Multi-level refined public data resource authorization control method based on authorization protocol

By employing a multi-level, refined authorization control method, the problems of insufficient authorization granularity, lack of scenario-based adaptation, and lagging security control in public data authorization have been solved. This has enabled refined management and security compliance of data resources, reduced the risk of data leakage, and improved the security and compliance of data use.

CN121682874BActive Publication Date: 2026-04-21YUNNAN PROVINCIAL BIG DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing public data authorization technologies suffer from insufficient authorization granularity, lack of scenario-based adaptation, and lagging security controls, resulting in high data leakage risks, high compliance costs, and insufficient market impetus.

Method used

A multi-level, refined authorization control method is adopted, which gradually narrows the data scope through negative lists, scenario binding, and field-level authorization. Combined with scheduled synchronization, policy execution engine, and lifecycle management, it achieves refined management and control of data resources.

Benefits of technology

It enables more refined data authorization, reduces the risk of sensitive data leakage, ensures compliance, avoids data supply beyond the scope and development period exceeding the limit, and improves the security and compliance of data use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121682874B_ABST
    Figure CN121682874B_ABST
Patent Text Reader

Abstract

This invention relates to a multi-level, refined public data resource authorization control method based on authorization agreements, belonging to the field of public data resource authorization operation technology. The invention includes the following steps: periodically synchronizing the public data resource catalog from the public data platform to the authorization operation platform; applying to add the catalog of data resources that cannot be authorized by the department to the negative list; the implementing agency filing the authorization operation agreement on the authorization operation platform; the operating agency creating application scenarios on the authorization operation platform; filing the development agreement on the authorization operation platform; the operating agency further refining the authorization of the initial processed data products, specifying the specific data item fields and return parameters for each initial processed data product based on the application scenario and assigned to the corresponding development agency; further controlling the scope of authorization; this invention enables refined data authorization, breaking through the traditional extensive model of full-database development and whole-table transfer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a multi-level refined public data resource authorization control method based on authorization agreements, belonging to the field of public data resource authorization operation technology. Background Technology

[0002] Public data licensing and operation refers to the process by which governments or public institutions authorize specific operating entities (such as enterprises or social organizations) to process and develop data resources into data products or services, thereby realizing the value of data elements. The current mainstream technical architecture and its existing shortcomings are as follows:

[0003] 1. Overview of existing technologies:

[0004] The licensing model is too broad: existing platforms mainly stipulate the scope and duration of data use through a single-level licensing agreement (such as a framework agreement between the government and the operating agency). For example, it may only stipulate that "a certain type of database can be accessed" or "the development of products in a specific field is allowed", which lacks detailed constraints on the data use scenarios, processing levels and data items.

[0005] Technical limitations: Existing platforms, such as the "Technical Requirements for Public Data Authorization and Operation Platforms" (T / CECC 024-2023), define the authorization architecture, but the authorization control unit only operates at the dataset level, unable to be refined to the data item level (such as a single field) or dynamically sampled by scenario. Security control relies on post-event auditing rather than embedding minimal authorization rules at each stage of data flow.

[0006] Insufficient regulatory mechanisms: Most systems adopt the "full access after authorization" model, which allows operating institutions to obtain all data at once, resulting in a high risk of data being used beyond its scope; at the same time, the data access permissions of development institutions are allocated independently by the operating institutions, and the government cannot directly intervene in its granular control.

[0007] 2. Existing technical problems and their causes:

[0008] Issue 1: Insufficient granularity of authorization makes it difficult to balance security and exploitation.

[0009] Public data often contains sensitive information such as personal privacy and public safety, and the current extensive authorization system is prone to data leakage or misuse. At its root, the lack of a technical framework of "layered protocol + dynamic constraints" makes it impossible to converge the scope of data from the resource layer (overall dataset) to the scenario layer (specific data items).

[0010] Question 2: Lack of scenario-based adaptation, making it difficult to implement the minimization principle:

[0011] The data requirements of development institutions vary significantly across different scenarios (e.g., medical analysis requires gender and age, while financial risk control requires credit records). However, existing technologies do not strongly bind authorization to application scenarios, resulting in an oversupply of data. For example, initially processed data products (such as anonymized statistical tables) are still transferred as a whole during secondary authorization, making it impossible to remove irrelevant data items as needed.

[0012] Question 3: Lagging safety controls and lack of pre-emptive prevention mechanisms:

[0013] Existing platforms rely on post-event log auditing, but lack a sample data sampling mechanism during the development phase, making it impossible to verify the necessity of data in the pre-development stage. Furthermore, authorization status monitoring focuses primarily on process compliance rather than the dynamic control of the data content itself.

[0014] 3. Consequences of the problem:

[0015] The aforementioned deficiencies have led to increased security risks in the authorized operation of public data (such as data being copied and disseminated beyond its scope), high compliance costs (requiring manual review of data usage), and insufficient market impetus (development institutions avoid high-value data due to security concerns), which seriously restricts the release of the value of data elements.

[0016] In response to the three major shortcomings mentioned in the background art—insufficient authorization granularity, lack of scenario-based adaptation, and lagging security control—this invention provides a multi-level, refined public data resource authorization control method based on authorization protocols. Summary of the Invention

[0017] In response to the three major shortcomings mentioned in the background technology—insufficient authorization granularity, lack of scenario-based adaptation, and lagging security control—this invention provides a multi-level refined public data resource authorization control method based on authorization protocols. This invention can achieve refined data authorization, breaking through the traditional extensive mode of full database development and whole table transfer.

