Shared file storage method based on dynamic authority autonomy and electronic equipment

By using a shared file storage method with dynamic permission autonomy, the system enters a member autonomy state after the initial administrator account expires. Each member can create a new account, and data sharing is authorized by the owner. This solves the risk of privacy leakage for super administrators and achieves absolute protection of user privacy and flexible sharing.

CN121935968APending Publication Date: 2026-04-28HUNAN HAISEN INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUNAN HAISEN INTELLIGENT TECHNOLOGY CO LTD
Filing Date
2026-03-09
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing shared file storage systems rely on a super administrator account with the highest privileges, which makes user privacy and security dependent on the administrator's moral constraints, posing a serious risk of privacy leaks, and making users hesitant to fully utilize backup and sharing functions.

Method used

By constructing a shared file storage method with dynamic permission autonomy, the initial administrator account immediately loses access to the user's storage space after creating the first system member account. The system then enters a member autonomy state, where each member can create new accounts, and data sharing is actively authorized by the data owner, forming a decentralized permission network.

Benefits of technology

It completely eliminates the possibility of super administrators accessing user privacy data without authorization, enhances users' sense of security, and achieves absolute privacy protection and a flexible file sharing mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121935968A_ABST
    Figure CN121935968A_ABST
Patent Text Reader

Abstract

The invention discloses a shared file storage method based on dynamic authority autonomy and electronic equipment, and relates to the technical field of data storage and privacy protection. The shared file storage method based on dynamic authority autonomy comprises the following steps that a system is activated and initialized through a unique initial administrator account; creating a first system member account through the initial administrator account; after the first system member account is successfully created, immediately enabling the access, viewing and management authority of the initial administrator account to all user member storage spaces to be invalid; afterwards, the system enters a member autonomous state, and any existing system member account has the authority of creating a new system member account. According to the method, through the dynamic permission failure and member autonomy mechanism, it is ensured that private data of the user cannot be checked by any super administrator at will from the system design level, and the use security of the user is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data storage and privacy protection technology, and in particular to a shared file storage method and electronic device based on dynamic permission autonomy. Background Technology

[0002] With the increasing demand for data storage and sharing among families and small businesses, shared file storage systems such as NAS have become widely used. However, existing systems of this type generally employ a static super administrator (SuperAdministrator)-based permission model. During system initialization, a super administrator account with supreme privileges, such as admin, is created. This administrator can access, view, modify, and even delete all users' files within the system without restriction, including sensitive content such as personal photo albums, documents, and backup data.

[0003] This architecture leads to serious privacy risks and psychological barriers. In a family setting, members (such as spouses and children) are hesitant to fully utilize the NAS's backup and sharing functions for fear that their personal phone backups, private photos, or files will be viewed by other members through the administrator's account. In small and medium-sized enterprises or teams, employees similarly worry that their work documents and private data will be spied on by the system administrator. User privacy and security essentially depend entirely on the personal integrity and ethics of the system's initial setup person or administrator, which in itself constitutes a huge security vulnerability and design flaw.

[0004] While some existing technologies focus on protecting data through hardware encryption modules or complex software encryption algorithms, such as NAS encrypted storage systems, these solutions primarily address the issue of preventing data from being cracked on the storage medium itself. They do not challenge or change the fundamental system architecture premise of a supreme super administrator. User privacy remains exposed to the administrator with the highest privileges. Therefore, the market urgently needs an innovative solution that can fundamentally reconstruct the permission model from the system design level, completely eliminating the problem of super administrator privacy abuse. Summary of the Invention

[0005] To address the aforementioned issues, this application provides a shared file storage method and electronic device based on dynamic permission autonomy. By constructing a decentralized and egalitarian member autonomy structure, it ensures from the system architecture level that each user's private data is only visible to themselves, thereby improving privacy and security.

[0006] The first technical solution adopted in this application is: providing a shared file storage method based on dynamic permission autonomy, including the following steps: The system is activated and initialized using a unique initial administrator account; The first system member account is created using the initial administrator account; Immediately after the first system member account is successfully created, the initial administrator account's access, viewing, and management permissions for all user member storage spaces are invalidated. After this, the system enters a state of member autonomy, where any existing system member account has the permission to create new system member accounts.

