status of the industrial Internet identification and resolution system, and select the corresponding data identifier registration method according to the load status and data type; Step S123 includes: S124: Compare the load status with a preset load threshold; S125: If the load status exceeds the preset load threshold, when the data type is structured data or unstructured data, execute the simplified registration process; S126: If the load status does not exceed the preset load threshold, when the data type is structured data, execute the standard registration process; when the data is unstructured data, execute the simplified registration process.
[0041] Among them, the standard registration process can be: The system receives data description information from the data generation enterprise. The data description information includes detailed information such as data field types and data format requirements. The system then verifies whether the received data description information conforms to the preset data format standard. For example, it checks whether the data fields are complete and whether the data types are correct. After the data format verification passes, the system assigns a standard data identifier to the data. The standard data identifier has global uniqueness and resolvability and is used to uniquely identify the data in the industrial Internet identification and resolution system.
[0042] The simplified registration process can be: The system receives data summary information from the data generation enterprise. The data summary information is a brief description of the data, such as basic information such as data name and data source, without detailed data field type and format descriptions. The system quickly assigns a simplified data identifier to the data. The simplified data identifier also has uniqueness and resolvability, but may contain less data element information to achieve quick assignment.
[0043] In step S123, the real-time monitoring of the load status of the industrial Internet identification and resolution system can be performed by the monitoring module inside the system. The monitoring module periodically detects indicators such as the CPU utilization rate, memory usage rate, and network bandwidth occupancy rate of the system, and comprehensively evaluates the current load status of the system. The preset load threshold can be set according to system performance and actual operation experience. For example, the CPU utilization rate of 80% can be set as the load threshold.
[0044] In step S124, comparing the load status with the preset load threshold is to compare the real-time monitored load status value with the preset load threshold by the load monitoring module of the system to determine whether the current system load exceeds the threshold.
[0045] In step S125, if it is determined that the load status exceeds the load threshold, the system controls the data identifier registration process selection module to force the selection of the simplified registration process, and for all newly registered data, regardless of whether the data type is structured data or unstructured data, execute the simplified registration process.
[0046] In step S126, if it is determined that the load status does not exceed the load threshold, the system selects a registration process according to the data type of the data to be registered. If the data type is structured data, the standard registration process is selected; if the data type is unstructured data, the simplified registration process is selected.
[0047] Specifically, for the data registration link of the industrial Internet identification resolution system, first determine the data type of the data to be registered. The data type is divided into two types: structured data and unstructured data. The system monitors its own load status in real time, such as CPU utilization. The system presets a load threshold, such as 80%. When receiving a data registration request, the system first compares the current load status with the preset threshold. If the system load exceeds 80%, the system determines that it is in a high-load state. At this time, regardless of whether the data to be registered is structured data or unstructured data, the system selects to execute the simplified registration process. The simplified registration process receives the data summary information and quickly assigns a simplified data identifier, aiming to ensure the efficiency of data registration and the stability of the system first when the system is under high load. If the system load does not exceed 80%, the system determines that it is in a low-load state. At this time, the system selects a registration process according to the data type. For structured data, the system executes the standard registration process. The standard registration process receives detailed data description information, performs data format verification, and then assigns a standard data identifier, aiming to ensure the quality and integrity of structured data registration. For unstructured data, even in a low-load state, the system still selects to execute the simplified registration process and quickly assigns a simplified data identifier to give consideration to the efficiency of unstructured data registration. Thus, through the above process, the system can dynamically select an appropriate data identifier registration method according to its own load status and data type, optimize the data registration efficiency of the system under high load on the premise of ensuring the quality of data registration, and improve the overall performance of the system.
[0048] Further, step S3 includes: S31: Pre-process the access control policy set and construct a policy index based on the data identifier pattern and the enterprise identifier pattern; S32: After receiving a data access request, query the policy index according to the data identifier included in the data access request and the enterprise identifier for which access is requested, and filter out the access control policies related to the data access request.