[0018] The technical solution of this invention is: a multi-level refined public data resource authorization control method based on an authorization protocol, the method comprising:

[0019] Step S1: Periodically synchronize the public data resource catalog from the public data platform to the authorized operation platform;

[0020] Step S2: The data source department applies to add the catalog of data resources that cannot be authorized by the department to the negative list on the authorized operation platform. Data resources added to the negative list cannot be authorized.

[0021] Step S3: The implementing agency files the authorization operation agreement on the authorized operation platform; the authorization operation agreement shall clearly specify the authorized operation agency, the scope of authorized data, the authorization period, and the authorization model.

[0022] Step S4: The operating organization creates an application scenario on the authorized operation platform, applies for data resource authorization based on the authorized data scope stipulated in the authorized operation agreement in step S3, and develops and generates preliminary data products. The usage period is the authorization period stipulated in the authorized operation agreement in step S3.

[0023] Step S5: After selecting a development agency based on the application scenario, the operating agency shall file a development agreement on the authorized operation platform. The development agreement shall clearly specify the authorized development agency, the authorized application scenario, the authorization period, and the authorized initial data products. The authorization period for the development agency shall not exceed the authorization period for the original data resources in the authorized operation agreement in step S3.

[0024] Step S6: The operating organization further refines the authorization of the initial processed data products, clarifying the specific data items, fields, and return parameters to be given to the corresponding development organization for each initial processed data product based on the application scenario; and further controls the scope of authorization.

[0025] Further, step S1 includes:

[0026] Step S11: Establish a public data resource catalog synchronization mechanism:

[0027] The public data platform deploys a scheduled task scheduler, which triggers the directory synchronization engine to perform the following operations at a specified time each day: (1) Call the GET / metadata interface opened by the public data platform to obtain the full public data resource directory and status identifier; (2) Persist the directory data to the local authorized directory database, with fields including resource_id, resource_name, status, and last_sync_time; (3) Mark the delisted resources as status=INACTIVE and the newly added resources as status=ACTIVE.

[0028] Step S12: Implement strong linkage between directory status and authorization process through the policy execution engine;

[0029] Step S13: Execute the reverse control process:

[0030] When the public data platform initiates a resource removal operation, it pre-calls the resource occupancy query interface of the authorized operation platform; (1) If authorized_count>0 is returned, the removal is blocked and the error code ERR_DEPRECATE_BLOCKED is returned, and an alternative solution application work order is generated at the same time; (2) If authorized_count=0 is returned, the removal is allowed immediately.

[0031] Further, step S2 includes:

[0032] Step S21: Use the audit workflow engine to drive the automated process of application-audit-execution; based on BPMN2.0 standard modeling, integrate electronic signature to verify the identity of the auditor, and store audit records on the blockchain to carry out the process of application to be added to the negative list-audit-approval-successful addition to the negative list;

[0033] Step S22: Use a state synchronizer to link the negative list and authorization policy in real time; use a publish-subscribe pattern to push a ResourceStatusChangeEvent to the policy execution engine when the negative list is updated, so as to achieve dynamic updates of the negative list.

[0034] Specifically, the BLOCKED / ACTIVE status flags enable atomic switching of resources between the negative list and the licenable pool; status changes trigger real-time hot updates of the policy execution engine to avoid the downtime maintenance required by traditional solutions.

[0035] Step S23: Use the strategy execution engine to dynamically manage authorization behavior based on the negative list, and add verification rules in the agreement creation / data application stage to achieve the effect of not being able to use the data catalog resources in the negative list.

[0036] Further, step S3 includes:

[0037] Step S31: The implementing agency creates and files an authorization operation agreement through the agreement management module of the authorization operation platform. This authorization operation agreement includes the following constraint fields:

[0038] Authorization Entity Binding Field: Specifies the identifier of the authorized operating organization;

[0039] Data range whitelist field: Defines the set of data resources that can be authorized;

[0040] Time-limited control field: Sets the authorization validity period;

[0041] Authorization pattern identifier field: declares the rules for data usage;

[0042] Step S32: After the authorized operation agreement is filed, the policy execution engine of the authorized operation platform automatically performs the following dynamic control:

[0043] (1) Application scope constraint: When the operating institution initiates a resource request through the data application interface of the authorized operation platform, the system calls the data scope whitelist field in the authorized operation agreement in real time to forcibly limit the range of optional data resources, so that it can only select the datasets in the whitelist;

[0044] (2) Authorization time limit interception mechanism: When the policy execution engine receives the application request, it automatically verifies the matching of the current timestamp with the time limit control field in the protocol: if the application time is within the validity period, the application is allowed to be submitted; if the validity period is exceeded, the protocol expiration interceptor is triggered, an error code is returned and the process is terminated.

