Data asset management system and method, computer equipment and storage medium

By classifying and grading data assets and managing access requests and approvals, the problem of low efficiency in access management in existing technologies has been solved, thereby improving the security and operational efficiency of data assets.

CN121959530APending Publication Date: 2026-05-01RICHFIT INFORMATION TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RICHFIT INFORMATION TECH
Filing Date
2024-10-31
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

When managing large and complex data assets, existing technologies often result in inefficient access control, high error rates, and reduced data asset security due to role-based authorization methods.

Method used

This paper provides a data asset management system that classifies and manages data assets by means of an asset permission basic module, management module, display module, and application and approval module. It supports the display of different types of data asset catalogs and permission application and approval, and uses the coding system of institutions and users for precise control.

Benefits of technology

It simplifies data asset access control operations, improves management efficiency, ensures data asset security, and guarantees that logged-in users can view and operate on data with valid permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121959530A_ABST
    Figure CN121959530A_ABST
Patent Text Reader

Abstract

The invention provides a data asset management system and method, computer equipment and a storage medium, and belongs to the technical field of computers. Through the asset authority basic module, the asset authority management module, the asset authority display module, the asset authority application approval module and other modules in the system, basic data needing authority management in the system can be synchronized, and data assets are subjected to classification and level-to-level management; according to the method, the corresponding data asset catalog is displayed under each data asset type, and authority application and authority approval are performed on different types of data assets, so that accurate control of different types of asset authorities on corresponding control is realized, the operation is simplified, the efficiency of asset authority management on the data assets is improved, and the user experience is improved. And moreover, the security of the data assets is ensured, and the login user can be ensured to check and operate the asset data with the effective authority.
Need to check novelty before this filing date? Find Prior Art

Description

Data asset management system, methods, computer equipment and storage media Technical Field

[0001] This application relates to the field of computer technology, and in particular to a data asset management system, method, computer device and storage medium. Background Technology

[0002] With the development of computer technology, the intelligent management of enterprise data assets is also gradually evolving. Data assets are a core intrinsic resource of an enterprise and are crucial to its development. In this context, asset access management of data assets is related to their security and is a problem that needs to be addressed.

[0003] Currently, the common approach is to fix data assets and assign roles to each user. When a user is assigned a role, they can access the data assets with corresponding permissions; when a user is not assigned a role, they cannot access the data assets with corresponding permissions. Traditional role-based authorization allows different users to access data assets with different permissions.

[0004] However, as the quantity and types of data assets gradually expand, more roles are needed to further refine permissions, leading to a gradual increase in the number of roles assigned to users. When the quantity and types of data assets become too large and complex, the above methods become inefficient for managing asset permissions, increasing the error rate and reducing the security of data assets. Summary of the Invention

[0005] This application provides a data asset management system, method, computer equipment, and storage medium that classifies and hierarchically manages data assets. This not only simplifies operations and improves the efficiency of asset access management but also ensures data asset security and guarantees that logged-in users can view and operate on asset data with existing valid permissions. The technical solution is as follows:

[0006] On the one hand, a data asset management system is provided, which includes an asset permission basic module, an asset permission management module, an asset permission display module, and an asset permission application and approval module; wherein,

[0007] The asset access control module is used to synchronize the basic data that needs to be managed for asset access control. The basic data includes data sources, metadata, institutional data, and user data.

[0008] The asset access management module is used to classify and manage data assets. The types of data assets can be extended. The hierarchy of data assets is the level under the category to which the data asset belongs. The data assets belong to an organization, and each organization has at least one of a parent organization and a child organization.

[0009] The asset permission display module is used to display the corresponding data asset catalog under each type of data asset;

[0010] The asset permission application and approval module is used to apply for and approve asset permissions for different types of data assets. Different types of data assets have different application pages, and the application input items displayed on different application pages are not exactly the same. The administrator of any organization can use it to approve the permissions of the organization's data assets.

[0011] In some embodiments, the asset access control module includes a data source management module, a metadata management module, an organization management module, and a user management module; wherein,

[0012] The data source management module is used to synchronize the data source information for asset access management in the data asset management system;

[0013] The metadata management module is used to synchronize the metadata corresponding to the data source information under the corresponding data architecture based on the data source information. The metadata includes technical metadata, business metadata, and management metadata.

[0014] The organization management module is used to synchronize the organizations that manage asset permissions in the data asset management system. Different organizations have different organization codes.

[0015] The user management module is used to synchronize users who manage asset permissions in the data asset management system. Different users have different employee codes, and each user's individual organization code is the organization code of the organization to which the user belongs.

[0016] In some embodiments, when any data asset is a relational data table, the metadata corresponding to the data asset includes database metadata, table metadata, and column metadata.

[0017] In some embodiments, the asset access management module includes an asset classification module, an asset management module, and an asset administrator module; wherein,

[0018] The asset classification module is used to classify and manage data assets in different dimensions, and the different dimensions are used to indicate different indicators of data assets.

[0019] The asset management module is used to manage the asset permissions of different types of data assets. Each data asset can be set as a public data asset or a non-public data asset. The public data assets are data assets that users have asset permissions for by default, and the non-public data assets are data assets that users do not have asset permissions for by default.

[0020] The asset administrator module is used to manage at least one administrator for each institution, and the administrator is used to approve asset permission applications for the non-public data assets.

[0021] In some embodiments, when any data asset is of type first relational data table, the administrator of the data asset is the administrator of the institution to which the data asset belongs; when any data asset is of type second relational data table, the administrator of the data asset includes the administrator of at least one conditional institution corresponding to the data asset, the conditional institution being used to manage the asset permissions of the data in the data asset.

[0022] In some embodiments, the asset access control module includes an asset catalog module, an asset access control determination module, and an asset physical data module; wherein,

[0023] The asset catalog module is used to display data asset catalogs of different types of data assets. Each data asset catalog includes the data asset name of the corresponding type of data asset.

[0024] The asset catalog module is also used to respond to a trigger operation on the data asset name of any data asset and display the asset details page of the data asset. Different types of data assets correspond to different asset details pages. The asset catalog module displays different asset details pages for the same data asset to users with different existing valid asset permissions.

[0025] The asset permission determination module is used to determine the existing valid asset permissions of the logged-in user. The existing valid asset permissions of the logged-in user are the valid asset permissions of the logged-in user, the valid asset permissions of the institution to which the logged-in user belongs, and the valid asset permissions of all the parent institutions of the institution.

[0026] The asset physical data module is used for the physical storage of data assets in the data asset management system.

[0027] In some embodiments, when any data asset is a relational data table, the asset catalog module is used to display sampled data on the asset details page of the data asset for logged-in users with valid permissions. The sampled data is table data in the relational data table for which the logged-in user has valid permissions.

[0028] In some embodiments, the asset access application and approval module includes an access application verification module, an asset access approval module, and an application and approval display module; wherein...

[0029] The permission application verification module is used to verify the asset permission for any data asset among different types of non-public data assets. The asset permission application is used to indicate the application object and the asset permission applied for by the application object. The application object includes at least one of users and institutions. The non-public data asset is a data asset that users do not have asset permissions for by default.

[0030] The asset permission approval module is used to initiate an application flow and enter the asset permission approval process when the asset permission application has passed the asset permission verification. The asset permission approval process includes at least one approval node, and each approval node is used by at least one administrator to approve the asset permission application. The application flow is used to instruct the logged-in user to initiate an asset permission application for the data asset for the application object. The logged-in user may be the same as or different from the application object.

[0031] The asset permission approval module is also used to end the approval node if any administrator corresponding to the approval node approves the asset permission application.

[0032] The application approval display module is used to display corresponding record information for each logged-in user. The record information includes application record information, pending approval record information, and approved record information. The application record information is the record information of resource permission applications initiated by the logged-in user. The pending approval record information is the record information of resource permission applications that need to be approved by the administrator after logging in. The approved record information is the record information of resource permission applications that have been approved by the currently logged-in administrator.

[0033] In some embodiments, the permission request verification module includes an asset permission request module and an asset permission verification module; wherein,

[0034] The asset permission application module is used by the logged-in user to initiate an asset permission application for the data asset for the application object;

[0035] The asset permission verification module is used to determine the existing valid asset permissions of the applicant, and to perform asset permission verification based on the existing valid asset permissions and the asset permissions applied for by the applicant.

[0036] In some embodiments, when the applicant is a user, the existing valid asset permissions of the applicant are the valid asset permissions of the applicant, the valid asset permissions of the institution to which the applicant belongs, and the valid asset permissions of all parent institutions of the institution; when the applicant is an institution, the existing valid asset permissions of the applicant are the valid asset permissions of the applicant and the valid asset permissions of all parent institutions of the applicant.

[0037] In some embodiments, when the applicant is making an asset permission application for the data asset for the first time, the asset permission verification module is used to determine that the asset permission application has passed the asset permission verification; when the applicant is not making an asset permission application for the data asset for the first time, the asset permission verification module is used to determine whether the asset permission application has passed the asset permission verification based on the expiration date of the existing valid asset permission indication and the expiration date of the asset permission indication applied for by the applicant.

