Data access management method, device and storage medium
By constructing a knowledge graph to analyze users' social relationships and automatically matching access permissions, the problem of insufficient identification of users' social relationships in smart home systems is solved, achieving precise permission control and simplified permission configuration, and improving the interactive experience in multi-user scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2026-03-31
- Publication Date
- 2026-06-02
AI Technical Summary
Existing smart home systems struggle to perceive dynamic social relationships among users in multi-user scenarios, resulting in complex permission configurations and poor interactive experiences. Traditional permission control solutions can only identify physical identities but cannot understand social relationships, creating a semantic gap.
By constructing a knowledge graph that integrates social relationships and data access permissions, the system analyzes the social relationships between users and automatically matches access permissions, enabling access control based on natural language commands. This breaks free from fixed role restrictions and improves the accuracy and flexibility of access management.
It effectively bridges the semantic gap between natural language interaction and backend permission logic, improves the interactive experience and permission control accuracy in multi-user scenarios of smart homes, and lowers the barrier to entry.
Smart Images

Figure CN122137661A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of smart home technology, and in particular to a data access control method, device and storage medium. Background Technology
[0002] With the widespread application of IoT and AI technologies, smart home systems have evolved from single-device control to collaborative processing systems for multiple users. Currently, privacy and access control in smart homes primarily employ role-based access control, configuring corresponding permission sets for fixed roles such as administrators, regular members, and visitors.
[0003] However, in complex family social scenarios, the above solutions can only identify the user's physical identity and have difficulty perceiving the social relationships between users, resulting in a significant semantic interaction gap and greatly affecting the system's interactive experience. Summary of the Invention
[0004] This application provides a data access control method, device, and storage medium that can sense the dynamic social relationships between users, bridge the semantic interaction gap, and thus improve the interactive experience of permission configuration in multi-user family scenarios.
[0005] On the one hand, a data access control method is provided, including: receiving a data access request initiated by a third user, the data access request being used to request authorization for a second user to access target data created by a first user, the data access request including target social relationships, the target social relationships including at least two of the following: the social relationship between the first user and the second user, the social relationship between the second user and the third user, and the social relationship between the first user and the third user; Based on the target data and target social relationships, the target access permissions of the second user to the target data are determined in the pre-constructed knowledge graph. The knowledge graph includes social relationships between multiple users and access permissions of each user to at least one piece of data. The multiple users include the first user, the second user, and the third user. The at least one piece of data includes the target data. The access permissions are used to indicate whether a user has the permission to access the corresponding data. Control the second user's access to the target data based on the target access permissions.
[0006] On the other hand, a data access control device is provided, including a communication unit and a processing unit.
[0007] The communication unit is used to receive a data access request initiated by a third user. The data access request is used to request authorization for a second user to access target data created by a first user. The data access request includes target social relationships, which include at least two of the following: the social relationship between the first user and the second user, the social relationship between the second user and the third user, and the social relationship between the first user and the third user. The processing unit is used to determine the target access permissions of the second user to the target data in a pre-built knowledge graph based on the target data and the target social relationships. The knowledge graph includes social relationships between multiple users and access permissions of each user to at least one piece of data. The multiple users include a first user, a second user, and a third user. The at least one piece of data includes the target data. The access permissions are used to indicate whether a user has the permission to access the corresponding data. The processing unit is also used to control the second user's access to target data according to the target access permissions.
[0008] In another aspect, an electronic device is provided, comprising: a memory and a processor; the memory and the processor are coupled; the memory is used to store a computer program; and the processor, when executing the computer program, implements the data access control method of any of the above embodiments.
[0009] In another aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium includes a non-transitory computer-readable storage medium storing computer instructions, which, when executed on a computer, cause the computer to perform the data access control method of any of the above embodiments.
[0010] In another aspect, a computer program product is provided, which includes computer program instructions that, when executed by a processor, implement the data access control method of any of the above embodiments.
