Multi-level refined public data resource authorization control method based on authorization protocol

By using a multi-level authorization agreement framework and dynamic management and control mechanism, the problems of insufficient authorization granularity and lagging security control in public data authorization are solved, realizing refined data authorization and security compliance, and reducing the risk of data leakage.

CN121682874AActive Publication Date: 2026-03-17YUNNAN PROVINCIAL BIG DATA CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202610195913.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-03-17
Estimated Expiration
2046-02-11

AI Technical Summary

Technical Problem

Existing public data authorization technologies suffer from insufficient authorization granularity, lack of scenario-based adaptation, and lagging security controls, resulting in high data leakage risks, high compliance costs, and insufficient market impetus.

Method used

A multi-level, refined public data resource authorization control method based on authorization protocols is adopted. Through a multi-level protocol framework, the scope of authorized data is locked to specific scenarios, time periods, objects, and data items. Dynamic management and control are achieved by combining a negative list, a policy execution engine, and scenario identification codes.

Benefits of technology

It enables refined data authorization, reduces the risk of sensitive data leakage, ensures compliance, avoids data supply beyond the scope and development period exceeding the limit, and improves the accuracy and security of data resource management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121682874A_ABST
    Figure CN121682874A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-level refined public data resource authorization control method based on an authorization protocol, and belongs to the technical field of public data resource authorization operation. The method comprises the following steps: synchronizing a public data resource directory to an authorized operation platform from a public data platform at regular time; adding an unauthorized data resource directory application of the department into a negative list; the implementation mechanism carries out authorized operation protocol filing on the authorized operation platform; the operation mechanism creates an application scene on the authorized operation platform; performing development protocol filing on the authorized operation platform; the operation mechanism carries out fine authorization on the primarily-processed data products again, specific data item fields given to the corresponding development mechanism by each primarily-processed data product based on the application scene are determined, and parameters are returned; the authorization range is further controlled; according to the method, refined data authorization can be realized, and a traditional extensive mode of full-library development and whole-table transfer is broken through.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a multi-level refined public data resource authorization control method based on authorization agreements, belonging to the field of public data resource authorization operation technology. Background Technology

[0002] Public data licensing and operation refers to the process by which governments or public institutions authorize specific operating entities (such as enterprises or social organizations) to process and develop data resources into data products or services, thereby realizing the value of data elements. The current mainstream technical architecture and its existing shortcomings are as follows:

[0003] 1. Overview of existing technologies:

[0004] The licensing model is too broad: existing platforms mainly stipulate the scope and duration of data use through a single-level licensing agreement (such as a framework agreement between the government and the operating agency). For example, it may only stipulate that "a certain type of database can be accessed" or "the development of products in a specific field is allowed", which lacks detailed constraints on the data use scenarios, processing levels and data items.

[0005] Technical limitations: Existing platforms, such as the "Technical Requirements for Public Data Authorization and Operation Platforms" (T / CECC 024-2023), define the authorization architecture, but the authorization control unit only operates at the dataset level, unable to be refined to the data item level (such as a single field) or dynamically sampled by scenario. Security control relies on post-event auditing rather than embedding minimal authorization rules at each stage of data flow.

[0006] Insufficient regulatory mechanisms: Most systems adopt the "full access after authorization" model, which allows operating institutions to obtain all data at once, resulting in a high risk of data being used beyond its scope; at the same time, the data access permissions of development institutions are allocated independently by the operating institutions, and the government cannot directly intervene in its granular control.

[0007] 2. Existing technical problems and their causes:

[0008] Issue 1: Insufficient granularity of authorization makes it difficult to balance security and exploitation.

[0009] Public data often contains sensitive information such as personal privacy and public safety, and the current extensive authorization system is prone to data leakage or misuse. At its root, the lack of a technical framework of "layered protocol + dynamic constraints" makes it impossible to converge the scope of data from the resource layer (overall dataset) to the scenario layer (specific data items).

[0010] Question 2: Lack of scenario-based adaptation, making it difficult to implement the minimization principle:

[0011] The data requirements of development institutions vary significantly across different scenarios (e.g., medical analysis requires gender and age, while financial risk control requires credit records). However, existing technologies do not strongly bind authorization to application scenarios, leading to an oversupply of data. For example, initially processed data products (such as anonymized statistical tables) are still transferred as a whole during secondary authorization, making it impossible to remove irrelevant data items as needed.

[0012] Question 3: Lagging safety controls and lack of pre-emptive prevention mechanisms:

[0013] Existing platforms rely on post-event log auditing, but lack a sample data sampling mechanism during the development phase, making it impossible to verify the necessity of data in the pre-development stage. Furthermore, authorization status monitoring focuses primarily on process compliance rather than the dynamic control of the data content itself.

[0014] 3. Consequences of the problem:

[0015] The aforementioned deficiencies have led to increased security risks (such as data being copied and disseminated beyond its scope), high compliance costs (requiring manual verification of data usage), and insufficient market impetus (development institutions avoid high-value data due to security concerns), which seriously restricts the release of the value of data elements.

[0016] In response to the three major shortcomings mentioned in the background art—insufficient authorization granularity, lack of scenario-based adaptation, and lagging security control—this invention provides a multi-level, refined public data resource authorization control method based on authorization protocols. Summary of the Invention

[0017] In response to the three major shortcomings mentioned in the background technology—insufficient authorization granularity, lack of scenario-based adaptation, and lagging security control—this invention provides a multi-level refined public data resource authorization control method based on authorization protocols. This invention can achieve refined data authorization, breaking through the traditional extensive mode of full database development and whole table transfer.