[0007] In an optional embodiment, after the system enters a member autonomy state, the personal storage space and its internal data of each system member account are not visible to all other system member accounts and the initial administrator account by default; data sharing can only be achieved by the holder of the account to which the data belongs performing an active authorization operation.

[0008] In an optional embodiment, the invalidation of the initial administrator account's permissions is permanent; after the initial administrator account's permissions are invalidated, it retains only basic system management functions unrelated to personal user data or enters a completely disabled state.

[0009] In an optional embodiment, after the system enters a member autonomy state, any system member account also has the permission to create guest accounts.

[0010] In an alternative embodiment, the guest account's functional permissions are restricted, including the inability to use the data backup function and the inability to create new folders in the storage space.

[0011] In an optional embodiment, the access permissions of the guest account are actively granted by the system member who created the guest account, and are limited to specific shared folders that are invited to join or specific files that are directly shared.

[0012] In an optional embodiment, the active authorization operation implements sharing in the following ways: System members move or copy their private files to a shared folder and authorize specific other member accounts to access that shared folder; or, System members can use the system's sharing function to generate access links for specific files or directly authorize access to other member accounts.

[0013] In an optional embodiment, the access rights of a system member account or guest account that has been granted access can be revoked by the system member who granted the authorization.

[0014] In an optional embodiment, the condition for restoring the full permissions of the initial administrator account is that all accounts created by members within the system are deactivated.

[0015] The second technical solution adopted in this application is: providing an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements the shared file storage method based on dynamic permission autonomy as described above.

[0016] Due to the adoption of the above technical solution, this application has at least one of the following beneficial effects compared with the prior art: 1. By implementing dynamic permission expiration and member self-governance mechanisms, the system design ensures that users' private data cannot be viewed arbitrarily by any super administrator, thus enhancing users' sense of security.

[0017] 2. While absolutely protecting personal privacy, it perfectly supports normal file collaboration and temporary sharing needs through proactive sharing, shared folders, and restricted guest account functions.

[0018] 3. Achieve the goal through innovative design of permission logic, without the need for complex hardware encryption modules or high-strength cryptographic calculations, thus reducing costs. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 A flowchart illustrating a shared file storage method based on dynamic permission autonomy provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of an embodiment of the electronic device of this application. Detailed Implementation

[0020] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It is understood that the specific embodiments described herein are only for explaining this application and not for limiting it. Furthermore, it should be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all structures. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0021] The terms "first," "second," etc., used in this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0022] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0023] In existing technologies, shared file storage systems such as Network Attached Storage (NAS) generally rely on a single super administrator account with the highest privileges for centralized management. This account can access all users' private data without restriction, causing users to be hesitant to fully utilize backup and sharing functions due to the risk of privacy breaches. This centralized permission model entrusts user data security to the moral constraints of the administrator, lacking fundamental technical guarantees.

[0024] In view of this, the shared file storage method based on dynamic permission autonomy proposed in this application permanently revokes the initial administrator's access, viewing, and management permissions to the user's storage space immediately after the creation of the first system member account, and delegates the right to create members to all members, thus constructing a decentralized autonomous architecture. This completely eliminates the possibility of a super administrator unauthorized access to user privacy data from the source of system design. Figure 1 As shown, Figure 1 A flowchart illustrating a shared file storage method based on dynamic permission autonomy provided in an embodiment of this application includes the following steps: The system is activated and initialized using a unique initial administrator account; The first system member account is created using the initial administrator account; Immediately after the first system member account is successfully created, the initial administrator account's access, viewing, and management permissions for all user member storage spaces are disabled. After this, the system enters a state of member autonomy, where any existing system member account has the permission to create new system member accounts.

[0025] In this embodiment, the system initialization process is completed by a unique initial administrator account (e.g., "admin"). This account is enabled after the device's first boot or system reset and is responsible for initialization operations such as network configuration, storage pool setup, and basic service startup. After initialization is complete, the initial administrator account performs the creation of the first system member account. For example, in a home NAS scenario, the father uses the "admin" account to create the account "mother" for the mother.