[0011] This application provides a data access control method that addresses data access requests carrying at least two of the following social relationships: the social relationship between a first user and a second user, the social relationship between a second user and a third user, and the social relationship between a first user and a third user. It leverages a pre-constructed knowledge graph that integrates social relationships and data access permissions, enabling direct perception of user relationships. This solves the technical problem of traditional access control schemes that can only identify physical identities but cannot understand social relationships. Furthermore, based on the target data and target social relationships, it automatically matches the second user's target access permissions to the target data within the knowledge graph and executes access control accordingly. This method eliminates the limitations of preset fixed roles, avoids complex manual configuration processes, and effectively bridges the semantic gap between natural language interaction and backend permission logic. While improving the accuracy and flexibility of access control, it significantly lowers the barrier to entry for smart homes and effectively enhances the interactive experience in multi-user smart home scenarios. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in this application, the accompanying drawings used in some embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0013] Figure 1 A system architecture diagram of a data access control system provided in some embodiments of this application; Figure 2 A schematic diagram of the logical hierarchy architecture of an electronic device provided for some embodiments of this application; Figure 3 A flowchart illustrating a data access control method provided in some embodiments of this application; Figure 4 An example diagram of a knowledge graph provided for some embodiments of this application; Figure 5 A flowchart illustrating another data access control method provided in some embodiments of this application; Figure 6 A flowchart illustrating another data access control method provided in some embodiments of this application; Figure 7 This application provides a schematic diagram of the structure of an electronic device according to some embodiments; Figure 8 This is a schematic diagram of the structure of another electronic device provided in some embodiments of this application. Detailed Implementation
[0014] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0015] It should be noted that, in this application, the terms "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.
[0016] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.
[0017] In the description of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more.
[0018] As described in the background section, with the widespread application of IoT and AI technologies, smart home systems have evolved from single-device control to collaborative processing platforms for multiple users. During this evolution, a large amount of highly fragmented and privacy-sensitive digital assets have been generated within the home. These digital assets include not only basic data such as text memos, but also highly privacy-sensitive multimodal data such as family photo albums, health records, financial statements, and security surveillance footage.
[0019] Currently, data access control in smart homes mainly adopts the following two modes: Mode 1, account-based access control mode; Mode 2, role-based access control mode. The following provides a detailed explanation of these two modes.
[0020] Mode 1: Account-based access control mode. Specifically, devices typically belong to a main account, which uses the family sharing function to assign device control permissions or data access permissions to other member accounts.
[0021] Mode 2: Role-based access control. Specifically, fixed roles such as administrators, regular members, and visitors are pre-configured, and corresponding fixed data access permission sets are assigned to each type of fixed role.
[0022] While both of these models can achieve basic user permission differentiation, they present a semantic gap problem in complex family social scenarios, where semantic understanding is disconnected from users' social relationships.
[0023] Specifically, the above mode can only identify the user's physical identity and cannot perceive the dynamic social relationships between users. For example, when a user issues natural language commands based on kinship social relationships, such as "show to wife" or "block access for children," the device cannot automatically complete the permission configuration for the corresponding members. The user needs to manually select the member list through the application's multi-level menu. There is a disconnect between the natural language commands and the background permission logic, resulting in a poor system interaction experience.
[0024] To address the aforementioned issues, this application provides a data access control method. For example, when a user inputs natural language commands such as "This reminder is only for my wife," "Share the family travel plan," and "Don't let the children see this" via voice or text, the electronic device can accurately parse the social relationship semantics in the command based on a pre-built knowledge graph that integrates social relationships and data access permissions. It can then automatically match and execute access control within the knowledge graph, thus eliminating the limitations of preset fixed roles and simplifying complex manual configuration processes. This effectively bridges the semantic gap between natural language interaction and backend permission logic, improving the accuracy and flexibility of permission control while enhancing the interactive experience in multi-user smart home scenarios.
[0025] The system architecture of the embodiments of this application will be described below as an example.
[0026] Some embodiments of this application provide a system architecture for a data access control system, such as... Figure 1 As shown, the data access control system may include an electronic device 101 and an interactive device 102. The electronic device 101 can communicate with the interactive device 102.