[0018] The technical solution of this invention is: a multi-level refined public data resource authorization control method based on an authorization protocol, the method comprising:

[0019] Step S1: Periodically synchronize the public data resource catalog from the public data platform to the authorized operation platform;

[0020] Step S2: The data source department applies to add the catalog of data resources that cannot be authorized by the department to the negative list on the authorized operation platform. Data resources added to the negative list cannot be authorized.

[0021] Step S3: The implementing agency files the authorization operation agreement on the authorized operation platform; the authorization operation agreement shall clearly specify the authorized operation agency, the scope of authorized data, the authorization period, and the authorization model.

[0022] Step S4: The operating organization creates an application scenario on the authorized operation platform, applies for data resource authorization based on the authorized data scope stipulated in the authorized operation agreement in step S3, and develops and generates preliminary data products. The usage period is the authorization period stipulated in the authorized operation agreement in step S3.

[0023] Step S5: After selecting a development agency based on the application scenario, the operating agency shall file a development agreement on the authorized operation platform. The development agreement shall clearly specify the authorized development agency, the authorized application scenario, the authorization period, and the authorized initial data products. The authorization period for the development agency shall not exceed the authorization period for the original data resources in the authorized operation agreement in step S3.

[0024] Step S6: The operating organization further refines the authorization of the initial processed data products, clarifying the specific data items, fields, and return parameters to be given to the corresponding development organization for each initial processed data product based on the application scenario; and further controlling the scope of authorization.

[0025] Further, step S1 includes:

[0026] Step S11: Establish a public data resource catalog synchronization mechanism:

[0027] The public data platform deploys a scheduled task scheduler, which triggers the directory synchronization engine to perform the following operations at a specified time each day: (1) Call the GET / metadata interface opened by the public data platform to obtain the full public data resource directory and status identifier; (2) Persist the directory data to the local authorized directory database, with fields including resource_id, resource_name, status, and last_sync_time; (3) Mark the delisted resources as status=INACTIVE and the newly added resources as status=ACTIVE.

[0028] Step S12: Implement strong linkage between directory status and authorization process through the policy execution engine;

[0029] Step S13: Execute the reverse control process:

[0030] When the public data platform initiates a resource removal operation, it pre-calls the resource usage query interface of the authorized operation platform; (1) If authorized_count>0 is returned, the removal is blocked and the error code ERR_DEPRECATE_BLOCKED is returned, and an alternative solution application work order is generated at the same time; (2) If authorized_count=0 is returned, the removal is allowed immediately.

[0031] Further, step S2 includes:

[0032] Step S21: Use the audit workflow engine to drive the automated process of application-audit-execution; based on BPMN2.0 standard modeling, integrate electronic signature to verify the identity of the auditor, and store audit records on the blockchain to carry out the process of application to be added to the negative list-audit-approval-successful addition to the negative list;

[0033] Step S22: Use a state synchronizer to link the negative list and authorization policy in real time; use a publish-subscribe pattern to push a ResourceStatusChangeEvent to the policy execution engine when the negative list is updated, so as to achieve dynamic updates of the negative list.

[0034] Specifically, the BLOCKED / ACTIVE status flags enable atomic switching of resources between the negative list and the licenable pool; status changes trigger real-time hot updates of the policy execution engine to avoid the downtime maintenance required by traditional solutions.

[0035] Step S23: Use the strategy execution engine to dynamically manage authorization behavior based on the negative list, and add verification rules in the agreement creation / data application stage to achieve the effect of not being able to use the data catalog resources in the negative list.

[0036] Further, step S3 includes:

[0037] Step S31: The implementing agency creates and files an authorization operation agreement through the agreement management module of the authorization operation platform. This authorization operation agreement includes the following constraint fields:

[0038] Authorization Entity Binding Field: Specifies the identifier of the authorized operating organization;

[0039] Data range whitelist field: Defines the set of data resources that can be authorized;

[0040] Time-limited control field: Sets the authorization validity period;

[0041] Authorization pattern identifier field: declares the rules for data usage;

[0042] Step S32: After the authorized operation agreement is filed, the policy execution engine of the authorized operation platform automatically performs the following dynamic control:

[0043] (1) Application scope constraint: When the operating institution initiates a resource request through the data application interface of the authorized operation platform, the system calls the data scope whitelist field in the authorized operation agreement in real time to forcibly limit the range of optional data resources, so that it can only select the datasets in the whitelist;

[0044] (2) Authorization time limit interception mechanism: When the policy execution engine receives the application request, it automatically verifies the matching of the current timestamp with the time limit control field in the protocol: if the application time is within the validity period, the application is allowed to be submitted; if the validity period is exceeded, the protocol expiration interceptor is triggered, an error code is returned and the process is terminated.