[0045] Further, step S4 includes:

[0046] Step S41, Application Scenario Creation and Protocol Resource Loading: The operating organization creates an application scenario on the authorized operation platform, and the system automatically generates a globally unique scene identifier code Scene_ID; the system automatically loads the authorized data range specified in the authorized operation agreement signed with the operating organization through the protocol parsing engine, and performs real-time filtering at the same time;

[0047] Step S42: Request for protocol resource authorization based on scene identifier:

[0048] The operating organization selects the data resources to be applied for within the authorized data scope specified in the authorized operation agreement. When submitting the application, the system automatically generates a structured application document and triggers a multi-level review workflow engine. Based on the applied data resources identified in the current scenario, the system performs the following technical controls:

[0049] Resource application scenario binding: The application form automatically embeds the hidden field Scene_ID, which is verified by the backend through a request interceptor; when the applied resource has been authorized based on a certain scenario and needs to be used in a new scenario, the application review process also needs to be triggered, and manual review is carried out again based on the new application scenario to prevent the abuse of data resources;

[0050] Step S43, Injecting Authorized Resources into the Data Development Platform: After both levels of review are approved, the system performs the following automated operations: (1) Dynamic Credential Generation: Create a time-sensitive access token for each authorized resource, with the validity period bound to the protocol expiration time; (2) Sandbox Resource Mounting: Mount the authorized resource to the independent container sandbox of the data development platform in the form of an encrypted volume; (3) Lifecycle Timer Startup: Register a resource recycling task in the scheduled task service, with the trigger time being the protocol expiration time;

[0051] Step S44: Data product generation in the development environment: Within the container sandbox of the data development platform, the operating organization accesses authorized resources through the secure computing engine and uses SQL / Spark tools to generate preliminary data products. Data lineage tags are automatically attached when the preliminary data products are output.

[0052] Step S45, Lifecycle Expiration Warning:

[0053] Thirty days before the agreement expires, the system automatically triggers an early warning mechanism: sending system message notifications and SMS reminders to the operating organization through the message distribution service;

[0054] Step S46, Automatic Resource Recycling: When the agreement expires, the system performs an atomic recycling operation; unloads the sandbox resource volume, freezes intermediate data products, recycles the temporary Fanwei token, and updates the authorization state machine;

[0055] Step S47, Post-recycling audit trail: The system generates a resource recycling audit report and archives it automatically. The report includes: statistics on actual resource usage time, number of data products generated and their storage location, and integrity verification values ​​of sandbox operation logs.

[0056] Further, step S42 includes:

[0057] (1) Scene identifier code generation and binding mechanism: The scene identifier code is constructed by the triple Scene_ID=Org_ID+SceneType_Hash+Timestamp, which serves as the primary key index in the entire process of data application, development and auditing;

[0058] (2) Cross-scenario resource usage control: When a resource reuse request is detected, it is automatically upgraded to an enhanced approval process. At the same time, the development environment is forced to be physically isolated, including allocating an independent Docker container for each Scene_ID.

[0059] (3) Contextualized data lineage tracing: All initial processed data products are marked with<Scene_ID,Resource_ID> Two data lineage tags are used to accurately track which scenario the data comes from and which scenario it is used in.

[0060] Further, step S5 includes:

[0061] Step S51, Development Agreement Filing:

[0062] The operating organization submits the development organization filing application on the authorized operation platform; including: (1) Scene binding verification: The system verifies the application scene to which the development organization belongs through the scene identifier verifier. The application scene to which the development organization belongs is consistent with the original resource authorization scene; (2) Development agreement generation: Generate a structured development agreement. The key fields include the name of the development organization, the binding scene table, the agreement period, and the list of authorized initial processing data product IDs;

[0063] Step S52, Authorization Period Cascading Control:

[0064] The system automatically executes a term inheritance algorithm to ensure that the authorization period for the development organization does not exceed the original data authorization period; the original data resource authorization period is the validity period of the authorization operation agreement; the specific method is as follows:

[0065] (1) Tracing the origin of primary processed data products: The system automatically parses the original authorization link of the selected primary processed data products;

[0066] (2) Aggregation calculation of original authorization period: Extract all associated original authorization periods, obtain the original authorization time window corresponding to each initial processing data product through the authorization link tracing engine, and calculate the effective range of development period: Use the time window intersection and union algorithm to determine the time boundary allowed by the development agreement;

[0067] (3) Dynamic verification of development period: When the operating organization submits a development period request, the system performs verification to check whether it exceeds the minimum and maximum time period. If it does not exceed the time period, the save is successful; otherwise, the save fails.

[0068] Further, step S6 includes:

[0069] Step S61: The operating organization performs field-level authorization on the initial processed data products; first, the data product metadata is parsed: the field metadata of the initial processed data products is automatically extracted through the product structure parsing engine;

[0070] Step S62, Field-level authorization strategy configuration: Use a visual authorization configurator to achieve fine-grained control, display the security classification and grading of data fields, and manually select data with low sensitivity for authorization;

[0071] Step S63: Create an isolated, refined sandbox environment for the development organization, and automatically generate a field filtering view based on the location of the authorized fields; if data is provided through the API, the system automatically injects a parameter permission validator; when calling the API to request an unauthorized field, an error is returned.

[0072] The present invention also provides a multi-level refined public data resource authorization control method system based on an authorization protocol, the system comprising: a module for executing the multi-level refined public data resource authorization control method based on the authorization protocol.

[0073] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the multi-level refined public data resource authorization control method based on the licensing protocol.