[0049] In step S31, the policy index can be constructed by parsing each policy in the access control policy set according to the data identifier pattern and the enterprise identifier pattern, extracting the pattern features, and then building an index structure based on these pattern features. For example, data structures such as hash tables, tree structures, or inverted indexes can be used to organize the policy index to achieve fast lookup. In the implementation of the hash table, the data identifier pattern can be used as the primary key, the enterprise identifier pattern can be used as the secondary key, and the policy set can be stored as the value.
[0050] Further, step S31 includes: S311: Monitor changes in the access control policy set, and identify policy changes such as new, modified, or deleted policies in the policy set; S312: For the identified policy changes, extract the changed data of the data identifier pattern and the enterprise identifier pattern in the control policy set; S313: According to the changed data, perform incremental updates on the data identifier pattern index and the enterprise identifier pattern index in the policy index, so that the policy index is synchronized with the updated control policy set.
[0051] Among them, in step S311, the policy set change monitoring is implemented by continuously polling the policy set status or by subscribing to the policy change event notification mechanism. When it is detected that the policy set has changed, the system records the change type, such as adding a policy, modifying a policy, or deleting a policy.
[0052] In step S312, the changed data extraction process is designed to only focus on the data identifier pattern and the enterprise identifier pattern fields in the policy. For a new policy, extract the data identifier pattern and the enterprise identifier pattern of the new policy. For a modified policy, extract the data identifier pattern and the enterprise identifier pattern of the modified policy. For a deleted policy, extract the data identifier pattern and the enterprise identifier pattern of the deleted policy. Thus, it can be ensured that the index update operation is based on the most necessary data, reducing unnecessary data processing overhead.
[0053] In step S313, the incremental update is performed only on the part of the policy index affected by the changed data. For example, if a new policy is added, add the index entries corresponding to the data identifier pattern and the enterprise identifier pattern of the new policy in the policy index. If a policy is modified, update the data identifier pattern index and the enterprise identifier pattern index of the corresponding entry in the policy index. If a policy is deleted, remove the corresponding entry from the policy index.
[0054] As a preferred implementation, the index structure adopts a tree structure, such as a prefix tree or a suffix tree, to facilitate pattern matching and incremental updates. For example: Among them, in some preferred solutions, step S31 further includes: S314: Construct a data identifier prefix tree T_d and an enterprise identifier prefix tree T_u, where T_d and T_u are respectively used to store data identifiers and enterprise identifiers; S315: For each policy p in the access control policy set P, insert the data identifier of p into T_d to obtain the data identifier subset p_d in the access control policy, and insert the enterprise identifier of p into T_u to obtain the enterprise identifier subset p_u in the access control policy; S316: Define a similarity function similarity(x, y) for calculating the similarity between the data requested for access and the access control policy, and its value range is [0, 1]; S317: Set a data identifier similarity threshold threshold_d and an enterprise identifier similarity threshold threshold_u; S318: Define a policy matching function match(p, d, u), which returns true if and only if similarity(d, p_d)>threshold_d and similarity(u, p_u)>threshold_u; where d is the data identifier in the data requested for access, and u is the enterprise identifier in the data requested for access.
[0055] Specifically, in steps S313 to S314, after receiving a data access request, the system first monitors whether there is a change in the access control policy set. The monitoring can be achieved by regularly checking the version number of the policy set or listening to the change events published by the policy management module. If it is detected that the policy set has changed, the system identifies the specific change content, such as adding an access control policy for a specific data identifier pattern and enterprise identifier pattern. For the identified policy change, the system extracts the data identifier pattern and enterprise identifier pattern from the changed policy. For example, if a newly added policy is to allow enterprise A to access all data identifiers starting with "part -", the system extracts the data identifier pattern "part - *" and the enterprise identifier pattern "enterprise A". According to the extracted changed data, the system performs an incremental update on the pre - constructed policy index. The incremental update operation is specifically to add, modify, or delete the corresponding index nodes or entries in the data identifier pattern index and the enterprise identifier pattern index to reflect the latest access control policy. Through the incremental update, the policy index always remains synchronized with the latest access control policy set, ensuring the accuracy and real - time nature of subsequent policy queries.