[0027] In some embodiments, the electronic device 101 is a locally deployed high-computing-power device used to execute the data access control method provided in this application embodiment. Specifically, the electronic device 101 receives a data access request initiated by a third user. This data access request requests authorization for a second user to access target data created by a first user. The data access request includes target social relationships, which include at least two of the following: social relationships between the first and second users, social relationships between the second and third users, and social relationships between the first and third users. Based on the target data and target social relationships, the electronic device 101 determines the target access permissions of the second user to the target data in a pre-built knowledge graph, and controls the second user's access to the target data according to the target access permissions. The knowledge graph includes social relationships between multiple users and access permissions for each user to at least one piece of data. The multiple users include the first user, the second user, and the third user. The access permissions indicate whether a user has permission to access the corresponding data.
[0028] For example, electronic device 101 can be deployed in a high-computing-power local device such as a home computing host or a fiber-to-the-room (FTTR) main gateway. Electronic device 101 integrates a semantic parsing module and a graph inference engine. The semantic parsing module, which can be implemented based on a large language model (LLM), is used to parse data access requests to obtain information about target social relationships and target data. The graph inference engine is used to determine the target access permissions of a second user for the target data within a pre-built knowledge graph and to control the second user's access behavior based on the target access permissions.
[0029] Interactive device 102 is used to collect user input data and context information, send the user input data and context information to electronic device 101, and obtain response results through electronic device 101. For example, the user input data is a data access request, and the input method includes, but is not limited to, voice input, touch input, and text input. Context information includes, but is not limited to, user location, device status, and spatial attributes (e.g., master bedroom, living room, etc.).
[0030] In some embodiments, the data access control system may further include a cloud server 103, which can communicate with the electronic device 101. The cloud server 103 is deployed on a high-performance computing host, edge server, or enterprise cloud platform to receive data access requests reported by the electronic device 101 and perform large-scale data processing and complex inference tasks. Specifically, the cloud server 103 can handle high-frequency data access requests, determine the access rights of a second user to target data through graph querying and path reasoning, and return the decision on the second user's access to the target data based on the determined access rights to the target data to the electronic device 101 to meet high-performance response requirements.
[0031] In other words, the data access control method provided in this application embodiment can be executed by the electronic device 101 or by the cloud server 103. For example, when the electronic device 101 is a high-computing-power device deployed locally, the data access control method can be executed by the electronic device 101 to ensure a faster response speed and ensure that the original data does not leave the intranet, thereby meeting the privacy protection requirements in the smart home scenario; when the electronic device 101 is a low-computing-power device deployed locally, the data access control method can be executed by the cloud server 103 to utilize the high computing power of the cloud to meet the high-performance processing requirements.
[0032] This application does not impose any restrictions on the specific form of the electronic device 101. For example, the electronic device 101 can be a home computing host or an FTTR main gateway. The home computing host or FTTR main gateway can be a single device or a cluster of multiple devices.
[0033] The interactive device 102 can specifically be a terminal device. A terminal device can be referred to as: terminal, user equipment (UE), access terminal, user unit, user station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device, etc. For example, a terminal device can specifically be a mobile phone, augmented reality (AR) device, virtual reality (VR) device, tablet computer, laptop computer, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), smart speaker, smart screen, mobile application (App), home robot, etc.
[0034] The cloud server 103 can be a single server or a server cluster consisting of multiple servers. Furthermore, the server cluster can also be a distributed cluster; this embodiment of the application does not impose any limitations on this.
[0035] It should be pointed out that, Figure 1 The system architecture shown does not constitute a limitation on the data access control system, except Figure 1 In addition to the devices shown, the data access control system may include more or fewer devices than illustrated, or combine certain devices, or use different device arrangements.
[0036] For example, electronic device 101 and interactive device 102 can be integrated into the same device. When electronic device 101 and interactive device 102 are integrated into the same device, the communication between them is the same as the communication between modules within the device. For ease of description, this application embodiment uses electronic device 101 and interactive device 102 as examples of multiple independent devices.