[0038] In some embodiments, the application approval display module includes an application display module, a pending approval display module, and an approved approval display module; wherein...

[0039] The application display module is used to display asset permission applications initiated by the logged-in user to the logged-in user. The application display module is also used by the logged-in user to cancel unapproved asset permission applications.

[0040] The pending approval display module is used to display asset permission applications pending approval to the administrator. The pending approval display module is also used by the administrator to approve the pending asset permission applications one by one or in batches.

[0041] The approved display module is used to show administrators approved asset permission applications.

[0042] On the other hand, an asset access management method is provided, applied to a data asset management system. The data asset management system includes an asset access basic module, an asset access management module, an asset access display module, and an asset access application and approval module. The method includes:

[0043] The asset access control module synchronizes the basic data that needs to be managed for asset access control. The basic data includes data sources, metadata, institutional data, and user data.

[0044] The asset access management module is used to classify and manage data assets. The types of data assets can be expanded. The hierarchy of data assets is the level under the category in which the data asset belongs. The data assets belong to an organization, and each organization has at least one of parent organization and child organization.

[0045] The asset permission display module displays the corresponding data asset catalog under each type of data asset.

[0046] The asset permission application and approval module allows for the application and approval of permissions for different types of data assets. Different types of data assets have different application pages, and the application input items displayed on different application pages are not exactly the same. Administrators of any organization can use this module to approve permissions for the organization's data assets.

[0047] In some embodiments, the asset access control module includes a data source management module, a metadata management module, an organization management module, and a user management module; the synchronization of basic data requiring asset access control through the asset access control module includes:

[0048] The data source management module synchronizes the data source information for asset access management in the data asset management system.

[0049] Through the metadata management module, based on the data source information, the metadata corresponding to the data source information is synchronized under the corresponding data architecture. The metadata includes technical metadata, business metadata, and management metadata.

[0050] Through the institution management module, the institutions that manage asset permissions in the data asset management system are synchronized, and different institutions have different institution codes.

[0051] The user management module synchronizes users who manage asset permissions in the data asset management system. Different users have different employee codes, and each user's individual organization code is the organization code of the organization to which the user belongs.

[0052] In some embodiments, when any data asset is a relational data table, the metadata corresponding to the data asset includes database metadata, table metadata, and column metadata.

[0053] In some embodiments, the asset access management module includes an asset classification module, an asset management module, and an asset administrator module; the step of classifying and hierarchically managing data assets through the asset access management module includes:

[0054] The asset classification module allows for the classification and hierarchical management of data assets across different dimensions, with each dimension indicating a different indicator of the data asset.

[0055] The asset management module manages the asset permissions of different types of data assets. Each data asset can be set as a public data asset or a non-public data asset. Public data assets are data assets that users have asset permissions for by default, while non-public data assets are data assets that users do not have asset permissions for by default.

[0056] The asset administrator module manages at least one administrator for each organization, who is responsible for approving asset permission applications for the non-public data assets.

[0057] In some embodiments, when any data asset is of type first relational data table, the administrator of the data asset is the administrator of the institution to which the data asset belongs; when any data asset is of type second relational data table, the administrator of the data asset includes the administrator of at least one conditional institution corresponding to the data asset, the conditional institution being used to manage the asset permissions of the data in the data asset.

[0058] In some embodiments, the asset access control module includes an asset catalog module, an asset access control module, and an asset physical data module; the step of displaying the corresponding data asset catalog under each type of data asset through the asset access control module includes:

[0059] The asset catalog module displays data asset catalogs for different types of data assets, with each data asset catalog including the data asset name for the corresponding type of data asset.

[0060] Through the asset catalog module, in response to a trigger operation on the name of any data asset, the asset details page of the data asset is displayed. Different types of data assets correspond to different asset details pages. The asset catalog module displays different asset details pages for the same data asset to users with different existing valid asset permissions.

[0061] The asset permission determination module determines the existing valid asset permissions of the logged-in user. The existing valid asset permissions of the logged-in user are the valid asset permissions of the logged-in user, the valid asset permissions of the institution to which the logged-in user belongs, and the valid asset permissions of all parent institutions of the institution.

[0062] The physical data module is used to physically store the data assets in the data asset management system.

[0063] In some embodiments, when any data asset is a relational data table, the asset catalog module is used to display sampled data on the asset details page of the data asset for logged-in users with valid permissions. The sampled data is table data in the relational data table for which the logged-in user has valid permissions.

[0064] In some embodiments, the asset permission application and approval module includes a permission application verification module, an asset permission approval module, and an application and approval display module; the process of applying for and approving asset permissions for different types of data assets through the asset permission application and approval module includes:

[0065] The permission application verification module verifies the asset permission for any data asset among different types of non-public data assets. The asset permission application is used to indicate the application object and the asset permission applied for by the application object. The application object includes at least one of users and institutions. The non-public data asset is a data asset that users do not have asset permissions for by default.

[0066] Through the asset permission approval module, if the asset permission application has passed the asset permission verification, an application flow is initiated to enter the asset permission approval process. The asset permission approval process includes at least one approval node. Each approval node is used by at least one administrator to approve the asset permission application. The application flow is used to instruct the logged-in user to initiate an asset permission application for the data asset for the application object. The logged-in user may be the same as or different from the application object.

[0067] Through the asset permission approval module, for any approval node, if any administrator corresponding to the approval node approves the asset permission application, the approval node is terminated.

[0068] The application approval display module displays corresponding record information for each logged-in user. The record information includes application record information, pending approval record information, and approved record information. The application record information is the record information of resource permission applications initiated by the logged-in user. The pending approval record information is the record information of resource permission applications that need to be approved by the administrator after logging in. The approved record information is the record information of resource permission applications that have been approved by the currently logged-in administrator.

[0069] In some embodiments, the permission application verification module includes an asset permission application module and an asset permission verification module; the step of verifying asset permission applications for any data asset among different types of non-public data assets through the permission application verification module includes:

[0070] Through the asset permission application module, the logged-in user initiates an asset permission application for the data asset for the application object;

[0071] The asset permission verification module determines the existing valid asset permissions of the applicant and performs asset permission verification based on the existing valid asset permissions and the asset permissions applied for by the applicant.

[0072] In some embodiments, when the applicant is a user, the existing valid asset permissions of the applicant are the valid asset permissions of the applicant, the valid asset permissions of the institution to which the applicant belongs, and the valid asset permissions of all parent institutions of the institution; when the applicant is an institution, the existing valid asset permissions of the applicant are the valid asset permissions of the applicant and the valid asset permissions of all parent institutions of the applicant.

[0073] In some embodiments, when the applicant is making an asset permission application for the data asset for the first time, the asset permission verification module is used to determine that the asset permission application has passed the asset permission verification; when the applicant is not making an asset permission application for the data asset for the first time, the asset permission verification module is used to determine whether the asset permission application has passed the asset permission verification based on the expiration date of the existing valid asset permission indication and the expiration date of the asset permission indication applied for by the applicant.

[0074] In some embodiments, the application approval display module includes an application display module, a pending approval display module, and an approved display module; displaying corresponding record information for each logged-in user through the application approval display module includes:

[0075] The application display module displays asset permission applications initiated by the logged-in user to the logged-in user. The application display module is also used by the logged-in user to cancel asset permission applications that have not been approved.

[0076] The pending approval display module displays asset permission applications that are pending approval to the administrator. The pending approval display module is also used by the administrator to approve the pending asset permission applications one by one or in batches.

[0077] The approved asset permission application is displayed to the administrator through the approved display module.

[0078] On the other hand, a computer device is provided, the computer device including a processor and a memory, the memory being used to store at least one computer program, the at least one computer program being loaded and executed by the processor to implement the asset access management method in the embodiments of this application.

[0079] On the other hand, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer-readable storage medium, and the at least one computer program is loaded and executed by a processor to implement the asset access management method in the embodiments of this application.

[0080] On the other hand, a computer program product is provided, including a computer program that is executed by a processor to implement the asset access management method in the embodiments of this application.

[0081] This application provides a data asset management system. Through multiple modules, including a basic asset permission module, an asset permission management module, an asset permission display module, and an asset permission application and approval module, the system can synchronize basic data requiring permission management and classify and manage data assets hierarchically. Each data asset type displays a corresponding data asset catalog. After clicking on an asset name to enter the asset details page, the page displays the corresponding type's public and individual asset information. Different asset types support viewing or operating existing valid permission data, as well as applying for and approving permissions for different types of data assets. This achieves precise control over permissions for different types of assets, simplifying operations, improving the efficiency of data asset permission management, ensuring data asset security, and guaranteeing that logged-in users can view and operate asset data with existing valid permissions. Attached Figure Description

[0082] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0083] Figure 1 is an architecture diagram of a data asset management system provided according to an embodiment of this application;

[0084] Figure 2 is a flowchart of a data asset management method according to an embodiment of this application;

[0085] Figure 3 is a schematic diagram of an asset rights calculation according to an embodiment of this application;

[0086] Figure 4 is a schematic diagram of an asset application permission verification method according to an embodiment of this application;

[0087] Figure 5 is a schematic diagram of the structure of a terminal according to an embodiment of this application;

[0088] Figure 6 is a schematic diagram of the structure of a server provided according to an embodiment of this application. Detailed Implementation

[0089] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0090] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items with essentially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor are there any restrictions on quantity or execution order.