[0056] In some specific embodiments, the incremental update process of the policy index is further optimized. For example, in the incremental update of the enterprise identifier pattern index, a multi-level index structure is adopted. The first-level index is organized according to the first letter or the first few characters of the enterprise identifier. Under each first-level index node, the second-level index stores the enterprise identifier patterns with the same prefix. When a new or modified enterprise identifier pattern is added, only the affected branches in the index structure need to be updated, without reconstructing the entire index, thereby improving the index update efficiency and reducing the system resource consumption.
[0057] In step S32, the process of querying the policy index is as follows: First, parse the data identifier and enterprise identifier included in the data access request, extract the data identifier pattern and enterprise identifier pattern of the requested access, and then use the extracted pattern features to search in the pre-constructed policy index, so as to quickly locate the access control policy set related to the current access request. The specific process of index query can include operations such as pattern matching, range search or keyword search to efficiently filter out the access control policies that meet the conditions. Thus, by pre-constructing the policy index, it is possible to avoid traversing the entire access control policy set for each data access request, thereby significantly improving the policy query efficiency.
[0058] Based on the above model, step S32 may include: S324: Receive a data access request, and extract the data identifier d and enterprise identifier u in the request; S325: Search for all prefixes related to d in T_d to obtain the subset P_d of data identifiers in the access control policy; search for all prefixes related to u in T_u to obtain the subset P_u of enterprise identifiers in the access control policy; S326: Calculate the intersection of P_d and P_u to obtain the relevant policy subset P_relevant; S327: Apply the match(p, d, u) function to each policy p in P_relevant to filter out the final matching policy set.
[0059] Through the construction of the prefix tree, this model provides an efficient policy index structure, greatly improving the query speed; through the setting of the similarity function and similarity threshold, it realizes the function of flexibly adjusting the matching accuracy; through the policy matching function, it ensures accurate policy screening; through search and intersection calculation, it can quickly locate potential relevant policies, and through the final screening, it ensures the accuracy of the matching policy set.
[0060] Furthermore, step S4 includes: S41: Based on the retrieved access control policies, evaluate whether there is a denial policy that matches the enterprise identifier of the access request and the data identifier of the requested access. If there is, it is determined that the enterprise requesting access does not have the access right to the data. S42: If there is no denial policy that matches the enterprise identifier of the access request and the data identifier of the requested access, continue to evaluate whether there is an approval policy that matches the enterprise identifier of the access request and the data identifier of the requested access. If there is, it is determined that the enterprise requesting access has the access right to the data. S43: If there is neither a denial policy that matches the enterprise identifier of the access request and the data identifier of the requested access nor an approval policy that matches them, it is determined that the enterprise requesting access does not have the access right to the data.
[0061] Among them, in step S41, after the system receives a data access request, it first retrieves the preset access control policy set and checks whether there is a denial policy in the policy set. A denial policy refers to a policy that clearly prohibits a specific enterprise from accessing specific data. The policy matching process is specifically as follows: compare the enterprise identifier of the access request with the enterprise identifier set in the denial policy, and at the same time compare the data identifier of the access request with the data identifier set in the denial policy. If a denial policy is found whose enterprise identifier and data identifier are both consistent with the information in the access request, the system immediately determines that the enterprise requesting access does not have the access right, and the access process terminates.
[0062] In step S42, if no matching denial policy is found in step S41, the system will continue to search for an approval policy in the access control policy set. An approval policy refers to a policy that clearly allows a specific enterprise to access specific data. The policy matching process is similar to that in step S41. The system compares the enterprise identifier of the access request with the enterprise identifier set in the approval policy and compares the data identifier of the access request with the data identifier set in the approval policy. If an approval policy is found whose enterprise identifier and data identifier are both consistent with the access request information, the system determines that the enterprise requesting access has the access right and allows data access.