[0074] The beneficial effects of this invention are:

[0075] 1. This invention, through a hierarchical convergence protocol framework of authorization operation agreement and development agreement, locks the scope of authorized data to specific scenarios, specific time periods, specific authorized objects, and specific data items; solves the problem of coarse authorization granularity, realizes refined data authorization, and breaks through the traditional extensive mode of full database development and whole table transfer;

[0076] 2. Regarding the authorized operation agreement, this invention restricts the scope of authorized data, the authorized object (operating institution), the authorization mode (related to the subsequent authorization application process), and the authorization period through the content of the agreement; thereby limiting the scope of data that the operating institution can authorize to operate.

[0077] 3. In terms of development protocol, this invention achieves scenario-based minimum authorization. In the development protocol, a strong binding mechanism is set up between the application and the initial data product and the authorized development institution, ensuring that the development institution can only obtain the data items necessary for the specific application scenario (such as only authorizing the "credit record" field in the financial risk control scenario, rather than the entire user information table), thereby eliminating the supply of data beyond the scope from the source.

[0078] 4. This invention enables precise management and control of data resources: through steps 1 and 2, the spot public data catalog is automatically synchronized and updated in real time, and unauthorized data is filtered out through a negative list; thus reducing the risk of sensitive data leakage.

[0079] 5. This invention can help ensure the compliance of authorized operations: by binding the structured filing of the agreement and the authorization period of data resources in step 3, events of authorization beyond the scope can be avoided;

[0080] 6. This invention can achieve multi-level authorization control: through step 5 development protocol term cascading verification and step 6 field-level fine authorization, it avoids unauthorized access to data items and also avoids the development period exceeding the authorized operation period, which would hinder data development. Attached Figure Description

[0081] Figure 1 This is a schematic diagram of the overall process in this invention;

[0082] Figure 2 A schematic diagram illustrating the process of adding a negative list to the data resource catalog in this invention;

[0083] Figure 3 This is a diagram illustrating the path to achieving the technical effects in this invention. Detailed Implementation

[0084] Example 1: This invention addresses the problems existing in the prior art by providing a multi-level refined public data resource authorization control method based on authorization protocols. This technology describes an authorization control method for data resources and pre-processed data products based on authorization protocols and development protocols. It achieves complete integration of technology and business scenarios, ensuring refined authorization of public data resources and achieving refined control of one application per scenario. This invention is applicable to governments or public institutions when authorizing third-party institutions to develop data products, and achieves minimized control and security compliance of data usage scope through a dynamic hierarchical authorization mechanism.

[0085] To achieve the above objectives, the multi-level refined public data resource authorization control method based on authorization protocols of the present invention includes the following specific steps:

[0086] Step S1: Periodically synchronize the public data resource catalog from the public data platform to the authorized operation platform; the public data resource catalog includes data resource types, data item information, whether registration has been completed, data classification information, etc.; this step mainly solves the problem of data resource update lag.

[0087] Further, step S1 includes:

[0088] Step S11: Establish a public data resource catalog synchronization mechanism:

[0089] The public data platform deploys a scheduled task (such as CronJob) and triggers the directory synchronization engine to perform the following operations at 00:00 every day: (1) Call the GET / metadata interface opened by the public data platform to obtain the full public data resource directory and status identifier (including is_new for new and is_deprecated for delisting); (2) Persist the directory data to the local authorized directory database, with fields including resource_id, resource_name, status, and last_sync_time; (3) Mark delisted resources as status=INACTIVE and new resources as status=ACTIVE.

[0090] Step S12: Implement strong linkage between directory status and authorization process through the policy execution engine. The specific linkage control rules are shown in Table 1.

[0091] Table 1. Interlocking Control Rules

[0092]

[0093] Step S13: Execute the reverse control process:

[0094] When the public data platform initiates a resource removal operation, it pre-calls the resource occupancy query interface of the authorized operation platform; (1) If authorized_count>0 is returned, the removal is blocked and the error code ERR_DEPRECATE_BLOCKED is returned, and an alternative solution application work order is generated at the same time; (2) If authorized_count=0 is returned, the removal is allowed immediately.

[0095] Step S2: The data source department applies to add the catalog of data resources that cannot be authorized by the department to the negative list on the authorized operation platform. Data resources added to the negative list cannot be authorized. This step mainly breaks through the dilemma of not daring to authorize.

[0096] Further, step S2 includes:

[0097] Step S21: Use the audit workflow engine to drive the automated process of application-audit-execution; based on BPMN2.0 standard modeling, integrate electronic signature to verify the identity of the auditor, and store audit records on the blockchain to carry out the process of application to be added to the negative list-audit-approval-successful addition to the negative list;

[0098] Step S22: Use a state synchronizer to link the negative list and authorization policy in real time; use a publish-subscribe pattern to push a ResourceStatusChangeEvent to the policy execution engine when the negative list is updated, so as to achieve dynamic updates of the negative list.

[0099] Specifically, the BLOCKED / ACTIVE status flags enable atomic switching of resources between the negative list and the licenable pool; status changes trigger real-time hot updates (taking effect in milliseconds) of the policy execution engine, which avoids the drawback of traditional solutions requiring downtime for maintenance;

[0100] Step S23: Use the policy execution engine to dynamically manage authorization behavior based on a negative list, and add verification rules in the agreement creation / data request stage, for example... The statement `IF resource_id IN negative_list_db THEN DISABLE` is used to prevent the use of data catalog resources in the negative list.