[0045] Further, step S4 includes:

[0046] Step S41, Application Scenario Creation and Protocol Resource Loading: The operating organization creates an application scenario on the authorized operation platform, and the system automatically generates a globally unique scene identifier code Scene_ID; the system automatically loads the authorized data range specified in the authorized operation agreement signed with the operating organization through the protocol parsing engine, and performs real-time filtering at the same time;

[0047] Step S42: Request for protocol resource authorization based on scene identifier:

[0048] The operating organization selects the data resources to be applied for within the authorized data scope specified in the authorized operation agreement. When submitting the application, the system automatically generates a structured application document and triggers a multi-level review workflow engine. Based on the applied data resources identified in the current scenario, the system performs the following technical controls:

[0049] Resource application scenario binding: The application form automatically embeds the hidden field Scene_ID, which is verified by the backend through a request interceptor; when the applied resource has been authorized based on a certain scenario and needs to be used in a new scenario, the application review process also needs to be triggered, and manual review is carried out again based on the new application scenario to prevent the abuse of data resources;

[0050] Step S43, Injecting Authorized Resources into the Data Development Platform: After both levels of review are approved, the system performs the following automated operations: (1) Dynamic Credential Generation: Create a time-sensitive access token for each authorized resource, with the validity period bound to the protocol expiration time; (2) Sandbox Resource Mounting: Mount the authorized resource to the independent container sandbox of the data development platform in the form of an encrypted volume; (3) Lifecycle Timer Startup: Register a resource recycling task in the scheduled task service, with the trigger time being the protocol expiration time;

[0051] Step S44: Data product generation in the development environment: Within the container sandbox of the data development platform, the operating organization accesses authorized resources through the secure computing engine and uses SQL / Spark tools to generate preliminary data products. Data lineage tags are automatically attached when the preliminary data products are output.

[0052] Step S45, Lifecycle Expiration Warning:

[0053] Thirty days before the agreement expires, the system automatically triggers an early warning mechanism: sending system message notifications and SMS reminders to the operating organization through the message distribution service;

[0054] Step S46, Automatic Resource Recycling: When the agreement expires, the system performs an atomic recycling operation; unloads the sandbox resource volume, freezes intermediate data products, recycles the temporary Fanwei token, and updates the authorization state machine;

[0055] Step S47, Post-recycling audit trail: The system generates a resource recycling audit report and archives it automatically. The report includes: statistics on actual resource usage time, number of data products generated and their storage location, and integrity verification values ​​of sandbox operation logs.

[0056] Further, step S42 includes:

[0057] (1) Scene identifier code generation and binding mechanism: The scene identifier code is constructed by the triple Scene_ID=Org_ID+SceneType_Hash+Timestamp, which serves as the primary key index in the entire process of data application, development and auditing;

[0058] (2) Cross-scenario resource usage control: When a resource reuse request is detected, it is automatically upgraded to an enhanced approval process. At the same time, the development environment is forced to be physically isolated, including allocating an independent Docker container for each Scene_ID.

[0059] (3) Contextualized data lineage tracing: All initial processed data products are marked with<Scene_ID,Resource_ID> Two data lineage tags are used to accurately track which scenario the data comes from and which scenario it is used in.

[0060] Further, step S5 includes:

[0061] Step S51, Development Agreement Filing:

[0062] The operating organization submits the development organization filing application on the authorized operation platform; including: (1) Scene binding verification: The system verifies the application scene to which the development organization belongs through the scene identifier verifier. The application scene to which the development organization belongs is consistent with the original resource authorization scene; (2) Development agreement generation: Generate a structured development agreement. The key fields include the name of the development organization, the binding scene table, the agreement period, and the list of authorized initial processing data product IDs;

[0063] Step S52, Authorization Period Cascading Control:

[0064] The system automatically executes a term inheritance algorithm to ensure that the authorization period for the development organization does not exceed the original data authorization period; the original data resource authorization period is the validity period of the authorization operation agreement; the specific method is as follows:

[0065] (1) Tracing the origin of primary processed data products: The system automatically parses the original authorization link of the selected primary processed data products;

[0066] (2) Aggregation calculation of original authorization period: Extract all associated original authorization periods, obtain the original authorization time window corresponding to each initial processing data product through the authorization link tracing engine, and calculate the effective range of development period: Use the time window intersection and union algorithm to determine the time boundary allowed by the development agreement;

[0067] (3) Dynamic verification of development period: When the operating organization submits a development period request, the system performs verification to check whether it exceeds the minimum and maximum time period. If it does not exceed the time period, the save is successful; otherwise, the save fails.

[0068] Further, step S6 includes:

[0069] Step S61: The operating organization performs field-level authorization on the initial processed data products; first, the data product metadata is parsed: the field metadata of the initial processed data products is automatically extracted through the product structure parsing engine;

[0070] Step S62, Field-level authorization strategy configuration: Use a visual authorization configurator to achieve fine-grained control, display the security classification and grading of data fields, and manually select data with low sensitivity for authorization;

[0071] Step S63: Create an isolated, refined sandbox environment for the development organization, and automatically generate a field filtering view based on the location of the authorized fields; if data is provided through the API, the system automatically injects a parameter permission validator; when calling the API to request an unauthorized field, an error is returned.

[0072] The present invention also provides a multi-level refined public data resource authorization control method system based on an authorization protocol, the system comprising: a module for executing the multi-level refined public data resource authorization control method based on the authorization protocol.

[0073] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the multi-level refined public data resource authorization control method based on the licensing protocol.