[0091] In this application, the term "at least one" means one or more, and "multiple" means two or more.

[0092] It should be noted that all information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in this application have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the data assets, data source information, metadata, institutional data, and user data involved in this application were all obtained with full authorization.

[0093] Figure 1 is an architecture diagram of a data asset management system according to an embodiment of this application. Referring to Figure 1, the data asset management system includes an asset permission basic module 101, an asset permission management module 102, an asset permission display module 103, and an asset permission application and approval module 104.

[0094] For example, the data asset management system adopts a B / S (Browser / Server) architecture, using Spring Boot as the development framework and Tomcat or Docker as the deployment medium. The browser / server architecture eliminates the need for users to install additional applications locally; they can access the server and retrieve its results directly through a browser, simplifying client-side complexity. Using Tomcat or Docker as the deployment medium makes system deployment, expansion, and management simpler and more efficient.

[0095] Optionally, the data asset management system can be deployed in a distributed cluster or on a single machine. In a distributed cluster deployment, the system can be deployed on multiple servers, improving system availability and scalability; in a single machine deployment, the system can be deployed on a single server, simplifying the deployment and management process.

[0096] The asset permission basic module 101 is used to synchronize the basic data that needs to be managed for asset permissions. The basic data includes data sources, metadata, institutional data, and user data. The asset permission management module 102 is used to classify and manage data assets. The types of data assets can be extended. The hierarchy of data assets is the level under the category in which the data asset belongs. Data assets belong to institutions, and each institution has at least one of parent and child institutions. The asset permission display module 103 is used to display the corresponding data asset catalog under each type of data asset. The asset details page displays the public information and individual information of the corresponding type of asset. The asset permission application and approval module 104 is used to apply for and approve asset permissions for different types of data assets. Different types of data assets have different application pages. The application input items displayed on different application pages are not exactly the same. The administrator of any institution is used to approve the permissions of the institution's data assets.

[0097] In addition, the data asset access control module also includes database 105. Database 105 stores data from the data asset management system, including at least basic asset access data, asset access management data, and asset access application and approval data. For example, database 105 uses MySQL. MySQL supports distributed and clustered deployments, allowing for flexible scaling of database performance and capacity as needed. MySQL provides various security mechanisms, such as data encryption and access control, to protect database security, which will not be elaborated upon here.

[0098] The asset access control module 101 includes a data source management module 1011, a metadata management module 1012, an organization management module 1013, and a user management module 1014. Accordingly, the data source management module 1011 synchronizes the data source information for asset access control in the data asset management system; the metadata management module 1012 synchronizes the metadata corresponding to the data source information under the corresponding data architecture, including technical metadata, business metadata, and management metadata; the organization management module 1013 synchronizes the organizations for asset access control in the data asset management system, with different organizations corresponding to different organization codes; and the user management module 1014 synchronizes the users for asset access control in the data asset management system, with different users corresponding to different employee codes, and each user's individual organization code being the organization code of the organization to which the user belongs.

[0099] The asset access management module 102 includes an asset classification module 1021, an asset management module 1022, and an asset administrator module 1023. Accordingly, the asset classification module 1021 is used to classify and manage data assets according to different dimensions, with each dimension indicating different indicators of the data assets. The asset management module 1022 is used to manage asset permissions for different types of data assets. Each data asset can be set as a public or non-public data asset. Public data assets are those for which users have default access rights, while non-public data assets are those for which users do not have default access rights. The asset administrator module 1023 is used to manage at least one administrator for each organization, who is responsible for approving asset permission applications for non-public data assets.

[0100] The asset access control module 103 includes an asset catalog module 1031, an asset access control module 1032, and an asset physical data module 1033. Accordingly, the asset catalog module 1031 displays data asset catalogs for different types of data assets, each catalog including the data asset name of the corresponding type. The asset catalog module 1031 also displays the asset details page of any data asset in response to a trigger operation on the data asset name. Different types of data assets correspond to different asset details pages, and the asset details pages displayed for the same data asset by users with different existing valid asset access rights are not entirely the same. The asset access control module 1032 determines the existing valid asset access rights of logged-in users. The existing valid asset access rights of logged-in users are the summed and merged valid asset access rights of the logged-in user, the valid asset access rights of the user's organization, and the valid asset access rights of all parent organizations of the organization. The asset physical data module 1033 is used for the physical storage of data assets in the data asset management system.

[0101] The asset permission application and approval module 104 includes a permission application verification module 1041, an asset permission approval module 1042, and an application and approval display module 1043. Accordingly, the permission application verification module 1041 verifies the asset permissions for any data asset application among different types of non-public data assets. The asset permission application indicates the applicant and the requested asset permissions. The applicant includes at least one of users and institutions. Non-public data assets are data assets for which users do not have asset permissions by default. The asset permission approval module 1042 initiates an application flow and enters the asset permission approval process after the asset permission application has passed the asset permission verification. The asset permission approval process includes at least one approval node, where each approval node is used by at least one administrator to approve the asset permission application. The application flow indicates the logged-in user's application for the requested asset. The process for applying for asset permissions for data assets can involve the same or different logged-in users and applicants. The asset permission approval module 1042 is also used to end the approval node when any administrator at the corresponding approval node approves the asset permission application. The application approval display module 1043 is used to display corresponding record information for each logged-in user. The record information includes application record information, pending approval record information, and approved record information. The application record information is the record information of resource permission applications initiated by the logged-in user. The pending approval record information is the record information of resource permission applications that need to be approved by the administrator after logging in. The approved record information is the record information of resource permission applications that have been approved by the currently logged-in administrator.

[0102] The permission application verification module 1041 includes an asset permission application module 1045 and an asset permission verification module 1046. Accordingly, the asset permission application module 1045 is used by the logged-in user to initiate an asset permission application for a data asset for the applicant; the asset permission verification module 1046 is used to determine the applicant's existing valid asset permissions and perform asset permission verification based on the existing valid asset permissions and the asset permissions applied for by the applicant.

[0103] The application approval display module 1043 includes an application display module 1047, a pending approval display module 1048, and an approved display module 1049. Accordingly, the application display module 1047 displays asset permission applications initiated by logged-in users, and is also used by logged-in users to cancel unapproved asset permission applications; the pending approval display module 1048 displays pending asset permission applications for administrators, and is also used by administrators to approve pending asset permission applications individually or in batches; the approved display module 1049 displays approved asset permission applications for administrators.

[0104] This application provides a data asset management system. Through multiple modules, including a basic asset permission module, an asset permission management module, an asset permission display module, and an asset permission application and approval module, the system can synchronize basic data requiring permission management and classify and manage data assets hierarchically. Each data asset type displays a corresponding data asset catalog. After clicking on an asset name to enter the asset details page, the page displays the corresponding type's public and individual asset information. Different asset types support viewing or operating existing valid permission data, as well as applying for and approving permissions for different types of data assets. This achieves precise control over permissions for different types of assets, simplifying operations, improving the efficiency of data asset permission management, ensuring data asset security, and guaranteeing that logged-in users can view and operate asset data with existing valid permissions.

[0105] It should be noted that the data asset management system provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the system can be divided into different functional modules to complete all or part of the functions described above. In addition, the data asset management system provided in the above embodiments and the asset access management method embodiments described below belong to the same concept. The data asset management system provided in the above embodiments is applicable to the following method embodiments. Similarly, the specific implementation process of the data asset management system provided in the above embodiments can be found in the following method embodiments, and will not be repeated here.

[0106] Figure 2 is a flowchart of a data asset management method according to an embodiment of this application. This method is applied to a data asset management system, which includes an asset permission basic module, an asset permission management module, an asset permission display module, and an asset permission application and approval module. Referring to Figure 2, the method includes the following steps:

[0107] 201. Through the asset access control module, synchronize the basic data that needs to be managed for asset access control. The basic data includes data sources, metadata, institutional data and user data.