[0037] The internal functional architecture of electronic device 101 is described below. When executing the data access control method provided in this application embodiment, electronic device 101 can divide the computing device into multiple levels and multiple logical modules according to the method execution logic. For example, as... Figure 2 As shown, the electronic device 101 may include: a perception access layer, a knowledge graph service layer, and an access control layer.
[0038] In some embodiments, the perception access layer is used to collect and preliminarily process data access requests initiated by third users, and output standardized information such as the third user's identity, target data, and target social relationships. Specifically, the perception access layer includes a multimodal recognition module and a semantic parsing engine.
[0039] The multimodal recognition module is used to assign a unique identity to the third user who initiates the data access request through voiceprint recognition and facial recognition technologies, so as to confirm the identity of the user who initiates the data access request and prevent the misuse of permissions.
[0040] The semantic parsing engine is used to parse the voice or text commands corresponding to data access requests and extract key information. For example, when a third user inputs "show my wife my medical examination report", the semantic parsing engine will break down "medical examination report" as the target data, "view" as the operation intention, and "wife" as the target social relationship between the third user (i.e. the first user) and the second user, thereby clarifying the operation that the user wants to perform.
[0041] In some embodiments, the knowledge graph service layer is used to determine the personnel node corresponding to the second user through the knowledge graph. Specifically, the knowledge graph service layer includes a graph database, a graph management module, and an inference engine.
[0042] Graph databases are used to store various entities and their relationships in a home setting. Entities include people, equipment, and data types, while relationships include parent-child, spouse, and equipment ownership types. Furthermore, the graph database supports dynamic expansion of entities and relationships to adapt to the changing needs of a home setting.
[0043] The graph management module is used to periodically maintain the nodes and relation edges in the knowledge graph, including operations such as adding, deleting, and modifying nodes and relation edges, to ensure the real-time performance and accuracy of the data in the knowledge graph.
[0044] As the core reasoning unit of the knowledge graph service layer, the reasoning engine is mainly used to accurately determine the personnel node corresponding to the second user in the knowledge graph based on the identity information of the third user and the target social relationship.
[0045] In addition, the reasoning engine is also used to deduce implicit social relationships based on the explicit social relationships already existing in the knowledge graph. For example, based on "A is B's father, B is C's father", it can deduce "A is C's grandfather" and fill in the derived implicit social relationships in the knowledge graph, thereby enriching the social relationship dimension between users and providing a more complete social relationship basis for determining the personnel nodes corresponding to the second user.
[0046] In some embodiments, the permission decision control layer is used to determine whether a second user has permission to access target data based on the graph reasoning results of the knowledge graph service layer. This permission decision control layer specifically includes a path search algorithm module, a conflict determination module, and a spatial context verification module.
[0047] The path search algorithm module is used to analyze the multi-hop relationship from the second user node to the target data node. When there is no direct social relationship between the second user and the first user who created the target data, the path search algorithm module determines the social relationship path from the second user node to the first user node through at least one intermediate user node based on the first relationship edge in the knowledge graph. Based on the second relationship edge in the knowledge graph, it determines the data association relationship between the first user node and the target data node. Then, based on the social relationship path and the data association relationship, it constructs an accessible path from the second user node to the target data node. Based on this accessible path, it determines that the second user has the permission to access the target data.
[0048] For example, if the target data is a medical examination report, and the first user is the second user's father-in-law, and there is no direct first relationship edge between the second user and his father-in-law, then the path search algorithm module determines the first relationship edge between the second user's wife's corresponding personnel node (i.e., the intermediate personnel node) and the first relationship edge between the second user's personnel node and the wife's corresponding personnel node, as well as the first relationship edge between the wife's corresponding personnel node and the father-in-law's corresponding personnel node, thereby constructing a social relationship path from the second user's personnel node through the wife's corresponding personnel node and the father-in-law's corresponding personnel node. Then, through the second relationship edge between the father-in-law's corresponding personnel node and the data node corresponding to the medical examination report, a complete path is constructed from the second user's personnel node to the data node corresponding to the medical examination report, so as to determine that the second user has the right to access the medical examination report based on the complete path.