[0074] The beneficial effects of this invention are:

[0075] 1. This invention, through a hierarchical convergence protocol framework of authorization operation agreement and development agreement, locks the scope of authorized data to specific scenarios, specific time periods, specific authorized objects, and specific data items; solves the problem of coarse authorization granularity, realizes refined data authorization, and breaks through the traditional extensive mode of full database development and whole table transfer;

[0076] 2. Regarding the authorized operation agreement, this invention restricts the scope of authorized data, the authorized object (operating organization), the authorization mode (related to the subsequent authorization application process), and the authorization period through the content of the agreement; thereby limiting the scope of data that the operating organization can authorize to operate.

[0077] 3. In terms of development protocol, this invention achieves scenario-based minimum authorization. In the development protocol, a strong binding mechanism is set up between the application and the initial data product and the authorized development institution, ensuring that the development institution can only obtain the data items necessary for the specific application scenario (such as only authorizing the "credit record" field in the financial risk control scenario, rather than the entire user information table), thereby eliminating the supply of data beyond the scope from the source.

[0078] 4. This invention enables precise management and control of data resources: through steps 1 and 2, the spot public data catalog is automatically synchronized and updated in real time, and unauthorized data is filtered out through a negative list; thus reducing the risk of sensitive data leakage.

[0079] 5. This invention can help ensure the compliance of authorized operations: by binding the structured filing of the agreement and the authorization period of data resources in step 3, events of authorization beyond the scope can be avoided;

[0080] 6. This invention can achieve multi-level authorization control: through the cascading verification of the development protocol period in step 5 and the fine-grained authorization at the field level in step 6, it avoids unauthorized access to data items and also avoids the development period exceeding the authorized operation period, which would hinder data development. Attached Figure Description

[0081] Figure 1 This is a schematic diagram of the overall process in this invention;

[0082] Figure 2 A schematic diagram illustrating the process of adding a negative list to the data resource catalog in this invention;

[0083] Figure 3 This is a diagram illustrating the path to achieving the technical effects in this invention. Detailed Implementation

[0084] Example 1: This invention addresses the problems existing in the prior art by providing a multi-level refined public data resource authorization control method based on authorization protocols. This technology describes an authorization control method for data resources and pre-processed data products based on authorization protocols and development protocols. It achieves complete integration of technology and business scenarios, ensuring refined authorization of public data resources and achieving refined control of one application per scenario. This invention is applicable to governments or public institutions when authorizing third-party institutions to develop data products, and achieves minimized control and security compliance of data usage scope through a dynamic hierarchical authorization mechanism.

[0085] To achieve the above objectives, the multi-level refined public data resource authorization control method based on authorization protocols of the present invention includes the following specific steps:

[0086] Step S1: Periodically synchronize the public data resource catalog from the public data platform to the authorized operation platform; the public data resource catalog includes data resource types, data item information, whether registration has been completed, data classification information, etc.; this step mainly solves the problem of data resource update lag.

[0087] Further, step S1 includes:

[0088] Step S11: Establish a public data resource catalog synchronization mechanism:

[0089] The public data platform deploys a scheduled task (such as CronJob) and triggers the directory synchronization engine to perform the following operations at 00:00 every day: (1) Call the GET / metadata interface opened by the public data platform to obtain the full public data resource directory and status identifier (including is_new for new and is_deprecated for delisting); (2) Persist the directory data to the local authorized directory database, with fields including resource_id, resource_name, status, and last_sync_time; (3) Mark delisted resources as status=INACTIVE and new resources as status=ACTIVE.

[0090] Step S12: Implement strong linkage between directory status and authorization process through the policy execution engine. The specific linkage control rules are shown in Table 1.

[0091] Table 1. Linkage Control Rules

[0092] Step S13: Execute the reverse control process:

[0093] When the public data platform initiates a resource removal operation, it pre-calls the resource usage query interface of the authorized operation platform; (1) If authorized_count>0 is returned, the removal is blocked and the error code ERR_DEPRECATE_BLOCKED is returned, and an alternative solution application work order is generated at the same time; (2) If authorized_count=0 is returned, the removal is allowed immediately.

[0094] Step S2: The data source department applies to add the catalog of data resources that cannot be authorized by the department to the negative list on the authorized operation platform. Data resources added to the negative list cannot be authorized. This step mainly breaks through the dilemma of not daring to authorize.

[0095] Further, step S2 includes:

[0096] Step S21: Use the audit workflow engine to drive the automated process of application-audit-execution; based on BPMN2.0 standard modeling, integrate electronic signature to verify the identity of the auditor, and store audit records on the blockchain to carry out the process of application to be added to the negative list-audit-approval-successful addition to the negative list;

[0097] Step S22: Use a state synchronizer to link the negative list and authorization policy in real time; use a publish-subscribe pattern to push a ResourceStatusChangeEvent to the policy execution engine when the negative list is updated, so as to achieve dynamic updates of the negative list.

[0098] Specifically, the BLOCKED / ACTIVE status flags enable atomic switching of resources between the negative list and the licenable pool; status changes trigger real-time hot updates (taking effect in milliseconds) of the policy execution engine, which avoids the drawback of traditional solutions requiring downtime for maintenance;

[0099] Step S23: Use the policy execution engine to dynamically manage authorization behavior based on a negative list, and add verification rules in the agreement creation / data request stage, for example... The statement `IF resource_id IN negative_list_db THEN DISABLE` is used to prevent the use of data catalog resources in the negative list.