[0108] In this embodiment, the asset permission basic module is the module that synchronizes the basic data corresponding to data asset permissions within the system. Accordingly, the asset permission basic module is used to synchronize data sources, metadata, organizational data, and user data that require asset permission management. Based on the synchronized data sources, the corresponding metadata is synchronized under the corresponding data architecture. This metadata includes different types of technical metadata, business metadata, and management metadata, such as relational data tables, files, reports, and analytical data. Relational data table metadata includes database metadata, table metadata, and column metadata; column metadata can be configured with permission-related settings. Each user belongs to a single organization or department. Organizations have hierarchical relationships. Subordinate organizations inherit asset permissions from their superior organizations by default. A user's existing valid asset permissions are the summed and merged valid asset permissions of the user themselves, the valid asset permissions of the user's organization, and the valid asset permissions of all parent organizations of that organization. Metadata, users, and organizations all have unique codes.

[0109] It should be noted that this system, based on different types of asset access control, greatly simplifies and facilitates asset access management, significantly reduces the corresponding development workload and costs, and improves the efficiency of asset access control. The asset types in this system are expandable, capable of meeting the needs of business development.

[0110] The following section provides a detailed introduction to the basic asset permissions module.

[0111] In some embodiments, the asset access control module includes a data source management module, a metadata management module, an organization management module, and a user management module. Accordingly, the method for synchronizing the basic data for asset access control through each module in the asset access control module is shown in (1-1) to (1-4) below.

[0112] (1-1) Synchronize the data source information that requires asset access management in the data asset management system through the data source management module.

[0113] The data source indicates the origin of data in the data asset management system. The above method ensures a successful connection for subsequent metadata synchronization. Optionally, this system supports various operations such as adding, editing, deleting, and querying data source information, which will not be elaborated here. This system employs data security protection strategies for usernames and passwords, such as encrypted storage and access control, to ensure that this information is not obtained by unauthorized users, thereby guaranteeing data security.

[0114] (1-2) Through the metadata management module, based on the data source information, the metadata corresponding to the data source information is synchronized under the corresponding data architecture.

[0115] Metadata has a unique code, ensuring data uniqueness, consistency, and traceability. This system supports various operations on metadata, including adding, modifying, deleting, querying, and enabling / disabling. It also supports manual addition and automatic synchronization of metadata.

[0116] Metadata includes technical metadata, business metadata, and management metadata. For example, technical metadata describes the storage structure and format of the data; business metadata describes the business meaning, purpose, and rules of the data; and management metadata describes the management information of the data, such as accessible users, accessible organizations, and storage periods. It should be noted that the above metadata is merely illustrative and does not constitute a limitation.

[0117] The metadata originates from relational data tables, files, reports, and analytical data. Correspondingly, data asset types include relational data tables, files, reports, and analytical data. A relational data table refers to a data structure stored in tabular form. For example, each row represents an entity, and each column represents an attribute. Accordingly, each row corresponds to a record, and each column corresponds to a dimension or metric. Analytical data refers to data obtained through the ETL (Extract-Transform-Load) data integration process. It should be noted that the above-mentioned metadata sources and corresponding data asset types are merely illustrative examples; those skilled in the art can set, adjust, and extend them as they see fit, without limitation.

[0118] In some embodiments, when any data asset is a relational data table, the metadata corresponding to the data asset includes database metadata, table metadata, and column metadata. That is, relational data table metadata includes database metadata, table metadata, and column metadata. Column metadata can be associated with permission-related settings, dimensions / metrics / standards, quality information, and security information. Typically, the permission-related settings associated with column metadata indicate that permissions are irrelevant by default. It should be noted that the content of the relational data table metadata and the information associated with the column metadata are merely illustrative examples, and those skilled in the art can adjust and extend them; no limitations are imposed here.

[0119] (1-3) Through the institution management module, synchronize the institutions in the data asset management system that need to be subject to asset access management.

[0120] Each organization has a unique organization code and sequence number; different organizations correspond to different organization codes. This system supports various operations such as adding, modifying, deleting, querying, and enabling / disabling organizations.

[0121] In this context, "organization" refers to a physical entity, and hierarchical relationships exist between organizations. For example, the organizational hierarchy, from highest to lowest, is: group, unit, and department. Subordinate organizations inherit asset permissions from their superior organizations by default. An organization's existing valid asset permissions are the combined valid asset permissions of the organization itself and all its parent organizations.

[0122] (1-4) Synchronize users who need to manage asset permissions in the data asset management system through the user management module.

[0123] Each user has a unique employee code and belongs to only one organization, such as only one department. Different users have different employee codes, and each user's individual organization code is the organization code of the organization to which the user belongs. This system supports various operations for users, including adding, modifying, deleting, querying, enabling / disabling, assigning roles, and resetting passwords.

[0124] By default, users inherit the asset permissions of their own organization. The user's existing valid asset permissions are the combined valid asset permissions of the user, the valid asset permissions of the user's own organization, and the valid asset permissions of all parent organizations above the user.

[0125] 202. Through the asset access management module, data assets are classified and managed hierarchically. The types of data assets can be extended and set. The hierarchy of data assets is the level under the category in which the data asset belongs. Data assets belong to an organization, and any organization has at least one of the parent organization and child organizations.

[0126] In this embodiment, the asset access control module is the module in this system that manages data asset permissions. Accordingly, the asset access control module is used to manage permissions for different types of data assets. Data assets are managed hierarchically under different data asset classifications, supporting different types such as relational data tables, files, reports, and analytical data. Each data asset has a unique code, belongs to a unique organization, and can be set to be public or private. Relational data tables are divided into permission-independent and permission-dependent types; relational data tables require selecting the database / table and setting permission-related parameters for columns. Files, reports, and analytical data require corresponding operations such as uploading files. The organization to which the data asset belongs sets up corresponding administrators according to designated rules to approve applications for permissions to non-public data assets.

[0127] It should be noted that this system, based on different types of asset access control, greatly simplifies and facilitates asset access management, significantly reduces the corresponding development workload and costs, and improves asset access control efficiency. The asset types in this system are expandable to meet business development needs. The asset access administrator's rules are flexible, supporting multiple administrator approvals, satisfying enterprise business operation mechanisms, and improving processing efficiency.

[0128] The asset access control module will be described in detail below.

[0129] In some embodiments, the asset access management module includes an asset classification module, an asset management module, and an asset administrator module. Accordingly, the method for classifying and hierarchically managing data assets through the asset access management module is shown in (2-1) to (2-3) below.

[0130] (2-1) Data assets are classified and managed in different dimensions through the asset classification module.

[0131] Different dimensions are used to indicate different metrics of data assets. This system supports various operations such as adding, editing, and deleting data assets. Through these methods, the efficiency of data asset management is improved, and data asset management needs are met.

[0132] (2-2) The asset management module manages the asset permissions of different types of data assets.

[0133] Each data asset has a unique code and belongs to only one organization, such as a department or unit. Different data assets have different codes, and the individual organization code for each data asset is the organization code of the organization to which the data asset belongs. This system supports various operations such as adding, editing, deleting, and querying data assets.

[0134] Data assets include various types such as relational tables, files, reports, and analytical data. A single data asset can belong to multiple asset categories simultaneously. Different data asset categories display corresponding data asset lists; that is, different data asset types correspond to different data asset lists. This enables the categorized management of data assets.

[0135] Data assets can be configured to be public or private. Accordingly, data assets are divided into public and private data assets. Public data assets are those to which users have default access rights, while private data assets are those to which users do not have default access rights. Relational data tables are further divided into permission-independent and permission-dependent types. For relational data table types, it must be determined whether the data asset is permission-dependent.

[0136] Data assets of various types, such as files, reports, and analytical data, require file uploads and other corresponding operations. Relational data table assets require selecting the database, table, and setting permissions for the columns. Optionally, after selecting a relational data table, relevant technical, business, quality, and security information can be displayed.

[0137] (2-3) The asset administrator module manages at least one administrator for each institution.

[0138] Each organization owning a data asset has a designated administrator. Administrators are responsible for approving asset access requests for non-public data assets. An organization can have multiple administrators, and one administrator can be responsible for multiple organizations. Multiple administrators can be assigned to the same organization to approve access to non-public data assets under that organization; a single administrator can approve access to non-public data assets under multiple organizations. This system supports various operations for administrators, including adding, modifying, deleting, and querying them.

[0139] In some embodiments, the rules for assigning administrators differ for different types of data assets. Accordingly, when any data asset is a first relational data table, the administrator of the data asset is the administrator of the organization to which the data asset belongs; when any data asset is a second relational data table, the administrator of the data asset includes the administrator corresponding to at least one conditional organization of the data asset. The conditional organization is used to manage asset permissions for row data in the permission-related relational data table. The same relational data table may correspond to one or more conditional organizations; there is no restriction on this.

[0140] The first relational data table is a permission-independent relational data table, while the second relational data table is a permission-dependent relational data table. For various data assets such as permission-independent relational data tables, files, reports, and analytical data, the administrator is the administrator of the organization to which the data asset belongs. For permission-dependent relational data tables, the administrator includes the administrator corresponding to the organization to which the data asset is located.

[0141] 203. Through the asset permission display module, the corresponding data asset catalog is displayed under each type of data asset. When the data asset name is clicked, the asset details page is displayed, which displays the public information and personalized information of the corresponding type of asset.