[0049] The conflict resolution module follows the blocking priority principle. When both allowed and denied access are present in the determined data access permissions, the denied access is selected first to resolve the data access permission conflict.
[0050] The spatial context verification module is used to dynamically adjust data access permissions based on the physical area information of the interactive device. For example, an interactive device located in the living room can display the complete target data; or an interactive device located in the bedroom can only display the de-identified target data, and output decisions such as whether to allow access to the target data and the specific way to display the target data.
[0051] The specific implementation process of the functions of each of the above modules can be found in the following description, and will not be repeated here.
[0052] It should be pointed out that, Figure 2 The hierarchical and modular architecture shown does not constitute a limitation on the internal structure of electronic device 101, except... Figure 2 In addition to the individual levels and modules shown, electronic device 101 may include more or fewer levels and modules than shown, or combine certain levels and modules, or have different arrangements of levels and modules.
[0053] The data access control method provided in the embodiments of this application will be described in detail below.
[0054] like Figure 3 The diagram shown is a flowchart illustrating a data access control method provided in an embodiment of this application. Figure 3 The method shown can be applied to computing devices. This data access control method includes: S301, Receive a data access request initiated by a third user.
[0055] The data access request is used to request authorization for a second user to access target data created by a first user. The data access request includes target social relationships, which include at least two of the following: the social relationship between the first user and the second user, the social relationship between the second user and the third user, and the social relationship between the first user and the third user.
[0056] In some embodiments, the first user, the second user, and the third user are different from each other. For example, the third user (e.g., the father) requests authorization for the second user (e.g., the mother) to access target data (e.g., report card) created by the first user (e.g., the child). In this case, the data access request includes at least one of the target social relationships: the marital relationship between the father and mother, the father-child relationship between the father and the child, or the mother-child relationship between the mother and the child.
[0057] In other embodiments, the first user is the same as the third user and different from the second user. For example, the third user (e.g., the father) requests authorization for the second user (e.g., the mother) to access target data (e.g., family financial data) created by the father (i.e., the first user and the third user are the same), where the data access request includes the marital relationship between the father and mother as the target social relationship.
[0058] In other embodiments, the first user is the same as the second user and different from the third user. For example, the third user (e.g., the father) requests authorization for the first user (e.g., the child) to access the report card created by the child (i.e., the first user is the same as the second user), in which case the data access request includes the father-child relationship as the target social relationship.
[0059] In some embodiments, after receiving a data access request, the data access request initiated by a third user can be identified and parsed to extract the third user's identity information, target data, and target social relationships. For example, a unique identifier can be assigned to the third user initiating the data access request through voiceprint recognition and / or facial recognition to confirm the identity information of the third user, and the data access request can be parsed through natural language processing (NLP) to determine the target data and target social relationships.
[0060] In this application embodiment, the third user can initiate a data access request in a variety of ways, such as inputting voice commands through a smart speaker, inputting text commands through a mobile application, or performing touch operations through a smart screen.
[0061] When inputting voice commands through a smart speaker or text commands through a mobile app, the input form of the data access request can be natural language expression, such as "Show my wife my medical report", "The whole family can see the travel plan", "Don't let the children see this reminder", etc.
[0062] When using the smart screen for touch operation, data access requests can also be input in the form of interface interaction commands. For example, a third user can long-press a memo and then click the "Only spouse visible" option in the pop-up permission settings panel; another example is that a third user can select a photo and then drag and drop the photo onto a family member's avatar to complete the authorization; yet another example is that a third user can switch between permission options such as "Allow children to view" and "Allow parents to view" using a toggle control on the data details page; and yet another example is that a third user can select quick configuration options such as "Shared by the whole family," "Shared by both spouses," or "Only visible to myself" from the preset permission templates by clicking.
[0063] The above is an exemplary description of the method by which a third user initiates a data access request and the input form of the data access request. For example, the method by which a third user initiates a data access request can also be through voice interaction with a home robot, and the input form of the data access request can also be a multimodal command by the third user combining gestures and voice. For example, the third user points to a photo on the robot screen and says "show it to grandparents"; or, for example, the third user points to a photo on the robot screen and says "don't show it to friends". This application embodiment does not limit this.