[0063] In step S43, if neither a denial policy that matches the access request nor an approval policy that matches it is found in the policy set, that is, the policy set does not make a clear stipulation for this access request, the system will handle it according to the default denial principle. At this time, the system determines that the enterprise requesting access does not have the access right and rejects the data access request.
[0064] In some specific embodiments, the access control policy is stored in the form of a rule list, and each rule includes a policy type (permit / deny), an enterprise identifier pattern, and a data identifier pattern. When a data access request is received, the system traverses the rule list. First, the system checks whether there is a rule with a policy type of deny, an enterprise identifier pattern that matches the enterprise identifier of the requested access, and a data identifier pattern that matches the data identifier of the requested access. If a matching deny rule is found, the system immediately returns a deny access result. If no matching deny rule is found, the system continues to traverse the rule list to find a rule with a policy type of permit, an enterprise identifier pattern that matches the enterprise identifier of the requested access, and a data identifier pattern that matches the data identifier of the requested access. If a matching permit rule is found, the system returns a permit access result. If the entire rule list is traversed and neither a matching deny rule nor a matching permit rule is found, a deny access result is returned according to the default deny principle.
[0065] Further, step S43 includes: S431: When it is determined that the enterprise requesting access does not have access rights to the data, trigger the generation of a default deny access log; S432: Record the default deny access log, which includes the data identifier of the data whose access is denied, the enterprise identifier of the requesting access, and the access request timestamp; S433: Store the default deny access log for security auditing and access control policy optimization.
[0066] Among them, for the default deny access log recording mechanism, in the access permission determination phase, when the access request does not conform to either the permit policy or the deny policy, the system performs a default deny operation.
[0067] Thus, step S431 is triggered, and the default deny access log generation process is started to ensure that all default deny access events are recorded. The content of the default deny access log includes the data identifier, the enterprise identifier, and the access request timestamp, providing a data basis for subsequent analysis.
[0068] In step S433, storing the default deny access log aims to support security auditing and access control policy optimization. Through log recording and analysis, the system can detect potential abnormal access patterns. For example, frequent default deny access may indicate policy configuration problems or potential unauthorized access attempts. Based on these logs, the access control policy can be adjusted and optimized, improving the system security and management efficiency.
[0069] Specifically, in the industrial Internet of Things identification and resolution system, when an enterprise initiates a data access request, the system first verifies the enterprise identity and the data requested for access. In the access permission judgment step, the system queries the preset access control policy. The policy matching process is executed to determine whether there is an allow or deny policy that matches the current access request. If neither a policy allowing the current access nor a policy explicitly denying the current access is found in the policy library, the system will reject this access request according to the default configuration. To enhance the auditability and security of the system, a default deny access logging mechanism is introduced. When a default deny occurs, the system automatically generates a log record that details the data identifier of the denied access, the enterprise identifier that initiated the access request, and the specific time of the access request. These log messages are uniformly stored in the log database, and security administrators can regularly analyze these logs to identify potential security risks. For example, a large number of default deny access logs from a specific enterprise within a short period may indicate abnormal access behavior of that enterprise or an oversight in the access control policy configuration. By analyzing the default deny access logs, managers can timely adjust and optimize the access control policy. For example, new allow or deny policies can be added, or the applicable scope of existing policies can be modified, thereby enhancing the data security protection ability and the refinement degree of access control.
[0070] In some specific embodiments, the storage medium of the default deny access logs can be a high-security distributed log storage system, such as Hadoop HDFS or cloud log services. The log data is organized and indexed using a time series database to optimize query efficiency. The log record format uses a structured data format, such as JSON, for convenient subsequent data analysis and processing. The access request timestamp accuracy reaches the millisecond level to accurately record the time when the access event occurs. The log analysis module is configured to regularly scan the default deny access logs and match them using preset abnormal access pattern rules. For example, the rule can be set as "more than 10 default deny accesses occur for a single enterprise identifier within 10 minutes". Once an abnormal pattern is matched, the system automatically triggers an alarm to notify the security administrator for manual review and handling. A policy optimization suggestion generation module is added. Based on the log analysis results, the system can give policy adjustment suggestions, such as "it is recommended to add a deny policy for enterprise identifier XXX for data identifier category YYY", to assist managers in optimizing the policy.