[0142] In this embodiment, the asset permission display module is the module in this system that displays data asset permissions. Accordingly, the asset permission display module is used to display permissions for different types of data assets. Data asset catalogs are displayed hierarchically under different dimensions of data asset classification. Upon clicking on a data asset name, the user enters the asset details page, displaying the corresponding type of asset's public and individual information, and supporting viewing or operating on asset data with existing valid permissions calculated from the asset permission calculation. Specifically, for public data assets, logged-in users have full permissions by default; for non-public data assets, logged-in users have no asset permissions by default, and must apply for and obtain approval to retain valid permissions. During permission calculation, the system queries, summarizes, and merges to obtain the logged-in user's final existing valid asset permissions.

[0143] It should be noted that this system uses a concise and visually appealing asset catalog to richly display details of different types of assets, facilitating the viewing and manipulation of asset data with existing valid permissions, thus improving information display efficiency and human-computer interaction efficiency. The system possesses powerful asset permission calculation capabilities, enabling rapid merging and calculation of asset permissions for logged-in users, their affiliated institutions, and all their parent institutions, resulting in high data processing efficiency.

[0144] The asset access control module is described in detail below.

[0145] In some embodiments, the asset permission display module includes an asset catalog module, an asset permission determination module, and an asset physical data module. Accordingly, this system uses the asset permission display module to display the corresponding data asset catalog under each type of data asset, and displays the corresponding type of asset public information and asset individual information on the asset details page, as shown in (3-1) to (3-3) below.

[0146] (3-1) The asset catalog module displays the data asset catalog of different types of data assets; the asset catalog module responds to the trigger operation of the data asset name of any data asset in the data asset catalog and displays the asset details page of the data asset.

[0147] Each data asset catalog includes the name of the corresponding data asset type. Data asset types include relational tables, files, reports, analytical data, and various other extensible types. By concisely and visually displaying the corresponding data asset catalogs under different data asset categories and automatically updating them based on the data assets, the system achieves categorized management of data assets.

[0148] Different types of data assets correspond to different asset detail pages. The information on these pages differs depending on the type of data asset. Furthermore, for the same data asset, the asset detail page displayed to the logged-in user will vary depending on whether the user has valid permissions. This system allows logged-in users to view public and personalized information about data assets on the asset detail page, as well as view and download asset data for which they already have valid permissions.

[0149] For ease of description, the information on the asset details page of a data asset is divided into public asset information and individual asset information. The public asset information and individual asset information are described below.

[0150] Public asset information is the information displayed on the asset details page for each type of data asset. It can also be referred to as public content in the asset details. Public asset information typically includes basic information about the data asset. For example, it may include the asset name, asset code, number of views, tags, organization, view type, description, and asset type.

[0151] Different types of data assets have different asset-specific information. For example, for relational data table type data assets, asset-specific information includes data source, column information, sampled data, lineage analysis, impact analysis, end-to-end analysis, and comments. Column information displays the technical and business information of the columns; sampled data is table data that logged-in users have valid permissions to view, and the display order of sampled data is consistent with the actual order; the number of sampled data entries displayed can be controlled through configuration; lineage analysis indicates the data source of the relational data table, i.e., upstream data; impact analysis indicates the data used in the relational data table, i.e., downstream data; end-to-end analysis includes both lineage analysis and impact analysis. For example, for data assets of the file, report, and analysis data types, asset-specific information includes overview, name, size, type, download count, storage location, and comments. The asset details page supports logged-in users to download asset data with valid permissions.

[0152] In general, public relational tables grant users full permissions by default. Non-public relational tables grant users no permissions by default. Relational tables are categorized as permission-independent or permission-dependent. Typically, relational tables are permission-independent by default. Specifically, for non-public, permission-independent relational tables, users can view all columns with valid permissions; that is, if a user has valid permissions for a column in the table, they can view all data in that column. For non-public, permission-dependent relational tables, users can view rows and columns with valid permissions; that is, if a user has valid permissions for a column in the table and also has valid row permissions related to that permission, they can view the rows in that column with valid permissions, but cannot view rows in that column without valid permissions.

[0153] In some embodiments, when any data asset is a relational data table, the asset catalog module is used to display sampled data on the asset details page of the data asset for logged-in users with valid permissions. The sampled data is table data in the relational data table for which the logged-in user has valid permissions.

[0154] (3-2) The asset permission determination module determines the existing valid asset permissions of the logged-in user. These permissions are a consolidated version of the logged-in user's existing valid asset permissions, the valid asset permissions of the user's organization, and the valid asset permissions of all parent organizations. The logged-in user can access asset data with existing valid permissions on the asset details page of the data asset. Typically, the system performs permission calculations on the data asset before the logged-in user views or operates on the data asset details page. Alternatively, the system performs permission calculations in response to a triggered operation on the data asset name of any data asset in the data asset catalog. No specific limitation is specified here.

[0155] The rules for calculating permissions differ depending on the level of public access and the type of data assets. Data assets are divided into public data assets and non-public data assets. For public data assets, logged-in users have full permissions by default and can access the data of the assets they have permission to access normally. For non-public assets, logged-in users do not have permissions by default and must apply for and have their permissions approved and kept valid before they can gain access.

[0156] During permission calculation, the system queries the logged-in user, their affiliated organization, and all existing valid asset permissions of their parent organizations, then aggregates and merges these permissions to obtain the logged-in user's final valid asset permissions. In other words, the permission calculation process refers to the process of calculating permissions for the data assets accessed by the logged-in user. This process includes steps such as querying and aggregating to determine the logged-in user's final valid asset permissions, and based on this, whether the logged-in user has the right to access the data asset normally.

[0157] The rules for aggregation and merging are as follows.

[0158] For data assets in relational tables with access restrictions, the column data permissions of a sub-conditional organization inherit all column data permissions of its parent conditional organization by default. Here, the data permissions of a conditional organization refer to the data permissions of the corresponding conditional organization's data records that a user has approved by that organization. For ease of description, conditional organization permissions can also be called row data permissions. Different conditional organization permissions are merged. For example, if a user initially requests permissions for the first row of a relational table with access restrictions, and then requests permissions for the second row, then within the permission expiration period, the user will have row data permissions for both the first and second rows simultaneously. Column data permissions employ a least-permission protection strategy, taking the intersection of permissions. For example, if a user has column data permissions for the first column of the first row in a relational table with access restrictions, and also has column data permissions for the first column and other columns in the second row, then after merging, the user will only have column data permissions for the first column in both the first and second rows, and will not have column data permissions for the other columns. Accordingly, the asset details page of this data asset should display at least the intersection of the row data of the first row and the column data of the first column, and the intersection of the row data of the second row and the column data of the first column. It should be noted that this intersection is the sampled data.

[0159] For data assets such as relational tables, files, reports, and analytical data, the expiration date of existing valid permissions for the same data asset is maximized. That is, the latest expiration date is chosen as the expiration date of a user's valid permissions for the data asset. This maximization principle ensures that users have access to data assets for a longer period, reducing repeated permission requests and improving data asset management efficiency and human-computer interaction efficiency.

[0160] The data asset permission calculation process is described below. Referring to Figure 3, which is a flowchart of an asset permission calculation method according to an embodiment of this application,...

[0161] First, data assets are categorized into relational tables, files, reports, analytical data, and many other extensible types. Data assets are also divided into public data assets and private data assets.

[0162] Secondly, for publicly available data assets, this system assumes that logged-in users have full permissions for those data assets and can access them normally. For non-public data assets, this system queries the logged-in user, the user's affiliated organization, and all existing valid asset permissions of its parent organizations, and then aggregates and merges these data to obtain the logged-in user's final valid asset permissions, thereby determining whether the logged-in user has the right to access the data asset normally. The specific aggregation and merging rules are the same as above.

[0163] The consolidated and verified access rules are as follows: If the final valid asset permissions indicate that the user has access to the data asset, the logged-in user can access the data asset normally, and the system will display the asset's public and individual information on the asset details page. If the final valid asset permissions indicate that the user does not have access to the data asset, the logged-in user needs to apply for asset permissions, and the system will indicate that the user currently does not have permission to access the data asset.

[0164] (3-3) The physical data module is used to physically store data assets in the data asset management system. This system supports both local and remote storage. Data assets include various types of scalable data assets such as relational tables, files, reports, and analytical data.

[0165] 204. The asset permission application and approval module allows for the application and approval of asset permissions for different types of data assets. Different types of data assets have different application pages, and the application input items displayed on different application pages are not exactly the same. Administrators of any organization can use this module to approve permissions for the organization's data assets.