[0064] S302. Based on the target data and target social relationships, determine the second user's target access permissions to the target data in the pre-constructed knowledge graph.
[0065] The knowledge graph includes social relationships among multiple users and access permissions for each user to at least one piece of data. The multiple users include a first user, a second user, and a third user. The at least one piece of data includes target data. Access permissions are used to indicate whether a user has permission to access the corresponding data.
[0066] In some embodiments, the implementation process of S302 above may be as follows: based on the social relationships between multiple users recorded in the knowledge graph and the target social relationships included in the data access request, determine the user identities corresponding to the first user and the second user in the knowledge graph; based on the user identity corresponding to the second user, locate the target data and obtain the access permissions set by the first user for the target data, as the target access permissions of the second user for the target data.
[0067] The following examples illustrate the content included in the knowledge graph and the implementation process of constructing the knowledge graph: In some embodiments, the knowledge graph (schema) includes person nodes corresponding to each user among multiple users, data nodes corresponding to each data in at least one data set, and relationship edges. The relationship edges include a first relationship edge and a second relationship edge. The first relationship edge is used to connect two person nodes and represents the social relationship between the users corresponding to the two person nodes. The second relationship edge is used to connect a person node and a data node and represents the access rights of the user corresponding to the person node to the data corresponding to the data node.
[0068] Furthermore, the nodes included in the aforementioned knowledge graph may also be referred to as entities or other descriptions, and this application embodiment does not limit this.
[0069] Through the above embodiments, personnel nodes and data nodes can be set in the knowledge graph. The first relation edge represents the social relationship between users, and the second relation edge represents the user's access permission to data. This enables a clear sorting and association of personnel identities, interpersonal social relationships, and data access permissions in a family setting. It effectively solves the problem of the disconnect between social relationship and data permission configuration in traditional permission control methods, and also provides practical information support for automatically matching the corresponding data access permissions based on the social relationship between users.
[0070] For example, for any user, the personnel nodes in the knowledge graph that have social connections with that user may include at least one of the following: the personnel node corresponding to the father, the personnel node corresponding to the mother, the personnel node corresponding to the eldest son, and the personnel node corresponding to the youngest daughter. The above is an exemplary description of personnel nodes. The personnel nodes involved in the embodiments of this application may also include personnel nodes corresponding to friends or teachers, and the embodiments of this application are not limited in this regard.
[0071] Data nodes include at least one of the following: data nodes corresponding to memo entries, data nodes corresponding to private photos, and data nodes corresponding to reminders.
[0072] For the first relationship edge, it can include at least one of the following: spousal relationship (is_spouse_of) edge, parent-child relationship (is_child_of) edge, and parent-child relationship edge. The spousal relationship edge here can also be replaced by descriptions such as husband-wife relationship edge, wife relationship edge, or husband-wife relationship edge, etc.; the parent-child relationship edge here can also be replaced by descriptions such as father-son relationship edge, father-daughter relationship edge, mother-son relationship edge, or mother-daughter relationship edge, etc.; and the parent-child relationship edge here can also be replaced by descriptions such as father relationship edge or mother relationship edge, etc. This application embodiment does not limit the above-mentioned alternative descriptions.
[0073] The above is an exemplary description of the first relationship edge. The first relationship edge described in the embodiments of this application may also include other relationship edges, such as friend relationship edges or teacher-student relationship edges. The embodiments of this application do not limit this.
[0074] For any data node in the knowledge graph, the second relation edge includes at least one of the following: an edge connecting any data node to the personnel node corresponding to the target user, where the target user is the user who created the data of any data node; an edge connecting the personnel node corresponding to each user in the first user group to any data node, where each user in the first user group is allowed to access the data corresponding to any data node; and an edge connecting the personnel node corresponding to each user in the second user group to any data node, where each user in the second user group is prohibited from accessing the data corresponding to any data node.