[0071] Further, step S433 includes: S4331: Aggregate the default deny access logs from the storage medium. The aggregated default deny access logs are based on preset conditions, and the preset conditions include a time range and a data identifier category; S4332: Analyze the aggregated default deny access logs to detect abnormal access patterns, where the abnormal access patterns include repeated deny accesses from a specific enterprise identifier or repeated deny accesses to a specific data identifier; S4333: Based on the detected abnormal access patterns, generate suggestions for adjusting the access control policy, where the suggestions include modifying existing policies or adding new policies to address the identified abnormal access patterns.
[0072] Among them, for step S4331, perform the aggregation operation on the default deny access logs. The aggregation process can be implemented based on preset conditions, where the preset conditions include a time range and a data identifier category. The setting of the time range enables the system to analyze the logs within a specific time period. For example, analyze the deny access records in the most recent week to promptly discover abnormal access behaviors that have occurred recently. The setting of the data identifier category enables the centralized aggregation of the deny access logs for specific types of data. For example, aggregate all the deny access logs regarding product design drawings to specifically analyze whether the access control policy for such data is reasonable and effective. As a possible implementation method, the system can use database query statements to retrieve the log records that meet the time range and data identifier category conditions from the log storage table and summarize the retrieval results to provide a data basis for subsequent analysis steps.
[0073] For step S4332, analyze the aggregated default deny access logs with the aim of detecting abnormal access patterns. The abnormal access patterns include repeated deny accesses from a specific enterprise identifier or repeated deny accesses to a specific data identifier. Specifically, the system can count the number of times each enterprise identifier is denied access and the number of times each data identifier is denied access in the aggregated logs. If a certain enterprise identifier is frequently denied access within a short period of time, or a certain data identifier is frequently denied access, it is determined as an abnormal access pattern. For example, if enterprise A is denied access to various data resources more than 10 times within one hour, or the data identifier "drawing of part XXX" is denied access more than 50 times within one day, the system can determine that there is an abnormal access pattern. The detection result of the abnormal access pattern provides a clear indication for subsequent policy adjustment.
[0074] Regarding step S4333, based on the abnormal access pattern detected in step S4332, generate suggestions for adjusting the access control policy. The policy adjustment suggestions include modifying the existing policy or adding new policies to address the identified abnormal patterns. For example, if repeated access denials from enterprise B are detected, the system can generate a suggestion to prompt the administrator to check the access permission configuration of enterprise B or add a specific access policy for enterprise B. Another example is that if repeated access denials for the data identifier "core process parameters" are detected, the system can generate a suggestion to prompt the administrator to evaluate whether the current access control policy for "core process parameters" is too strict or whether new allowable access policies need to be added to meet reasonable access requirements. The generation of policy adjustment suggestions provides intelligent support for the optimization of the access control policy.
[0075] Furthermore, step S5 includes: S51: When it is determined that the enterprise requesting access has access rights, the system generates a time-limited temporary access token, which is associated with the current data access request and contains access channel information; S52: The system issues the generated temporary access token to the enterprise requesting access; S53: The enterprise requesting access uses the temporary access token to establish a data access channel to the data storage location to obtain the requested data; S54: While providing the data access channel, the system asynchronously records the data access log, which is associated with the data identifier and the temporary access token.
[0076] Among them, in step S51, regarding the security and manageability issues of the access channel, a temporary access token mechanism is introduced. In step S52, after the permission verification passes, the system does not directly provide a permanent or long-term valid access channel, but generates a time-limited temporary access token. This token is equivalent to a temporary "pass", which is only valid within a limited time and is bound to a specific data access request. The token contains the information required to establish the access channel, such as the data storage location, access key, etc. The system sends this temporary token to the enterprise requesting access, and the enterprise must use this token to establish a data access channel.