[0101] Step S3: The implementing agency files the authorization operation agreement on the authorized operation platform; the authorization operation agreement should clearly specify the authorized operation agency, the scope of authorized data, the authorization period, and the authorization mode; this step mainly eliminates the problem of conflicting authorization periods at the N-level.

[0102] Further, step S3 includes:

[0103] Step S31: The implementing agency (such as a government department) creates and files an authorized operation agreement through the agreement management module of the authorized operation platform. This authorized operation agreement includes the following constraint fields:

[0104] Authorized Entity Binding Field: Specifies the identifier of the authorized operating organization (such as the organization ID);

[0105] Data range whitelist field: Defines the set of data resources that can be authorized (such as "Medical Insurance Database A, Social Security Database B").

[0106] Time-limited control field: Sets the authorization validity period (e.g., start and end timestamps);

[0107] Authorization mode identifier field: declares the data usage rules (e.g., "de-identification processing only");

[0108] Step S32: After the authorized operation agreement is filed, the policy execution engine of the authorized operation platform automatically performs the following dynamic control:

[0109] (1) Application scope constraint: When the operating institution initiates a resource request through the data application interface of the authorized operating platform, the system calls the data scope whitelist field in the authorized operating agreement in real time to forcibly limit the range of optional data resources, so that it can only select the datasets in the whitelist (such as prohibiting the selection of the unauthorized "Tax Treasury Table C").

[0110] (2) Authorization time limit interception mechanism: When the policy execution engine receives the application request, it automatically verifies the matching of the current timestamp with the time limit control field in the protocol: if the application time is within the validity period, the application is allowed to be submitted; if the validity period is exceeded, the protocol expiration interceptor is triggered, an error code is returned and the process is terminated.

[0111] Step S4: The operating organization creates an application scenario on the authorized operation platform, applies for data resource authorization based on the authorized data scope stipulated in the authorized operation agreement in step S3, and develops and generates preliminary data products. The usage period is the authorization period stipulated in the authorized operation agreement in step S3.

[0112] Further, step S4 includes:

[0113] Step S41, Application Scenario Creation and Protocol Resource Loading: The operating organization creates an application scenario (such as a smart medical diagnostic model) on the authorized operation platform. The system automatically generates a globally unique scenario identifier code Scene_ID. The system automatically loads the authorized data range specified in the authorized operation agreement signed with the operating organization through the protocol parsing engine, and performs real-time filtering at the same time.

[0114] Step S42: Request for protocol resource authorization based on scene identifier:

[0115] Within the authorized data scope stipulated in the authorized operation agreement, the operating organization selects the data resources to be applied for. When submitting the application, the system automatically generates a structured application document (including application scenario description and resource ID list) and triggers a multi-level review workflow engine. Based on the applied data resources identified in the current scenario, the system performs the following technical controls:

[0116] Resource application scenario binding: The application form automatically embeds the hidden field Scene_ID, which is verified by the backend through a request interceptor; when the applied resource has been authorized based on a certain scenario and needs to be used in a new scenario, the application review process also needs to be triggered, and manual review is carried out again based on the new application scenario to prevent the abuse of data resources;

[0117] Step S43, Injecting Authorized Resources into the Data Development Platform: After both levels of review are passed, the system performs the following automated operations: (1) Dynamic credential generation: Create a time-limited access token for each authorized resource, with the validity period bound to the protocol expiration time; (2) Sandbox resource mounting: Mount the authorized resource to the independent container sandbox of the data development platform in the form of an encrypted volume; (3) Lifecycle timer start: Register a resource recycling task in the scheduled task service, with the trigger time being the protocol expiration time;

[0118] Step S44, Development Environment Data Product Generation: Within the container sandbox of the data development platform, the operating organization accesses authorized resources through a secure computing engine (such as a TEE trusted execution environment), and uses SQL / Spark tools to generate preliminary data products. When the preliminary data products are output, data lineage tags (recording the original resource ID and processing path) are automatically attached.

[0119] Step S45, Lifecycle Expiration Warning:

[0120] Thirty days before the agreement expires, the system automatically triggers an early warning mechanism: sending system message notifications and SMS reminders to the operating organization through the message distribution service;

[0121] Step S46, Automatic Resource Recycling: When the agreement expires, the system performs an atomic recycling operation; unloads the sandbox resource volume, freezes intermediate data products, recycles the temporary Fanwei token, and updates the authorization state machine;

[0122] Step S47, Post-recycling audit trail: The system generates a resource recycling audit report and archives it automatically. The report includes: statistics on actual resource usage time, number of data products generated and their storage locations, and integrity check value (SHA-256 digest) of sandbox operation logs.

[0123] Further, step S42 includes:

[0124] (1) Scene identifier code generation and binding mechanism: The scene identifier code is constructed by the triple Scene_ID=Org_ID+SceneType_Hash+Timestamp, which serves as the primary key index in the entire process of data application, development and auditing;

[0125] (2) Cross-scenario resource usage control: When a resource reuse request is detected, it is automatically upgraded to an enhanced approval process. At the same time, the development environment is forced to be physically isolated, including allocating an independent Docker container for each Scene_ID.

[0126] (3) Contextualized data lineage tracing: All initial processed data products are marked with<Scene_ID,Resource_ID> Two data lineage tags are used to accurately track which scenario the data comes from and which scenario it is used in.