[0100] Step S3: The implementing agency files the authorization operation agreement on the authorized operation platform; the authorization operation agreement should clearly specify the authorized operation agency, the scope of authorized data, the authorization period, and the authorization mode; this step mainly eliminates the problem of conflicting authorization periods at the N-level.

[0101] Further, step S3 includes:

[0102] Step S31: The implementing agency (such as a government department) creates and files an authorized operation agreement through the agreement management module of the authorized operation platform. This authorized operation agreement includes the following constraint fields:

[0103] Authorized Entity Binding Field: Specifies the identifier of the authorized operating organization (such as the organization ID);

[0104] Data range whitelist field: Defines the set of data resources that can be authorized (such as "Medical Insurance Database A, Social Security Database B").

[0105] Time-limited control field: Sets the authorization validity period (e.g., start and end timestamps);

[0106] Authorization mode identifier field: declares the data usage rules (e.g., "de-identification processing only");

[0107] Step S32: After the authorized operation agreement is filed, the policy execution engine of the authorized operation platform automatically performs the following dynamic control:

[0108] (1) Application scope constraint: When the operating institution initiates a resource request through the data application interface of the authorized operating platform, the system calls the data scope whitelist field in the authorized operating agreement in real time to forcibly limit the range of optional data resources, so that it can only select the datasets in the whitelist (such as prohibiting the selection of the unauthorized "Tax Treasury Table C").

[0109] (2) Authorization time limit interception mechanism: When the policy execution engine receives the application request, it automatically verifies the matching of the current timestamp with the time limit control field in the protocol: if the application time is within the validity period, the application is allowed to be submitted; if the validity period is exceeded, the protocol expiration interceptor is triggered, an error code is returned and the process is terminated.

[0110] Step S4: The operating organization creates an application scenario on the authorized operation platform, applies for data resource authorization based on the authorized data scope stipulated in the authorized operation agreement in step S3, and develops and generates preliminary data products. The usage period is the authorization period stipulated in the authorized operation agreement in step S3.

[0111] Further, step S4 includes:

[0112] Step S41, Application Scenario Creation and Protocol Resource Loading: The operating organization creates an application scenario (such as a smart medical diagnostic model) on the authorized operation platform. The system automatically generates a globally unique scenario identifier code Scene_ID. The system automatically loads the authorized data range specified in the authorized operation agreement signed with the operating organization through the protocol parsing engine, and performs real-time filtering at the same time.

[0113] Step S42: Request for protocol resource authorization based on scene identifier:

[0114] Within the authorized data scope stipulated in the authorized operation agreement, the operating organization selects the data resources to be applied for. When submitting the application, the system automatically generates a structured application document (including application scenario description and resource ID list) and triggers a multi-level review workflow engine. Based on the applied data resources identified in the current scenario, the system performs the following technical controls:

[0115] Resource application scenario binding: The application form automatically embeds the hidden field Scene_ID, which is verified by the backend through a request interceptor; when the applied resource has been authorized based on a certain scenario and needs to be used in a new scenario, the application review process also needs to be triggered, and manual review is carried out again based on the new application scenario to prevent the abuse of data resources;

[0116] Step S43, Injecting Authorized Resources into the Data Development Platform: After both levels of review are passed, the system performs the following automated operations: (1) Dynamic credential generation: Create a time-limited access token for each authorized resource, with the validity period bound to the protocol expiration time; (2) Sandbox resource mounting: Mount the authorized resource to the independent container sandbox of the data development platform in the form of an encrypted volume; (3) Lifecycle timer start: Register a resource recycling task in the scheduled task service, with the trigger time being the protocol expiration time;

[0117] Step S44: Data product generation in the development environment: Within the container sandbox of the data development platform, the operating organization accesses authorized resources through a secure computing engine (such as a TEE trusted execution environment) and uses SQL / Spark tools to generate preliminary data products. When the preliminary data products are output, data lineage tags (recording the original resource ID and processing path) are automatically attached.

[0118] Step S45, Lifecycle Expiration Warning:

[0119] Thirty days before the agreement expires, the system automatically triggers an early warning mechanism: sending system message notifications and SMS reminders to the operating organization through the message distribution service;

[0120] Step S46, Automatic Resource Recycling: When the agreement expires, the system performs an atomic recycling operation; unloads the sandbox resource volume, freezes intermediate data products, recycles the temporary Fanwei token, and updates the authorization state machine;

[0121] Step S47, Post-recycling audit trail: The system generates a resource recycling audit report and archives it automatically. The report includes: statistics on actual resource usage time, number of data products generated and their storage locations, and integrity check value (SHA-256 digest) of sandbox operation logs.

[0122] Further, step S42 includes:

[0123] (1) Scene identifier code generation and binding mechanism: The scene identifier code is constructed by the triple Scene_ID=Org_ID+SceneType_Hash+Timestamp, which serves as the primary key index in the entire process of data application, development and auditing;

[0124] (2) Cross-scenario resource usage control: When a resource reuse request is detected, it is automatically upgraded to an enhanced approval process. At the same time, the development environment is forced to be physically isolated, including allocating an independent Docker container for each Scene_ID.

[0125] (3) Contextualized data lineage tracing: All initial processed data products are marked with<Scene_ID,Resource_ID> Two data lineage tags are used to accurately track which scenario the data comes from and which scenario it is used in.