[0077] Since the access token is temporary, even if the token is leaked, its valid time is limited, greatly reducing the security risk. Compared with long-term valid access credentials, temporary tokens can effectively prevent unauthorized long-term access.
[0078] In step S53, the temporary access token is associated with each data access request, and the access log is also associated with this token. This means that each data access behavior can be traced back to a specific token, and further to the enterprise that requested the access and the specific data access event, providing convenience for security auditing and problem troubleshooting.
[0079] Through the temporary token, the system can manage the access channel more finely. For example, the validity period of the token, the scope of access permissions, etc. can be controlled. Each access requires a new application for the token, which enables the data owner to better grasp the usage of the data and adjust the access policy as needed.
[0080] In step S54, while providing the data access channel, the access log is recorded asynchronously. This means that the log recording process does not block the establishment of the data access channel and data transmission, improving the system's response speed and overall performance. Especially in high-concurrency access scenarios, this asynchronous processing method can significantly enhance the user experience.
[0081] Please refer to Figure 2 , a data element management device based on the industrial Internet identification and resolution system. The device is applied to the steps of any of the above methods. The device includes: Data registration module 201: In response to the enterprise's data registration request, register the data identifier of the data in the industrial Internet identification and resolution system, and when registering, associate the data identifier with the data ownership information, where the data ownership information includes the enterprise identifier; Request access module 202: Receive a data access request, where the data access request includes the data identifier of the data to be accessed and the enterprise identifier of the requesting access enterprise; Access verification module 203: Verify the enterprise identifier of the requesting access, and query the access control policy associated with the data identifier according to the data identifier; Permission judgment module 204: Based on the queried access control policy, judge whether the enterprise requesting access has the access permission for the data; Data access module 205: If it is determined that there is access permission, provide an access channel for the data, record the data access log, and associate the data access log with the data identifier.
[0082] Among them, the data registration module 201, the request access module 202, the access verification module 203, the permission judgment module 204, and the data access module 205 are integrated in the data element management device to work together.
[0083] The data registration module 201 and the request access module 202 serve as the input ends of the device, respectively receiving the enterprise's data registration request and the data access request from the data access enterprise.
[0084] The access verification module 203 and the permission judgment module 204, as the core processing units of the device, execute the key logic of access control and permission management.
[0085] The data access module 205, as the output end of the device, is responsible for providing a data access channel and recording access logs in the case of authorized access, so as to achieve the traceability of data access. The data flow and control coordination between each module are coordinated and managed by the control unit inside the device, and the control unit can be implemented by hardware such as a central processing unit or a programmable logic controller and corresponding software programs.
[0086] The data registration module 201 is configured to interact with the industrial Internet identification resolution system, the request access module 202 is configured to receive access requests from enterprise clients, and the data access module 205 is configured to establish a connection with the data storage system to provide a data access channel. The access verification module 203 and the permission judgment module 204 need to access the access policy storage and the ownership information database to complete the verification and judgment operations. Thus, the collaborative work of the above modules realizes the data element management function of the data element management device under the industrial Internet identification resolution system.
[0087] Specifically, in the industrial Internet identification resolution system, the working principle of the data element management device is as follows: First, the data generation enterprise registers the data it produces with the system through the data registration module 201. During the registration process, the data registration module 201 not only assigns a unique data identifier to the data, but also associates this identifier with the data ownership information, and the ownership information clarifies the enterprise to which the data belongs. When other enterprises need to access this data, they send a data access request to the device through the request access module 202, and the request contains the data identifier to be accessed and the enterprise identifier of the requestor. After receiving the request, the access verification module 203 first verifies the identity of the enterprise requesting access, and then queries the access control policy associated with the data according to the data identifier. The permission judgment module 204 conducts a permission evaluation based on the queried ownership information and access control policy to judge whether the enterprise requesting access is authorized to access the data. If the permission judgment module 204 determines that the enterprise requesting access has access permission, the data access module 205 will provide a secure data access channel for the enterprise to allow it to obtain the required data, and at the same time of data access, the data access module 205 will also record detailed data access logs and associate the logs with the data identifier for subsequent data traceability and security auditing. Through the collaborative operation of the above modules, the data element management device realizes the effective management and utilization of data elements in the industrial Internet environment on the premise of ensuring data security.