[0026] The critical turning point occurs the instant the first system member account is successfully created. The system automatically triggers a permission invalidation mechanism, stripping the initial administrator account of access, viewing, and management permissions for all user storage spaces. This means that even if the "admin" account still exists, it can no longer browse, download, modify, or delete any member's personal files. At this point, the system enters a state of member autonomy; management permissions are no longer centralized in a single account but distributed among all existing members. Each member has the permission to create new members, forming a decentralized permission network. For example, the mother can continue to create an account "son" for her son, and the son can create accounts for visitors; the permission transfer chain extends naturally without the intervention of a centralized administrator.

[0027] In summary, the shared file storage method based on dynamic permission autonomy in this embodiment includes the following steps: the system is activated and initialized using a unique initial administrator account; the first system member account is created using the initial administrator account; immediately after the first system member account is successfully created, the initial administrator account's access, viewing, and management permissions for all user member storage spaces are invalidated; thereafter, the system enters a member autonomy state, where any existing system member account has the permission to create new system member accounts. This application, through dynamic permission invalidation and member autonomy mechanisms, ensures from a system design perspective that users' private data cannot be arbitrarily viewed by any super administrator, enhancing user security.

[0028] Once the system enters a member-autonomous state, each system member account's personal storage space and its internal data are not visible to any other system member account or the initial administrator account by default; data sharing can only be achieved through active authorization by the holder of the account to which the data belongs.

[0029] Each member account has its own independent personal storage space (such as / home / mother, / home / son). The system ensures that its content is completely isolated from all other accounts by default through access control lists (ACLs) or encrypted storage technology. This means that without explicit authorization, no account can list, read or write other people's private files.

[0030] Sharing must be initiated by the data owner. The system provides two main sharing methods: Shared folder mechanism: Users can move or copy files to a shared folder (such as family photos) and specify which members have access rights.

[0031] Direct file sharing: Users can generate a sharing link through the system or directly authorize specific members to obtain temporary or permanent access.

[0032] This approach ensures users have absolute control over their own data, fundamentally eliminating the risk of privacy leaks.

[0033] The initial administrator account's permissions are permanently invalidated; after the initial administrator account's permissions are invalidated, it will only retain basic system management functions unrelated to personal user data or be completely disabled.

[0034] The expiration of privileges is permanent and irreversible; after expiration, the initial administrator account may retain the following basic system management functions: Check the system's running status (CPU, memory, network usage); Manage storage pools and monitor hard drive health; Configure network settings (IP, DNS, SMB / AFP protocol); View system logs (system events only, excluding user operation logs).

[0035] Alternatively, depending on the system configuration, the account can be completely disabled and unable to log in, serving only as a backup identity during system recovery; this ensures system maintainability while completely eliminating the possibility of the super administrator accessing user data without authorization.

[0036] After the system enters a state of member autonomy, any system member account also has the permission to create guest accounts.

[0037] Guest accounts have limited access permissions, including the inability to use data backup and the inability to create new folders in storage space.

[0038] Access permissions for guest accounts are granted by the system member who created the guest account and are limited to specific shared folders that the guest is invited to join or specific files that are directly shared.

[0039] To facilitate temporary collaboration, the system allows any member to create a guest account. A guest account is a temporary account with restricted permissions, characterized by: Functionality limitations: The phone / PC backup function cannot be used, and new folders cannot be created in the storage space to prevent abuse of storage resources or data intrusion.

[0040] Access restrictions: Guest account access permissions are precisely controlled by the creator, allowing access only to explicitly authorized shared folders or files. For example, a mother could create a guest account "guest1" and only allow it access to the "Family Travel Plans" folder.

[0041] Temporary: Guest accounts can be set to have an expiration date, which will automatically expire, further ensuring system security.

[0042] This design protects core privacy while providing flexible, temporary sharing capabilities, making it suitable for scenarios such as home visitors and project collaborations.

[0043] The methods for achieving sharing through proactive authorization include: System members move or copy their private files to a shared folder and authorize specific other member accounts to access that shared folder; or, System members can use the system's sharing function to generate access links for specific files or directly authorize access to other member accounts.