[0126] Step S5: After selecting a development agency based on the application scenario, the operating agency shall file a development agreement on the authorized operation platform. The development agreement shall clearly specify the authorized development agency, the authorized application scenario, the authorization period, and the authorized initial data products. The authorization period for the development agency shall not exceed the authorization period for the original data resources in the authorized operation agreement in step S3.

[0127] Further, step S5 includes:

[0128] Step S51, Development Agreement Filing:

[0129] The operating organization submits the development organization filing application on the authorized operation platform; including: (1) Scene binding verification: The system verifies the application scene to which the development organization belongs through the scene identifier verifier. The application scene to which the development organization belongs is consistent with the original resource authorization scene; (2) Development agreement generation: Generate a structured development agreement. The key fields include the name of the development organization, the binding scene table, the agreement period, and the list of authorized initial processing data product IDs;

[0130] Step S52, Authorization Period Cascading Control:

[0131] The system automatically executes a term inheritance algorithm to ensure that the authorization period of the development organization does not exceed the original data authorization period; the original data resource authorization period is the authorization validity period of the authorization operation agreement in step S31; the specific method is as follows:

[0132] (1) Tracing the origin of primary processed data products: The system automatically parses the original authorization link of the selected primary processed data products;

[0133] (2) Aggregation calculation of original authorization period: Extract all associated original authorization periods, obtain the original authorization time window corresponding to each initial processing data product through the authorization link tracing engine, and calculate the effective range of development period: Use the time window intersection and union algorithm to determine the time boundary allowed by the development agreement;

[0134] (3) Dynamic verification of development period: When the operating organization submits a development period request, the system performs verification to check whether it exceeds the minimum and maximum time period. If it does not exceed the time period, the save is successful; otherwise, the save fails.

[0135] Step S6: The operating organization further refines the authorization of the initial processed data products, clarifying the specific data items, fields, and return parameters to be given to the corresponding development organization for each initial processed data product based on the application scenario; and further controlling the scope of authorization.

[0136] Further, step S6 includes:

[0137] Step S61: The operating organization performs field-level authorization on the initial processed data products; first, the data product metadata is parsed: the field metadata of the initial processed data products is automatically extracted through the product structure parsing engine;

[0138] Step S62, Field-level authorization strategy configuration: Use a visual authorization configurator to achieve fine-grained control, display the security classification and grading of data fields, and manually select data with low sensitivity for authorization;

[0139] Step S63: Create an isolated, refined sandbox environment for the development organization, and automatically generate a field filtering view based on the location of the authorized fields; if data is provided through the API, the system automatically injects a parameter permission validator; when calling the API to request an unauthorized field, an error is returned.

[0140] The present invention also provides a multi-level refined public data resource authorization control method system based on an authorization protocol, the system comprising: a module for executing the multi-level refined public data resource authorization control method based on the authorization protocol.

[0141] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the multi-level refined public data resource authorization control method based on the licensing protocol.

[0142] To verify the effectiveness of the present invention, the present invention has the following implementation effects as shown in Table 2:

[0143] Table 2 shows the implementation effects of the present invention.

[0144] This invention has the following technical advantages:

[0145] 1. Process Compliance: The negative list level-one review complies with the "Trial Measures for the Authorization and Operation Management of a Certain Public Data Resource"; the flexible agreement on the term meets the authorization requirements of case-by-case discussion;

[0146] 2. Lightweight technology: After removing the blockchain, the system throughput increased by 300% (TPS from 127 to 512), and the operation and maintenance cost was reduced by 60% (no need to maintain the node cluster).

[0147] 3. Security is still guaranteed: Database transaction logs ensure traceability of operations (retention period ≥ 5 years).

[0148] The following explanation uses authorization control in a financial risk control scenario as an example.

[0149] Suppose a public data platform authorizes medical insurance database data to operating institution A. Under the normal authorization model, the following problems may occur:

[0150] 1. Risk of full access: Operating institution A obtains the entire medical insurance form (including 218 fields such as ID number and genetic disease history) at once, and development institution B obtains full access to the form through a sub-protocol;

[0151] 2. Expiration Date Vulnerability: The original license period expires on December 31, 2025. If the development agreement is mistakenly set to June 30, 2026, the system will have no restrictions, making it difficult to detect.

[0152] 3. Scenario generalization and abuse: Development agency B used the data for unauthorized "commercial insurance sales", and sensitive fields were copied and spread.

[0153] The proposed solution enables layered management: In the first stage, through step S2, resource-level negative list management is implemented. The data source department adds the entire "Gene Testing Result Table" to the negative list (resource level). When operating institution A creates an agreement, this table is automatically removed from the optional list (the strategy engine intercepts in real time). In the second stage, through steps S4 to S6, field-level dynamic convergence is achieved. The operating institution creates a "Financial Risk Control" scenario for application. According to the constraints of step S4, only the two non-sensitive tables, "Insured Status" and "Contribution Base," in the medical insurance database are selected. Then, a preliminary product, "Insured Person Credit Benchmark Table" (containing 15 fields), is generated in the encrypted sandbox. According to step 6, when the operating institution authorizes A to provide the preliminary product to the development institution, the development institution only obtains the three selected fields (credit rating, contribution base, and insured status). In the third stage, based on step S5, a time-limited circuit breaker can be implemented. If the development agreement is mistakenly filled with 2026-06-30, the system will verify the parent agreement's time limit (2025-12-31) in real time. The front end will immediately disable the submit button and prompt "The end date exceeds the parent agreement by 183 days". The actual security effect is shown in Table 3.