[0088] In some specific embodiments, the data registration module 201 may be a Web application with a graphical user interface. Enterprise users can fill out a data registration form through this program. The form includes fields such as data type, data description, and owner enterprise identifier. When the user submits a registration request, the Web application encapsulates the request data into a data packet that conforms to the interface specification of the industrial Internet identifier resolution system and sends it to the identifier resolution system for data identifier registration and ownership information association.
[0089] The request access module 202 may be an API interface that provides data access services externally and receives access requests from authorized enterprise IT systems.
[0090] The access verification module 203 and the permission judgment module 204 can be deployed in a secure server environment, use a high-performance database to store access control policies and ownership information, and adopt an efficient policy matching algorithm to ensure the real-time performance and accuracy of access verification and permission judgment.
[0091] The data access module 205 can adopt lightweight message queue technology to asynchronously record data access logs and store the log information in a distributed log system to support the efficient storage and retrieval of massive access logs.
[0092] The above are only embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data element management method based on the industrial Internet identification resolution system, characterized in that: The method is applied to an industrial machinery collaborative manufacturing ecosystem, the ecosystem including multiple companies involved in parts production and product assembly, and includes the following steps: S1: In response to a data registration request from an enterprise, register a data identifier of the data in the industrial Internet identity resolution system, and when registering, associate the data identifier with data ownership information, wherein the data ownership information includes an enterprise identifier; S2: receiving a data access request, wherein the data access request includes a data identifier of the data requested for access and an identification of the enterprise requested for access; S3: verifying the enterprise identity of the access request, and querying the access control policy associated with the data identifier according to the data identifier; S4: Based on the queried access control policy, determine whether the enterprise requesting access has access rights to the data; S5: If it is determined that the access right is granted, an access channel to the data is provided, a data access log is recorded, and the data access log is associated with the data identifier.
2. According to claim 1, a data element management method based on the industrial Internet identification resolution system is characterized in that: Step S1 includes: S11: Determine the data type of the data to be registered; S12: Selecting a corresponding data identifier registration method according to the data type; S13: According to the selected data identifier registration method, register the data identifier of the data in the Industrial Internet identity resolution system, and when registering, associate the data identifier with the data ownership information, wherein the data ownership information includes the owner's enterprise identifier.
3. According to claim 2, a data element management method based on the industrial Internet identification resolution system is characterized in that: In step S12, the data types include structured data and unstructured data; The data identifier registration method includes: A standard registration process, wherein the standard registration process includes: receiving data description information, verifying data format, and allocating a standard data identifier; Simplifying the registration process, the simplified registration process comprising: receiving data summary information and quickly allocating a simplified data identifier; Step S12 includes: S123: monitor the load status of the industrial Internet identity resolution system in real time, and select a corresponding data identifier registration method according to the load status and the data type; Step S123 includes: S124: comparing the load state with a preset load threshold; S125: If the load state exceeds the preset load threshold, a simplified registration process is performed when the data type is structured data or unstructured data; S126: If the load status does not exceed the preset load threshold, when the data type is structured data, a standard registration process is executed; when the data type is unstructured data, a simplified registration process is executed.
4. According to a data element management method based on the industrial Internet identification resolution system according to claim 1, it is characterized in that: Step S3 includes: S31: pre-processing the access control policy set and constructing a policy index based on the data identifier pattern and the enterprise identifier pattern; S32: After receiving the data access request, query the policy index according to the data identifier and the enterprise identifier of the access request included in the data access request, and filter out the access control policy related to the data access request.