[0166] In this embodiment, the asset permission application and approval module is the module in this system for applying for and approving permissions for non-public data assets. Accordingly, the asset permission application and approval module is used to apply for and approve permissions for different types of non-public data assets. After applying for permissions for different types of non-public data assets, the system queries, summarizes, and merges the existing valid asset permissions of the applicant user / applicant organization. These permissions are then compared with the applied-for asset permissions for permission verification. If the permission verification is successful, the application is successful, and the corresponding application flow is initiated, entering the asset permission approval process. Logged-in users can view asset permission application and approval information and can cancel unapproved asset permission application information. Corresponding data asset administrators can log in to approve and view pending and approved asset permission application information.

[0167] It should be noted that this system offers flexible asset permission applications, supporting applications from users / organizations. Applications are submitted only when permissions are needed, simplifying operations and significantly improving efficiency. The system also features flexible rules for asset permission administrators, supporting multiple administrator approvals to meet enterprise business operation mechanisms and improve processing efficiency. Furthermore, the system offers flexible asset permission approval operations, supporting both item-by-item and batch approvals, greatly enhancing approval efficiency. Finally, the system boasts robust asset permission verification capabilities, enabling rapid merging and calculation of existing valid permissions for multiple users or organizations applying simultaneously, as well as rapid verification and calculation of multiple granular asset permission applications. This results in fast response times and high data processing efficiency.

[0168] Meanwhile, the system features a unified asset access approval process. By establishing corresponding application and approval procedures, the system ensures precise granting of permissions, which is beneficial for protecting data asset security. In the event of asset access conflicts, the system adopts a least privilege protection strategy to ensure the security of asset data and improve data security.

[0169] The following is a detailed introduction to the asset authorization application and approval module.

[0170] In some embodiments, the asset permission application and approval module includes a permission application verification module, an asset permission approval module, and an application and approval display module. Accordingly, the method for applying for and approving asset permissions for different types of data assets through the asset permission application and approval module is shown in (4-1) to (4-3) below.

[0171] (4-1) The permission application verification module verifies the asset permissions for any data asset application among different types of non-public data assets. The asset permission application indicates the applicant and the asset permissions applied for. In other words, the asset permission application verification module is the module in this system that performs the application and verification of permissions for non-public data assets.

[0172] In some embodiments, the permission application verification module includes an asset permission application module and an asset permission verification module.

[0173] Accordingly, through the asset permission application module, logged-in users can initiate asset permission applications for data assets. Through this module, the system displays different application pages for different types of data assets, responding to the logged-in user's input of the corresponding application items to complete the application.

[0174] In this context, a logged-in user is the user who initiates an asset permission application, and the application target is the object for which permissions are to be granted in the asset permission application. A logged-in user can initiate an asset permission application for either a user or an organization, and both users and organizations can be single or multiple. That is, the application target includes at least one of the following: a user or an organization. Since a logged-in user can apply for asset permissions themselves, the application target can be the same as or different from the logged-in user.

[0175] For asset applications using relational data tables with no access restrictions, you need to enter the columns you want to access, the recipient of the application, and the deadline. For asset applications using relational data tables with access restrictions, in addition to entering the columns you want to access, the recipient of the application, and the deadline, you also need to enter the relevant organizational criteria to determine the rows you want to access. For asset applications using data types such as documents, reports, and analytical data, you need to enter the recipient of the application and the deadline.

[0176] Multiple values ​​can be entered for the desired column, the target of the application, and the eligible organization. The deadline is not a required input field. If the logged-in user does not enter a deadline, the user will request a permanent permission by default. If the logged-in user enters a specific deadline, the user will be granted permission for that deadline, and the permission will automatically expire when the deadline arrives.

[0177] Accordingly, the asset permission verification module determines the applicant's existing valid asset permissions and performs asset permission verification based on the existing valid asset permissions and the asset permissions applied for by the applicant. In other words, after applying for asset permissions for non-public data assets, asset permission verification is performed according to the corresponding verification rules.

[0178] The overall process of asset authorization verification is described below. Referring to Figure 4, which is a schematic diagram of an asset application authorization verification according to an embodiment of this application,...

[0179] First, after applying for asset permissions for non-public data assets, the system queries, summarizes, and merges the existing valid asset permissions for the applicant. Optionally, the method for calculating asset permissions during the summarization and merging process is the same as the method for calculating asset permissions in the asset permission determination module described above.

[0180] In some embodiments, the permission verification rules differ for different applicants. Accordingly, when the applicant is a user, the existing valid asset permissions of the applicant are the combined valid asset permissions of the applicant, the valid asset permissions of the institution to which the applicant belongs, and the valid asset permissions of all the institution's parent institutions; when the applicant is an institution, the existing valid asset permissions of the applicant are the combined valid asset permissions of the applicant and the valid asset permissions of all the institution's parent institutions.

[0181] In some embodiments, the rules for calculating the scope of permissions differ for different types of data assets. That is, the permission scope for data assets of permission-independent relational data table types includes column data permissions. The permission scope for data assets of permission-related relational data table types includes column data permissions and conditional organizational data permissions. The permission scope for data assets of file, report, and analytical data types includes operation permissions such as download permissions.

[0182] Then, the applicant's existing valid asset permissions are compared with the asset permissions applied for, thereby realizing permission verification.

[0183] In some embodiments, when the applicant is applying for asset permissions for the data asset for the first time, the asset permission verification module is used to determine that the asset permission application has passed the asset permission verification; when the applicant is not applying for asset permissions for the data asset for the first time, the asset permission verification module is used to determine whether the asset permission application has passed the asset permission verification based on the expiration date of the existing valid asset permission indication and the expiration date of the asset permission indication applied for by the applicant.

[0184] In other words, when the applicant is a user, the permission verification will pass if the user, their affiliated institution, and all their parent institutions lack the authority to apply for assets, or if their existing authority has expired, or if the expiration date of the final valid asset permission is shorter than the expiration date of the applied asset permission, or if the final valid asset permission is not permanent while the applied asset permission is permanent. Similarly, when the applicant is an institution, the permission verification will pass if the applying institution and all their parent institutions lack the authority to apply for assets, or if their existing authority has expired, or if the expiration date of the final valid asset permission is shorter than the expiration date of the applied asset permission, or if the final valid asset permission is not permanent while the applied asset permission is permanent.

[0185] Specifically, if the applicant's existing valid asset permissions are not permanent, but the requested asset permissions are permanent, the asset permission verification will pass and the application will be successful. If the expiration date of the applicant's existing valid asset permissions is shorter than the expiration date of the requested asset permissions, the asset permission verification will pass and the application will be successful. If the expiration date of the applicant's existing valid asset permissions is longer than the expiration date of the requested asset permissions, the asset permission verification will fail and the application will fail; there is no need to reapply. If the applicant's existing valid asset permissions are permanent, the asset permission verification will fail and the application will fail; there is no need to reapply. Only after successful permission verification can the application be successfully submitted, and the corresponding application flow will be initiated, entering the asset permission approval process, awaiting approval from the relevant asset administrator.

[0186] It should be noted that this system possesses robust asset permission verification capabilities, enabling rapid merging and calculation of existing valid permissions for multiple users or organizations applying for the same permission, as well as rapid verification and calculation of multiple asset permission requests at different granularities. Furthermore, the system features a unified asset permission approval process, controlling the precise granting of permissions through application and approval operations. In the event of conflicting asset permissions, a least privilege protection strategy is employed to ensure the absolute security of asset data.

[0187] (4-2) Through the asset permission approval module, if the asset permission application has passed the asset permission verification, the application flow is initiated and the asset permission approval process is entered. The asset permission approval process includes at least one approval node. Each approval node is used by at least one administrator to approve the asset permission application. Through the asset permission approval module, for any approval node, if any administrator corresponding to the approval node approves the asset permission application, the approval node ends.

[0188] Accordingly, asset permission application and approval process management is based on Activiti. After the system environment is ready, the corresponding database tables are automatically generated. The actiBPM plugin is installed, the corresponding .bpmn file is created, and the flowchart is drawn. After a data asset permission application is successful, the system automatically deploys, starts the process, initiates the application flow, and enters the asset permission approval process. The process ends after the asset administrator completes the approval.

[0189] The asset access approval process includes one or more approval nodes. Each approval node supports approval by multiple administrators. For the same approval node, the process at that node ends after any corresponding administrator approves it, meaning that the approval at that node is complete. When the asset access approval process includes a single approval node, the entire asset access approval process ends after that single approval node completes its approval; when the asset access approval process includes multiple approval nodes, the entire asset access approval process ends only after all approval nodes have completed their approvals.

[0190] (4-3) The application approval display module displays corresponding record information for each logged-in user. This record information includes application record information, pending approval record information, and approved record information. Application record information refers to resource permission applications initiated by the logged-in user; pending approval record information refers to resource permission applications awaiting approval by the administrator after login; and approved record information refers to resource permission applications approved by the currently logged-in administrator. In some embodiments, the application approval display module includes an application display module, a pending approval display module, and an approved display module. That is, the application approval display module is the module in this system that displays the application and approval of permissions for non-public data assets. The application approval display module includes modules such as "My Applications," "Pending Approvals," and "My Approvals."