[0127] Step S5: After selecting a development agency based on the application scenario, the operating agency shall file a development agreement on the authorized operation platform. The development agreement shall clearly specify the authorized development agency, the authorized application scenario, the authorization period, and the authorized initial data products. The authorization period for the development agency shall not exceed the authorization period for the original data resources in the authorized operation agreement in step S3.

[0128] Further, step S5 includes:

[0129] Step S51, Development Agreement Filing:

[0130] The operating organization submits the development organization filing application on the authorized operation platform; including: (1) Scene binding verification: The system verifies the application scene to which the development organization belongs through the scene identifier verifier. The application scene to which the development organization belongs is consistent with the original resource authorization scene; (2) Development agreement generation: Generate a structured development agreement. The key fields include the name of the development organization, the binding scene table, the agreement period, and the list of authorized initial processing data product IDs;

[0131] Step S52, Authorization Period Cascading Control:

[0132] The system automatically executes a term inheritance algorithm to ensure that the authorization period of the development organization does not exceed the original data authorization period; the original data resource authorization period is the authorization validity period of the authorization operation agreement in step S31; the specific method is as follows:

[0133] (1) Tracing the origin of primary processed data products: The system automatically parses the original authorization link of the selected primary processed data products;

[0134] (2) Aggregation calculation of original authorization period: Extract all associated original authorization periods, obtain the original authorization time window corresponding to each initial processing data product through the authorization link tracing engine, and calculate the effective range of development period: Use the time window intersection and union algorithm to determine the time boundary allowed by the development agreement;

[0135] (3) Dynamic verification of development period: When the operating organization submits a development period request, the system performs verification to check whether it exceeds the minimum and maximum time period. If it does not exceed the time period, the save is successful; otherwise, the save fails.

[0136] Step S6: The operating organization further refines the authorization of the initial processed data products, clarifying the specific data items, fields, and return parameters to be given to the corresponding development organization for each initial processed data product based on the application scenario; and further controls the scope of authorization.

[0137] Further, step S6 includes:

[0138] Step S61: The operating organization performs field-level authorization on the initial processed data products; first, the data product metadata is parsed: the field metadata of the initial processed data products is automatically extracted through the product structure parsing engine;

[0139] Step S62, Field-level authorization strategy configuration: Use a visual authorization configurator to achieve fine-grained control, display the security classification and grading of data fields, and manually select data with low sensitivity for authorization;

[0140] Step S63: Create an isolated, refined sandbox environment for the development organization, and automatically generate a field filtering view based on the location of the authorized fields; if data is provided through the API, the system automatically injects a parameter permission validator; when calling the API to request an unauthorized field, an error is returned.

[0141] The present invention also provides a multi-level refined public data resource authorization control method system based on an authorization protocol, the system comprising: a module for executing the multi-level refined public data resource authorization control method based on the authorization protocol.

[0142] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the multi-level refined public data resource authorization control method based on the licensing protocol.

[0143] To verify the effectiveness of the present invention, the present invention has the following implementation effects as shown in Table 2:

[0144] Table 2 shows the implementation effects of the present invention.

[0145]

[0146] This invention has the following technical advantages:

[0147] 1. Process Compliance: The negative list level-one review complies with the "Trial Measures for the Authorization and Operation Management of a Certain Public Data Resource"; the flexible term agreement meets the authorization requirements of case-by-case discussion;

[0148] 2. Lightweight technology: After removing the blockchain, the system throughput increased by 300% (TPS from 127 to 512), and the operation and maintenance cost was reduced by 60% (no need to maintain the node cluster).

[0149] 3. Security is still guaranteed: Database transaction logs ensure traceability of operations (retention period ≥ 5 years).

[0150] The following explanation uses authorization control in a financial risk control scenario as an example.

[0151] Suppose a public data platform authorizes medical insurance database data to operating institution A. Under the normal authorization model, the following problems may occur:

[0152] 1. Risk of full access: Operating institution A obtains the entire medical insurance form (including 218 fields such as ID number and genetic disease history) at once, and development institution B obtains full access to the form through a sub-protocol;

[0153] 2. Expiration Date Vulnerability: The original license period expires on December 31, 2025. If the development agreement is mistakenly set to June 30, 2026, the system will have no restrictions and it may be difficult to detect.

[0154] 3. Scenario generalization and abuse: Development agency B used the data for unauthorized "commercial insurance sales", and sensitive fields were copied and spread.

[0155] The proposed solution enables layered management: In the first stage, through step S2, resource-level negative list management is implemented. The data source department adds the entire "Gene Testing Result Table" to the negative list (resource level). When operating institution A creates an agreement, this table is automatically removed from the optional list (the strategy engine intercepts in real time). In the second stage, through steps S4 to S6, field-level dynamic convergence is achieved. The operating institution creates a "Financial Risk Control" scenario for application. According to the constraints of step S4, only the two non-sensitive tables, "Insured Status" and "Contribution Base," in the medical insurance database are selected. Then, a preliminary product, "Insured Person Credit Benchmark Table" (containing 15 fields), is generated in the encrypted sandbox. According to step 6, when the operating institution authorizes A to provide the preliminary product to the development institution, the development institution only obtains the three selected fields (credit rating, contribution base, and insured status). In the third stage, based on step S5, a time-limit circuit breaker can be implemented. If the development agreement is mistakenly filled with 2026-06-30, the system will verify the parent agreement's time limit (2025-12-31) in real time. The front end will immediately disable the submit button and prompt "The end date exceeds the parent agreement by 183 days". The actual security effect is shown in Table 3.