5. According to claim 4, a data element management method based on the industrial Internet identification resolution system is characterized in that: Step S31 includes: S311: monitor changes in the access control policy set and identify policy changes that are added, modified, or deleted in the policy set; S312: extracting change data of the data identifier pattern and the enterprise identifier pattern in the access control policy set for the identified policy change; S313: Perform incremental updates on the data identifier pattern index and the enterprise identifier pattern index in the policy index according to the changed data, so as to synchronize the policy index with the updated access control policy set.
6. According to a data element management method based on the industrial Internet identification resolution system according to claim 1, it is characterized in that: Step S4 includes: S41: Based on the queried access control policy, evaluating whether there is a rejection policy that matches the enterprise identifier of the access request and the data identifier of the access request; if so, determining that the access requesting enterprise does not have access rights to the data; S42: If there is no deny policy that matches the enterprise identifier of the access request and the data identifier of the access request, continue to evaluate whether there is a permit policy that matches the enterprise identifier of the access request and the data identifier of the access request; if so, determine that the enterprise requesting access has access rights to the data; S43: If there is neither a deny policy that matches the enterprise identifier of the requested access and the data identifier of the requested access, nor an allow policy that matches the enterprise identifier of the requested access and the data identifier of the requested access, it is determined that the enterprise requesting access does not have access rights to the data.
7. A data element management method based on the industrial Internet identification resolution system according to claim 6, characterized in that: Step S43 includes: S431: When it is determined that the enterprise requesting access does not have access rights to the data, triggering generation of a default access denial log; S432: Record a default access denial log, wherein the default access denial log includes: a data identifier of the data denied access, an enterprise identifier requesting access, and an access request timestamp; S433: Storing the default access denial log for security auditing and access control policy optimization.
8. The data element management method based on the industrial Internet identification resolution system according to claim 7 is characterized in that: Step S433 includes: S4331: Aggregate the default access denied log from the storage medium, where the aggregated default access denied log is based on a preset condition, where the preset condition includes a time range and a data identifier category; S4332: Analyze the aggregated default denied access log to detect abnormal access patterns, wherein the abnormal access patterns include repeated access denials from a specific enterprise identity or repeated access denials for a specific data identifier; S4333: Based on the detected abnormal access pattern, generate a suggestion for adjusting the access control policy, wherein the suggestion includes modifying an existing policy or adding a new policy to resolve the identified abnormal access pattern.
9. The data element management method based on the industrial Internet identification resolution system according to claim 1 is characterized in that: Step S5 includes: S51: When it is determined that the enterprise requesting access has access rights, the system generates a temporary access token with time validity, which is associated with this data access request and includes access channel information; S52: The system sends the generated temporary access token to the enterprise requesting access; S53: The enterprise requesting access uses the temporary access token to establish a data access channel with the data storage location to obtain the data requested for access; S54: While providing the data access channel, the system asynchronously records a data access log, wherein the data access log is associated with the data identifier and the temporary access token.
10. A data element management device based on the industrial Internet identification resolution system, characterized in that: The device is applied to the steps of any one of the methods in claims 1 to 9, and the device comprises: Data registration module: in response to a data registration request from a data generating enterprise, registers a data identifier of the data in the industrial Internet identification resolution system, and during registration, associates the data identifier with data ownership information, wherein the data ownership information includes an enterprise identification; Access request module: receiving a data access request, wherein the data access request includes a data identifier of the data requested for access and an identification of the enterprise requested for access; Access verification module: verifying the enterprise identity of the access request, and querying the access control policy associated with the data identifier according to the data identifier; Permission judgment module: based on the queried access control policy, judge whether the enterprise requesting access has the access rights to the data; Data access module: if it is determined that the data has access rights, an access channel to the data is provided, a data access log is recorded, and the data access log is associated with the data identifier.
Citation Information
Cited By
A method and system for identity resolution and data rights linkage
CN122824411A