[0191] Accordingly, the application display module shows logged-in users the asset permission applications they have initiated. This module also allows logged-in users to cancel unapproved asset permission applications. In other words, after logging in, users can view their applied asset permission information, including approved and unapproved applications. Unapproved asset permission applications can be canceled. Approved asset permission applications allow users to view approval information but cannot be canceled; however, they can be queried.

[0192] Accordingly, the pending approval display module shows administrators asset permission applications awaiting approval. This module is also used by administrators to approve these applications individually or in batches. In other words, after logging in, data asset administrators can view and approve asset permission applications awaiting their approval. Optionally, this system supports both individual and batch approval. In the case of individual approval, the approval page displays applicant information, asset permission application information, and asset permission approval information. In the case of batch approval, the approval page displays asset approval information. It should be noted that in both scenarios, administrators can perform approval operations including approving and rejecting. When rejecting an application, the reason for rejection is mandatory. It should also be noted that after an asset permission application is approved, the application record is entered into the corresponding page of the approved module. The applicant can then view / operate on the corresponding asset permission data.

[0193] Accordingly, the approved asset permission applications are displayed to administrators through the approved display module. In other words, data asset administrators can view their approved asset permission application information after logging into the system. This system supports querying.

[0194] It should be noted that the asset permission approver designation rules in this system are flexible, supporting multiple approval candidates to meet the needs of enterprise business operations. The asset permission approval process in this system is flexible, supporting both item-by-item and batch approvals, greatly improving approval efficiency.

[0195] This application provides a data asset management method. In this method, multiple modules within a data asset management system, including a basic asset permission module, an asset permission management module, an asset permission display module, and an asset permission application and approval module, can synchronize basic data requiring permission management within the system. Data assets are categorized and managed hierarchically. A corresponding data asset catalog is displayed for each type of data asset. Clicking on an asset name leads to the asset details page, which displays public and personalized information for the corresponding asset type. Different asset types support viewing or operating on existing valid permission data, as well as applying for and approving permissions for different types of data assets. This achieves precise control over permissions for different types of assets, simplifying operations, improving the efficiency of data asset permission management, ensuring data asset security, and guaranteeing that logged-in users can view and operate on asset data with existing valid permissions.

[0196] It should be noted that this application, by proposing a data asset management system and method, not only supports various functions such as asset permission basics, asset permission management, asset catalog, asset permission calculation, asset permission application, asset permission verification, asset permission approval, and asset permission data access / operation, based on different types of data asset management systems and unique permission calculation and verification technologies, but also supports visualization and workflow. The aforementioned data asset management system and method not only conform to the enterprise's organizational structure and business operation mechanism, but are also simple and visual, support multiple types and are scalable, support instant application, and support flexible application and approval, enabling precise permission control. This reduces the development cost of asset permission management, solves the problems of security risks and difficulty in permission control for different types of assets, and provides protection and security for asset management operations.

[0197] Figure 5 is a schematic diagram of a terminal according to an embodiment of this application. The terminal 500 can be a portable mobile terminal, such as a smartphone, tablet computer, MP3 player (Moving Picture Experts Group Audio Layer III), MP4 player (Moving Picture Experts Group Audio Layer IV), laptop computer, or desktop computer. The terminal 500 may also be referred to as a user device, portable terminal, laptop terminal, desktop terminal, or other names.

[0198] Typically, terminal 500 includes a processor 501 and a memory 502.

[0199] Processor 501 may include one or more processing cores, such as a quad-core processor, a penta-core processor, etc. Processor 501 may be implemented using at least one hardware form selected from DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). Processor 501 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 501 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, processor 501 may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.

[0200] The memory 502 may include one or more computer-readable storage media, which may be non-transitory. The memory 502 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 502 are used to store at least one computer program, which is executed by the processor 501 to implement the asset rights management method provided in the method embodiments of this application.

[0201] In some embodiments, the terminal 500 may also optionally include a peripheral device interface 503 and at least one peripheral device. The processor 501, memory 502, and peripheral device interface 503 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 503 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency circuit 504, a display screen 505, a camera assembly 506, an audio circuit 507, and a power supply 508.

[0202] Peripheral device interface 503 can be used to connect at least one I / O (Input / Output) related peripheral device to processor 501 and memory 502. In some embodiments, processor 501, memory 502 and peripheral device interface 503 are integrated on the same chip or circuit board; in some other embodiments, any one or two of processor 501, memory 502 and peripheral device interface 503 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.

[0203] The radio frequency (RF) circuit 504 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 504 communicates with communication networks and other communication devices via electromagnetic signals. The RF circuit 504 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. In some embodiments, the RF circuit 504 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The RF circuit 504 can communicate with other terminals through at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: the World Wide Web, metropolitan area networks, intranets, various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks, and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF circuit 504 may also include circuitry related to NFC (Near Field Communication), which is not limited in this application.

[0204] Display screen 505 is used to display a UI (User Interface). This UI may include graphics, text, icons, videos, and any combination thereof. When display screen 505 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 501 for processing. In this case, display screen 505 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 505, disposed on the front panel of terminal 500; in other embodiments, there may be at least two display screens, disposed on different surfaces of terminal 500 or in a folded design; in still other embodiments, display screen 505 may be a flexible display screen, disposed on a curved or folded surface of terminal 500. Furthermore, display screen 505 may be configured as a non-rectangular irregular shape, i.e., a non-rectangular screen. Display screen 505 may be made of materials such as LCD (Liquid Crystal Display) or OLED (Organic Light-Emitting Diode).

[0205] The camera assembly 506 is used to acquire images or videos. In some embodiments, the camera assembly 506 includes a front-facing camera and a rear-facing camera. Typically, the front-facing camera is located on the front panel of the terminal, and the rear-facing camera is located on the back of the terminal. In some embodiments, there are at least two rear-facing cameras, which are any one of a main camera, a depth-sensing camera, a wide-angle camera, and a telephoto camera, to achieve background blurring by fusion of the main camera and the depth-sensing camera, panoramic shooting by fusion of the main camera and the wide-angle camera, VR (Virtual Reality) shooting, or other fusion shooting functions. In some embodiments, the camera assembly 506 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash is a combination of a warm-light flash and a cool-light flash, which can be used for light compensation at different color temperatures.

[0206] The audio circuit 507 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, converting the sound waves into electrical signals that are input to the processor 501 for processing, or input to the radio frequency circuit 504 for voice communication. For stereo sound acquisition or noise reduction purposes, multiple microphones may be used, each located at a different part of the terminal 500. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert the electrical signals from the processor 501 or the radio frequency circuit 504 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into audible sound waves but also into inaudible sound waves for purposes such as distance measurement. In some embodiments, the audio circuit 507 may also include a headphone jack.

[0207] Power supply 508 is used to power the various components in terminal 500. Power supply 508 can be AC ​​power, DC power, a disposable battery, or a rechargeable battery. When power supply 508 includes a rechargeable battery, the rechargeable battery can support wired or wireless charging. The rechargeable battery can also be used to support fast charging technology.

[0208] In some embodiments, the terminal 500 further includes one or more sensors 509. The one or more sensors 509 include, but are not limited to, an accelerometer 510, a gyroscope 511, a pressure sensor 512, an optical sensor 513, and a proximity sensor 514.

[0209] Accelerometer 510 can detect the magnitude of acceleration along the three axes of a coordinate system established by terminal 500. For example, accelerometer 510 can be used to detect the components of gravitational acceleration along the three axes. Processor 501 can control display screen 505 to display the user interface in either a landscape or portrait view based on the gravitational acceleration signal acquired by accelerometer 510. Accelerometer 510 can also be used for games or for acquiring user motion data.

[0210] The gyroscope sensor 511 can detect the orientation and rotation angle of the terminal 500. The gyroscope sensor 511, in conjunction with the accelerometer sensor 510, can collect 3D motion data from the user on the terminal 500. Based on the data collected by the gyroscope sensor 511, the processor 501 can perform the following functions: motion sensing (e.g., changing the UI based on the user's tilt), image stabilization during shooting, game control, and inertial navigation.

[0211] The pressure sensor 512 can be disposed on the side bezel of the terminal 500 and / or on the lower layer of the display screen 505. When the pressure sensor 512 is disposed on the side bezel of the terminal 500, it can detect the user's grip signal on the terminal 500, and the processor 501 can perform left / right hand recognition or quick operation based on the grip signal collected by the pressure sensor 512. When the pressure sensor 512 is disposed on the lower layer of the display screen 505, the processor 501 can control the operable controls on the UI interface based on the user's pressure operation on the display screen 505. The operable controls include at least one of button controls, scroll bar controls, icon controls, and menu controls.