[0154] Table 3 Comparison of Safety Effects

[0155] This invention uses S2 to block the entire table (such as a gene detection table) at the resource level; and uses S6 to achieve granular control of fields (such as hiding genetic disease history fields) at the post-processing level.

[0156] This invention achieves a gradual convergence of data access surfaces by using the process of "full database table → negative list filtering → scenario-based table selection → initial processing products → field-level authorization," reducing the data access surface from 218 fields to 3 fields, which aligns with the principle of minimizing the processing steps layer by layer.

[0157] The specific embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of the present invention.

Claims

1. A method for multi-level refinement of public data resource authorization control based on authorization protocol, characterized in that: The method comprises: Step S1, synchronizing a public data resource directory to an authorized operation platform from a public data platform in time; Step S2, a data source department applies to join a negative list for data resources that cannot be authorized on the authorized operation platform; data resources in the negative list cannot be authorized; Step S3, an implementing agency records an authorized operation agreement on the authorized operation platform; in the authorized operation agreement, the authorized operation agency, the authorized data range, the authorized period, and the authorized mode are specified; Step S4, an operation agency creates an application scenario on the authorized operation platform, applies for data resource authorization within the authorized data range specified in the authorized operation agreement of step S3, develops a primary processed data product, and the use period is the authorized period specified in the authorized operation agreement of step S3; Step S5, after the operation agency selects a development agency based on the application scenario, the development agency records a development agreement on the authorized operation platform; in the development agreement, the authorized development agency, the authorized application scenario, the authorized period, and the authorized primary processed data product are specified; the authorized period of the development agency shall not exceed the period of the original data resource authorization in the authorized operation agreement of step S3; Step S6, the operation agency further authorizes the primary processed data product, specifies the specific data item field and return parameter of each primary processed data product given to the corresponding development agency based on the application scenario, and further controls the authorized range.

2. The method of claim 1, wherein the method further comprises: The step S1 comprises: Step S11, establishing a public data resource directory synchronization mechanism: The public data platform deploys a timing task scheduler, which triggers a directory synchronization engine to perform the following operations at a specified time every day: (1) calling the GET / metadata interface exposed by the public data platform to obtain the full public data resource directory and status identifier; (2) persistently storing the directory data to the local authorized directory database, including the fields resource_id, resource_name, status, and last_sync_time; (3) marking the status of the decommissioned resources as INACTIVE, and marking the status of the new resources as ACTIVE; Step S12, realizing strong linkage between the directory state and the authorization process through a policy execution engine; Step S13, executing a reverse control process: When the public data platform initiates a resource decommissioning operation, it pre-calls the resource occupation query interface of the authorized operation platform; (1) if the return authorized_count>0, the decommissioning is blocked and an error code ERR_DEPRECATE_BLOCKED is returned, and a replacement scheme application work order is generated; (2) if the return authorized_count =0, the decommissioning is allowed immediately.

3. The method of claim 1, wherein the method further comprises: The step S2 comprises: Step S21, using an audit workflow engine to drive the automatic process of application-audit-execution; based on the BPMN2.0 standard modeling, integrating electronic signature verification to verify the identity of the auditor, and recording the audit record on the chain for storage, the process of applying to join the negative list-audit-audit pass-joining the negative list successfully is performed; Step S22, using a state synchronizer, real-time linkage of the negative list and authorization policy; using the publish-subscribe mode, when the negative list is updated, pushing the ResourceStatusChangeEvent event to the policy execution engine to achieve dynamic updating of the negative list; Among them, the atomic level switching of resources between the negative list and the authorized pool is realized through the BLOCKED / ACTIVE state identification; the state change triggers the policy execution engine to update in real time, which is used to avoid the defect that the traditional scheme needs to be shut down for maintenance; Step S23, using the policy execution engine, dynamically controlling the authorization behavior based on the negative list, adding verification rules in the protocol creation / data application link to achieve the effect of being unable to use the data directory resources in the negative list.

4. The method of claim 1, wherein the method further comprises: The step S3 includes: Step S31, the implementing agency creates and records the authorized operation agreement through the agreement management module of the authorized operation platform, and the authorized operation agreement contains the following constraint fields: Authorization subject binding field: specifies the identification of the authorized operation agency; Data range white list field: defines the authorized data resource set; Time control field: set the authorization validity period; Authorization mode identification field: declare data usage rules; Step S32, after the authorized operation agreement is recorded, the policy execution engine of the authorized operation platform automatically performs the following dynamic control: (1) Application range constraint: when the operation agency initiates a resource request through the data application interface of the authorized operation platform, the system calls the data range white list field in the authorized operation agreement in real time to forcibly limit the selectable data resource range, so that it can only select the data set in the white list; (2) Authorization time interception mechanism: the policy execution engine automatically checks the matching of the current timestamp and the time control field in the agreement when receiving the application request: if the application time is within the valid period, the application is allowed to be submitted; if it exceeds the valid period, the agreement invalid interceptor is triggered, and an error code is returned and the process is terminated.