[0044] The access permissions granted to a system member account or guest account can be revoked by the system member who granted the permission.

[0045] The sharing mechanism is designed to be bidirectionally controllable. Users can choose to move files to a shared folder and invite other members to add the folder to their access list. The system supports dynamically updating the access list, allowing users to add or remove members at any time.

[0046] Another way is to generate a shareable link, which can be password-protected, have an expiration date, and have access limits, making it suitable for temporary or external sharing.

[0047] The permission revocation function is a crucial part of privacy control. Authorizers can revoke an account's access to a specific folder or file at any time via the system interface with a single click. The changes take effect immediately, without waiting for a synchronization period. This ensures users maintain continuous control over shared content.

[0048] The conditions for restoring full privileges to the initial administrator account are: all accounts created by members within the system must be deactivated.

[0049] The restoration of initial administrator privileges is designed as a strict and rarely triggered system reset operation. The restoration condition is that all accounts created by members in the system (including system member accounts and guest accounts) have voluntarily logged out. This means that initial administrator privileges can only be restored when all users actively leave the system (e.g., all family members move out, or the business project ends).

[0050] The recovery process is automatically triggered: after the system detects the last member account has been logged out, it automatically sends a permission restoration notification to the initial administrator account, or directly grants it full permissions. This mechanism ensures that the system maintains its decentralized nature throughout its lifecycle, only reverting to a centralized management model during a complete reset.

[0051] Regarding the above embodiments, this application provides an electronic device; please refer to [link / reference]. Figure 2 , Figure 2 This is a schematic diagram of the structure of an embodiment of the electronic device of this application. The computer device includes a memory and a processor, wherein the memory and the processor are coupled to each other. The memory stores program data, and the processor executes the program data to implement the steps of any embodiment of the shared file storage method based on dynamic permission autonomy described above.

[0052] In this embodiment, the processor may also be referred to as a CPU (Central Processing Unit). The processor may be an integrated circuit chip with signal processing capabilities. The processor may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.

[0053] In the several embodiments provided in this application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0054] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0055] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0056] The above description is merely an embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A shared file storage method based on dynamic permission autonomy, characterized in that, Includes the following steps: The system is activated and initialized using a unique initial administrator account; The first system member account is created using the initial administrator account; Immediately after the first system member account is successfully created, the initial administrator account's access, viewing, and management permissions for all user member storage spaces are invalidated. After this, the system enters a state of member autonomy, where any existing system member account has the permission to create new system member accounts.

2. The method according to claim 1, characterized in that, After the system enters a member-autonomous state, the personal storage space and its internal data of each system member account are not visible to all other system member accounts and the initial administrator account by default; data sharing can only be achieved by the holder of the account to which the data belongs performing an active authorization operation.

3. The method according to claim 1, characterized in that, The invalidation of the initial administrator account's permissions is permanent; after the initial administrator account's permissions are invalidated, it will only retain basic system management functions unrelated to personal user data or will be completely disabled.

4. The method according to claim 1 or 2, characterized in that, After the system enters a state of member autonomy, any system member account also has the permission to create guest accounts.

5. The method according to claim 4, characterized in that, The guest account's functional permissions are restricted, including the inability to use the data backup function and the inability to create new folders in the storage space.

6. The method according to claim 4, characterized in that, Access permissions for the guest account are granted by the system member who created the guest account, and are limited to specific shared folders that the guest is invited to join or specific files that are directly shared.

7. The method according to claim 2, characterized in that, The methods for implementing sharing through the proactive authorization operation include: System members move or copy their private files to a shared folder and authorize specific other member accounts to access that shared folder; or, System members can use the system's sharing function to generate access links for specific files or directly authorize access to other member accounts.

8. The method according to claim 7, characterized in that, The access permissions granted to a system member account or guest account can be revoked by the system member who granted the permission.

9. The method according to claim 1, characterized in that, The conditions for restoring the full permissions of the initial administrator account are: all accounts created by members within the system are cancelled.

10. An electronic device, characterized in that, It includes a memory and a processor, the memory storing a computer program that, when executed by the processor, implements the method as described in any one of claims 1 to 9.