[0212] An optical sensor 513 is used to collect ambient light intensity. In one embodiment, the processor 501 can control the display brightness of the display screen 505 based on the ambient light intensity collected by the optical sensor 513. Optionally, when the ambient light intensity is high, the display brightness of the display screen 505 is increased; when the ambient light intensity is low, the display brightness of the display screen 505 is decreased. In another embodiment, the processor 501 can also dynamically adjust the shooting parameters of the camera assembly 505 based on the ambient light intensity collected by the optical sensor 513.

[0213] The proximity sensor 514, also known as the distance sensor, is installed on the front panel of the terminal 500. The proximity sensor 514 is used to detect the distance between the user and the front of the terminal 500. In one embodiment, when the proximity sensor 514 detects that the distance between the user and the front of the terminal 500 is gradually decreasing, the processor 501 controls the display screen 505 to switch from a screen-on state to a screen-off state; when the proximity sensor 514 detects that the distance between the user and the front of the terminal 500 is gradually increasing, the processor 501 controls the display screen 505 to switch from a screen-off state to a screen-on state.

[0214] Those skilled in the art will understand that the structure shown in FIG5 does not constitute a limitation on terminal 500, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.

[0215] Figure 6 is a schematic diagram of a server structure according to an embodiment of this application. The server 600 can vary significantly due to different configurations or performance. It may include one or more Central Processing Units (CPUs) 601 and one or more memories 602. The memory 602 stores at least one computer program, which is loaded and executed by the processor 601 to implement the asset access management methods provided in the various method embodiments described above. Of course, the server may also have wired or wireless network interfaces, a keyboard, and input / output interfaces for input and output. The server may also include other components for implementing device functions, which will not be elaborated upon here.

[0216] This application also provides a computer-readable storage medium storing at least one computer program, which is loaded and executed by a processor to implement the asset access control method described in the above embodiments. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, or optical data storage device, etc.

[0217] This application also provides a computer program product, including a computer program that is executed by a processor to implement the asset access management method in this application.

[0218] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0219] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A data asset management system, characterized in that, The data asset management system includes an asset permission basic module, an asset permission management module, an asset permission display module, and an asset permission application and approval module. The asset permission basic module synchronizes the basic data requiring asset permission management, including data sources, metadata, institutional data, and user data. The asset permission management module classifies and manages data assets, with expandable data asset types. The hierarchy of a data asset is the level under its category, and each data asset belongs to an institution, with each institution having at least one parent and one child institution. The asset permission display module displays the corresponding data asset catalog for each data asset type. The asset permission application and approval module handles asset permission applications and approvals for different types of data assets. Different data asset types have different application pages with varying input fields. Administrators of each institution approve permissions for the institution's data assets.

2. The data asset management system according to claim 1, characterized in that, The asset access control module includes a data source management module, a metadata management module, an organization management module, and a user management module. The data source management module synchronizes the data source information for asset access control within the data asset management system. The metadata management module synchronizes the metadata corresponding to the data source information under the corresponding data architecture. This metadata includes technical metadata, business metadata, and management metadata. The organization management module synchronizes the organizations for asset access control within the data asset management system; different organizations have different organization codes. The user management module synchronizes the users for asset access control within the data asset management system; different users have different employee codes, and each user's individual organization code is the organization code of the organization to which the user belongs.

3. The data asset management system according to claim 2, characterized in that, When any data asset is a relational data table, the metadata corresponding to the data asset includes database metadata, table metadata, and column metadata.

4. The data asset management system according to claim 1, characterized in that, The asset access management module includes an asset classification module, an asset management module, and an asset administrator module. The asset classification module is used to classify and manage data assets according to different dimensions, with each dimension indicating different indicators of the data assets. The asset management module manages the asset permissions for different types of data assets. Each data asset can be set as a public or non-public data asset. Public data assets are those for which users have default access permissions, while non-public data assets are those for which users do not have default access permissions. The asset administrator module manages at least one administrator for each organization, and the administrator approves asset permission applications for the non-public data assets.

5. The data asset management system according to claim 4, characterized in that, When any data asset is of type first relational data table, the administrator of the data asset is the administrator of the institution to which the data asset belongs; when any data asset is of type second relational data table, the administrator of the data asset includes the administrator of at least one conditional institution corresponding to the data asset, and the conditional institution is used to manage the asset permissions of the bank data in the data asset.

6. The data asset management system according to claim 1, characterized in that, The asset permission display module includes an asset catalog module, an asset permission determination module, and an asset physical data module. The asset catalog module displays data asset catalogs for different types of data assets, with each catalog including the data asset name for the corresponding data asset type. The asset catalog module also displays the asset details page of any data asset in response to a trigger operation on its data asset name. Different types of data assets correspond to different asset details pages, and the asset details pages displayed for the same data asset by users with different existing valid asset permissions are not entirely identical. The asset permission determination module determines the existing valid asset permissions of a logged-in user. The existing valid asset permissions of a logged-in user are the summed and merged valid asset permissions of the logged-in user, the valid asset permissions of the user's organization, and the valid asset permissions of all parent organizations of the user's organization. The asset physical data module is used for the physical storage of data assets in the data asset management system.

7. The data asset management system according to claim 6, characterized in that, When any data asset is a relational data table, the asset catalog module is used to display sampled data on the asset details page of the data asset for logged-in users with valid permissions. The sampled data is table data in the relational data table for which the logged-in user has valid permissions.

8. The data asset management system according to claim 1, characterized in that, The asset permission application and approval module includes a permission application verification module, an asset permission approval module, and an application and approval display module. The permission application verification module verifies asset permissions for any data asset application among different types of non-public data assets. The asset permission application indicates the applicant and the requested asset permissions. The applicant includes at least one of users and institutions, and the non-public data assets are those for which users have no default asset permissions. The asset permission approval module initiates an application flow and enters the asset permission approval process when the asset permission application has passed the verification. The asset permission approval process includes at least one approval node, where each node is used by at least one administrator to approve the asset permission application. The application flow uses... The process involves instructing a logged-in user to initiate an asset permission application for the data asset on behalf of the application object, wherein the logged-in user may be the same as or different from the application object; the asset permission approval module is further configured to terminate the approval node if any administrator corresponding to the approval node approves the asset permission application; the application approval display module is configured to display corresponding record information for each logged-in user, including application record information, pending approval record information, and approved record information. The application record information is the record information of resource permission applications initiated by the logged-in user, the pending approval record information is the record information of resource permission applications awaiting approval by an administrator after logging in, and the approved record information is the record information of resource permission applications approved by the currently logged-in administrator.

9. The data asset management system according to claim 8, characterized in that, The permission application verification module includes an asset permission application module and an asset permission verification module; wherein, the asset permission application module is used by the logged-in user to initiate an asset permission application for the data asset for the application object; the asset permission verification module is used to determine the existing valid asset permissions of the application object, and perform asset permission verification based on the existing valid asset permissions and the asset permissions applied for by the application object.

10. The data asset management system according to claim 9, characterized in that, When the applicant is a user, the existing valid asset permissions of the applicant are the combined valid asset permissions of the applicant, the valid asset permissions of the institution to which the applicant belongs, and the valid asset permissions of all the institution's parent institutions; when the applicant is an institution, the existing valid asset permissions of the applicant are the combined valid asset permissions of the applicant and the valid asset permissions of all the institution's parent institutions.

11. The data asset management system according to claim 9, characterized in that, When the application is for the first time to apply for asset permissions for the data asset, the asset permission verification module is used to determine that the asset permission application has passed the asset permission verification. When the applicant is not making an asset permission application for the data asset for the first time, the asset permission verification module is used to determine whether the asset permission application has passed the asset permission verification based on the expiration date of the existing valid asset permission indication and the expiration date of the asset permission indication applied for by the applicant.

12. The data asset management system according to claim 8, characterized in that, The application approval display module includes an application display module, a pending approval display module, and an approved display module. The application display module displays asset permission applications initiated by logged-in users, and also allows logged-in users to cancel unapproved asset permission applications. The pending approval display module displays pending asset permission applications for administrators, and also allows administrators to approve pending asset permission applications individually or in batches. The approved display module displays approved asset permission applications for administrators.

13. A data asset management method, characterized in that, This method is applied to a data asset management system, which includes an asset permission basic module, an asset permission management module, an asset permission display module, and an asset permission application and approval module. The method includes: synchronizing basic data requiring asset permission management through the asset permission basic module, including data sources, metadata, institutional data, and user data; classifying and hierarchically managing data assets through the asset permission management module, where the types of data assets can be extended, and the hierarchy of data assets is the level under the category to which the data asset belongs, with each institution having at least one of parent and child institutions; displaying the corresponding data asset catalog under each data asset type through the asset permission display module; and applying for and approving asset permissions for different types of data assets through the asset permission application and approval module, where different types of data assets have different application pages with slightly different input fields, and an administrator of any institution approves the permissions for the institution's data assets.

14. A computer device, characterized in that, The computer device includes a processor and a memory, the memory being used to store at least one computer program, the at least one computer program being loaded by the processor and executed as the data asset management method of claim 13.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store at least one computer program, which is used to execute the data asset management method of claim 13.