[0156] Table 3 Comparison of Safety Effects

[0157]

[0158] This invention uses S2 to block the entire table (such as a gene detection table) at the resource level; and uses S6 to achieve granular control of fields (such as hiding genetic disease history fields) at the post-processing level.

[0159] This invention achieves a gradual convergence of data access surfaces by using the process of "full database table → negative list filtering → scenario-based table selection → initial processing products → field-level authorization," reducing the data access surface from 218 fields to 3 fields, which aligns with the principle of minimizing the processing steps layer by layer.

[0160] The specific embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of the present invention.

Claims

1. A multi-level, refined public data resource authorization control method based on authorization protocols, characterized in that: The method includes: Step S1: Periodically synchronize the public data resource catalog from the public data platform to the authorized operation platform; Step S2: The data source department applies to add the catalog of data resources that cannot be authorized by the department to the negative list on the authorized operation platform. Data resources added to the negative list cannot be authorized. Step S3: The implementing agency files the authorization operation agreement on the authorized operation platform; the authorization operation agreement shall clearly specify the authorized operation agency, the scope of authorized data, the authorization period, and the authorization model. Step S4: The operating organization creates an application scenario on the authorized operation platform, applies for data resource authorization based on the authorized data scope stipulated in the authorized operation agreement in step S3, and develops and generates preliminary data products. The usage period is the authorization period stipulated in the authorized operation agreement in step S3. Step S5: After selecting a development agency based on the application scenario, the operating agency shall file a development agreement on the authorized operation platform. The development agreement shall clearly specify the authorized development agency, the authorized application scenario, the authorization period, and the authorized initial data products. The authorization period for the development agency shall not exceed the authorization period for the original data resources in the authorized operation agreement in step S3. Step S6: The operating organization further refines the authorization of the initial processed data products, clarifying the specific data item fields and return parameters to the corresponding development organization for each initial processed data product based on the application scenario; and further controlling the scope of authorization. Step S4 includes: Step S41, Application Scenario Creation and Protocol Resource Loading: The operating organization creates an application scenario on the authorized operation platform, and the system automatically generates a globally unique scene identifier code Scene_ID; the system automatically loads the authorized data range specified in the authorized operation agreement signed with the operating organization through the protocol parsing engine, and performs real-time filtering at the same time; Step S42: Request for protocol resource authorization based on scene identifier: The operating organization selects the data resources to be applied for within the authorized data scope specified in the authorized operation agreement. When submitting the application, the system automatically generates a structured application document and triggers a multi-level review workflow engine. Based on the applied data resources identified in the current scenario, the system performs the following technical controls: Resource application scenario binding: The application form automatically embeds the hidden field Scene_ID, which is verified by the backend through a request interceptor; when the applied resource has been authorized based on a certain scenario and needs to be used in a new scenario, the application review process also needs to be triggered, and manual review is carried out again based on the new application scenario to prevent the abuse of data resources; Step S6 includes: Step S61: The operating organization performs field-level authorization on the initial processed data products; first, the data product metadata is parsed: the field metadata of the initial processed data products is automatically extracted through the product structure parsing engine; Step S62, Field-level authorization strategy configuration: Use a visual authorization configurator to achieve fine-grained control, display the security classification and grading of data fields, and manually select data with low sensitivity for authorization; Step S63: Create an isolated, refined sandbox environment for the development organization, and automatically generate a field filtering view based on the location of the authorized fields; if data is provided through the API, the system automatically injects a parameter permission validator; when calling the API to request an unauthorized field, an error is returned.

2. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: Step S1 includes: Step S11: Establish a public data resource catalog synchronization mechanism: The public data platform deploys a scheduled task scheduler, which triggers the directory synchronization engine to perform the following operations at a specified time each day: (1) Call the GET / metadata interface opened by the public data platform to obtain the full public data resource directory and status identifier; (2) Persist the directory data to the local authorized directory database, with fields including resource_id, resource_name, status, last_sync_time; (3) Mark the delisted resources as status=INACTIVE and the newly added resources as status=ACTIVE. Step S12: Implement strong linkage between directory status and authorization process through the policy execution engine; Step S13: Execute the reverse control process: When the public data platform initiates a resource removal operation, it pre-calls the resource occupancy query interface of the authorized operation platform; (1) If authorized_count>0 is returned, the removal is blocked and the error code ERR_DEPRECATE_BLOCKED is returned, and an alternative solution application work order is generated at the same time; (2) If authorized_count=0 is returned, the removal is allowed immediately.

3. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: Step S2 includes: Step S21: Use the audit workflow engine to drive the automated process of application-audit-execution; based on BPMN2.0 standard modeling, integrate electronic signature to verify the identity of the auditor, and store audit records on the blockchain to carry out the process of application to be added to the negative list-audit-approval-successful addition to the negative list; Step S22: Use a state synchronizer to link the negative list and authorization policy in real time; use a publish-subscribe pattern to push a ResourceStatusChangeEvent to the policy execution engine when the negative list is updated, so as to achieve dynamic updates of the negative list. Specifically, the BLOCKED / ACTIVE status flags enable atomic switching of resources between the negative list and the licenable pool; status changes trigger real-time hot updates of the policy execution engine to avoid the downtime maintenance required by traditional solutions. Step S23: Use the strategy execution engine to dynamically manage authorization behavior based on the negative list, and add verification rules in the agreement creation / data application stage to achieve the effect of not being able to use the data catalog resources in the negative list.

4. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: Step S3 includes: Step S31: The implementing agency creates and files an authorization operation agreement through the agreement management module of the authorization operation platform. This authorization operation agreement includes the following constraint fields: Authorization Entity Binding Field: Specifies the identifier of the authorized operating organization; Data range whitelist field: Defines the set of data resources that can be authorized; Time-limited control field: Sets the authorization validity period; Authorization pattern identifier field: declares the rules for data usage; Step S32: After the authorized operation agreement is filed, the policy execution engine of the authorized operation platform automatically performs the following dynamic control: (1) Application scope constraint: When the operating institution initiates a resource request through the data application interface of the authorized operation platform, the system calls the data scope whitelist field in the authorized operation agreement in real time to forcibly limit the range of optional data resources, so that it can only select the datasets in the whitelist; (2) Authorization time limit interception mechanism: When the policy execution engine receives the application request, it automatically verifies the matching of the current timestamp with the time limit control field in the protocol: if the application time is within the validity period, the application is allowed to be submitted; if the validity period is exceeded, the protocol expiration interceptor is triggered, an error code is returned and the process is terminated.

5. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: Step S4 further includes: Step S43, Injecting Authorized Resources into the Data Development Platform: After both levels of review are approved, the system performs the following automated operations: (1) Dynamic Credential Generation: Create a time-sensitive access token for each authorized resource, with the validity period bound to the protocol expiration time; (2) Sandbox Resource Mounting: Mount the authorized resource to the independent container sandbox of the data development platform in the form of an encrypted volume; (3) Lifecycle Timer Startup: Register a resource recycling task in the scheduled task service, with the trigger time being the protocol expiration time; Step S44: Data product generation in the development environment: Within the container sandbox of the data development platform, the operating organization accesses authorized resources through the secure computing engine and uses SQL / Spark tools to generate preliminary data products. Data lineage tags are automatically attached when the preliminary data products are output. Step S45, Lifecycle Expiration Warning: Thirty days before the agreement expires, the system automatically triggers an early warning mechanism: sending system message notifications and SMS reminders to the operating organization through the message distribution service; Step S46, Automatic Resource Recycling: When the agreement expires, the system performs an atomic recycling operation; unloads the sandbox resource volume, freezes intermediate data products, recycles the temporary Fanwei token, and updates the authorization state machine; Step S47, Post-recycling audit trail: The system generates a resource recycling audit report and archives it automatically. The report includes: statistics on actual resource usage time, number of data products generated and their storage location, and integrity verification values ​​of sandbox operation logs.

6. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 5, characterized in that: Step S42 includes: (1) Scene identifier code generation and binding mechanism: The scene identifier code is constructed by the triple Scene_ID=Org_ID+SceneType_Hash+Timestamp, which serves as the primary key index in the entire process of data application, development and auditing; (2) Cross-scenario resource usage control: When a resource reuse request is detected, it is automatically upgraded to an enhanced approval process. At the same time, the development environment is forced to be physically isolated, including allocating an independent Docker container for each Scene_ID. (3) Contextualized data lineage tracing: All initial processed data products are marked with<Scene_ID, Resource_ID> Two data lineage tags are used to accurately track which scenario the data comes from and which scenario it is used in.

7. The multi-level refined public data resource authorization control method based on authorization protocols according to claim 1, characterized in that: Step S5 includes: Step S51, Development Agreement Filing: The operating organization submits the development organization filing application on the authorized operation platform; including: (1) Scene binding verification: The system verifies the application scene to which the development organization belongs through the scene identifier verifier. The application scene to which the development organization belongs is consistent with the original resource authorization scene; (2) Development agreement generation: Generate a structured development agreement. The key fields include the name of the development organization, the binding scene table, the agreement period, and the list of authorized initial processing data product IDs; Step S52, Authorization Period Cascading Control: The system automatically executes a term inheritance algorithm to ensure that the authorization period for the development organization does not exceed the original data authorization period; the original data resource authorization period is the validity period of the authorization operation agreement; the specific method is as follows: (1) Tracing the origin of primary processed data products: The system automatically parses the original authorization link of the selected primary processed data products; (2) Aggregation calculation of original authorization period: Extract all associated original authorization periods, obtain the original authorization time window corresponding to each initial processing data product through the authorization link tracing engine, and calculate the effective range of development period: Use the time window intersection and union algorithm to determine the time boundary allowed by the development agreement; (3) Dynamic verification of development period: When the operating organization submits a development period request, the system performs verification to check whether it exceeds the minimum and maximum time period. If it does not exceed the time period, the save is successful; otherwise, the save fails.

8. A multi-level refined public data resource authorization control method system based on authorization protocols, characterized in that, The system includes a module for executing the multi-level refined public data resource authorization control method based on an authorization protocol as described in any one of claims 1 to 7.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the multi-level refined public data resource authorization control method based on the authorization protocol as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Authorization authentication method and device under cross-channel multi-service scene

    CN116405290A

  • Operation system and method for digital transformation project

    CN120725490A