5. The method of claim 1, wherein the method further comprises: The step S4 includes: Step S41, application scenario creation and protocol resource loading: the operation agency creates an application scenario in the authorized operation platform, and the system automatically generates a globally unique scenario identification code Scene_ID; the system automatically loads the authorized data range specified in the authorized operation agreement signed with the operation agency through the protocol analysis engine, and simultaneously performs real-time filtering; Step S42, protocol resource authorization application based on scene identification: The operation agency selects the data resources to be applied in the authorized data range specified in the authorized operation agreement, and the system automatically generates a structured application document when submitting the application, and triggers a multi-level audit workflow engine; based on the application data resources of the current scenario identification, the system performs the following technical control: Resource application scenario binding: the Scene_ID hidden field is automatically embedded in the application form, and the back end is verified through the request interceptor; when the applied resources have been authorized based on a certain scenario, they need to be used in a new scenario, which also needs to trigger the application review process, based on the new application scenario, manual review is performed again to prevent data resource abuse; Step S43, authorized resource injection data development platform: after passing the two-level audit, the system performs the following automatic operations: (1) dynamic credential generation: create time-limited access tokens for each authorized resource, with a validity period bound to the protocol expiration time; (2) sandbox resource mounting: mount the authorized resources to the data development platform's independent container sandbox in the form of an encrypted volume; (3) lifecycle timer start: register resource recycling tasks in the timing task service, with a trigger time of the protocol expiration time; Step S44, development environment data product generation: the operating agency accesses the authorized resources through the secure computing engine in the container sandbox of the data development platform, and generates primary processing data products using SQL / Spark tools. The primary processing data products are automatically attached with data provenance tags when output; Step S45, lifecycle expiration warning: 30 days before the expiration of the agreement, the system automatically triggers the warning mechanism: through the message distribution service, send system message notifications and SMS reminders to the operating agency; Step S46, resource automatic recycling: when the agreement expires, the system performs atomic recycling operations; unload the sandbox resource volume, freeze intermediate data products, recycle temporary generic tokens, and update the authorized state machine; Step S47, post-recycling audit tracking: the system generates a resource recycling audit report and automatically archives it. The report includes: resource actual usage duration statistics, data product generation quantity and storage location, and sandbox operation log integrity check value.

6. The method of claim 5, wherein the method further comprises: The step S42 includes: (1) Scene identification code generation and binding mechanism: construct an unforgeable scene identification code through the Scene_ID=Org_ID+SceneType_Hash+Timestamp triplet, which is used as the primary key index in the data application, development, and audit process; (2) Cross-scene resource usage control: when resource reuse requests are detected, automatically upgrade to a strengthened approval process. At the same time, the development environment is forced to be physically isolated, which includes assigning an independent Docker container for each Scene_ID; (3) Scene-based data provenance tracing: all primary processing data products are tagged with <Scene_ID, Resource_ID> data provenance tags, which are used to accurately track the data from which scene and which scene is used.

7. The method of claim 1, wherein the method further comprises: The step S5 includes: Step S51, development agreement filing: The operating agency submits a development agency filing application on the authorized operating platform; including: (1) scene binding verification: the system verifies the development agency's application scene through the scene identification verifier, and the development agency's application scene is consistent with the original resource authorization scene; (2) development agreement generation: generate a structured development agreement, with key fields including development agency name, binding scene table, protocol term, and authorized primary processing data product ID list; Step S52, authorized term cascade control: The system automatically performs term inheritance algorithm to ensure that the development agency's authorized term does not exceed the original data authorized term; the original data resource authorized term is the authorized validity period of the authorized operating agreement; the specific method is: (1) Primary processing data product association traceability: the system automatically analyzes the original authorization link of the selected primary processing data product; (2) Original authorization period aggregation calculation: extract all associated original authorization periods, obtain the original authorization time window corresponding to each primary processing data product through the authorization link tracing engine, and calculate the development period effective interval: adopt the time window intersection and union algorithm to determine the time boundary allowed by the development agreement; (3) Development period dynamic verification: when the operation agency submits a development period request, the system performs verification to determine whether it exceeds the minimum and maximum time period, and saves successfully if it does not exceed, or fails if it does.

8. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: The step S6 comprises: Step S61, the operation agency performs field-level authorization on the primary processing data product; first, data product metadata analysis is performed: the field metadata of the primary processing data product is automatically extracted through a product structure analysis engine; Step S62, field-level authorization strategy configuration: a visual authorization configuration tool is used to achieve fine-grained control, display the security classification and grading of data fields, and manually check and authorize low-sensitivity data; Step S63, a separate fine-grained sandbox environment is created for the development agency, and a field filtering view is automatically generated according to the authorized field orientation; if data is provided through an API, a parameter permission checker is automatically injected by the system; when an unauthorized field is called, an error is returned.

9. A multi-level refinement public data resource authorization control method system based on an authorization protocol, characterized in that, The system comprises a module for executing the multi-level fine-grained public data resource authorization control method based on an authorization agreement as claimed in any one of claims 1 to 8.

10. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to implement the multi-level fine-grained public data resource authorization control method based on an authorization agreement as claimed in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Authorization authentication method and device under cross-channel multi-service scene

    CN116405290A

  • Multi-platform data collaborative governance authority dynamic control method and system

    CN120296797A

  • Operation system and method for digital transformation project

    CN120725490A

  • Public data platform compliance early warning system based on legal risk indicators

    CN121032227A