[0075] For example, in a family finance and bill sharing scenario: the data nodes corresponding to the bill data of a joint couple's account are linked to the corresponding personnel nodes of both spouses through an "allow access" relationship (visible_to), ensuring that both spouses have joint viewing rights; the data nodes corresponding to personal private consumption records are only bound to the personnel node corresponding to the creator through a data ownership relationship (owned_by), and other family members have no access rights by default; the data nodes for payment notices can temporarily establish an "allow access" relationship (visible_to) linked to the personnel nodes corresponding to children to achieve short-term targeted authorization; at the same time, all data nodes corresponding to financial data are uniformly configured with an "blocked access" relationship (blocked_from) linked to the personnel nodes corresponding to friends, restricting external personnel access from the source, and comprehensively adapting to the hierarchical isolation management requirements of family financial data.
[0076] For example, in a camera video access control scenario, the node corresponding to the video data collected by the living room camera is associated with all family members' nodes through an "allow access" relationship edge, allowing all family members to view the playback content; the video data node collected by the bedroom camera is only bound to the nodes of the spouses through an "allow access" relationship edge, allowing only the spouses to access and view the content. When the interactive device switches to visitor mode, it can automatically establish an "disallow access" relationship edge for security data nodes in sensitive areas such as the bedroom, blocking the image content in private areas and avoiding the risk of privacy leaks.
[0077] For example, in a scenario of hierarchical access control for access records, the nanny's personnel node only establishes an access permission relationship with the data node corresponding to the entry and exit records, and can only view her personal access records; the personnel nodes corresponding to each family member establish a general access permission relationship with the data node corresponding to all access control records, and have the right to view complete access control data; after identifying an abnormal intrusion event and generating alarm data, the data node corresponding to the alarm data will automatically establish an association relationship with the personnel nodes corresponding to all adult family members, and push abnormal security alarm notifications to all adult members in real time.
[0078] Through the above embodiments, the second relationship edge can be refined into data ownership relationship edge, allowed access relationship edge, and prohibited access relationship edge, which makes a fine division of the permissions between personnel and data, clarifies the graph expression form of different permissions, and provides a clear and quantifiable basis for data permission judgment. It can accurately adapt to the differentiated and personalized data access permission configuration needs in the family scenario and realize the fine-grained management of data access permissions.
[0079] In this context, the data ownership edge is used to clarify the subject that created the data. That is, only the personnel node corresponding to the user who created the data can establish a data ownership edge with the data node corresponding to that data. Where S is the personnel node corresponding to the user who created the data, and D is the data node corresponding to the data. The user who created the data has the authority to adjust the permissions for accessing the data. In addition, users who have a specific social relationship with the user who created the data may also have the authority to adjust the permissions for accessing the data; or, the user who created the data may also authorize other users to adjust the permissions for accessing the data.
[0080] Allow access edges are used to configure the authorized access scope of data. For example, all personnel nodes corresponding to users in the first user group can establish allow access edges with any of the aforementioned data nodes. Where T is the personnel node corresponding to all users in the first user group, and thus all users in the first user group can be granted access to any data based on the access permission relationship.
[0081] Access-restricted edges are used to define the scope of data access restrictions. For example, all personnel nodes corresponding to users in the second user group can establish access-restricted edges with any of the aforementioned data nodes. Where Y represents the personnel node corresponding to all users in the second user group, and thus, access rights to any data can be blocked for all users in the second user group based on this access prohibition relationship.
[0082] For example, such as Figure 4As shown, the knowledge graph includes one data node and three personnel nodes, and the nodes are associated with each other through the first relation edge and the second relation edge.
[0083] Among them, the data node in the knowledge graph is the data node corresponding to the "birthday surprise memo". The node identifier of this data node is memo_001. The data content stored in this data node is "buying Lego toys", which is used to record the items for preparing a birthday surprise for the child.
[0084] The personnel nodes in the knowledge graph include: the personnel node corresponding to the mother, the personnel node corresponding to the father, and the personnel node corresponding to the son. The node identifier for the personnel node corresponding to the mother is P01, and the social relationship is mother or wife; the node identifier for the personnel node corresponding to the father is P02, and the social relationship is father or husband; the node identifier for the personnel node corresponding to the son is P03, and the social relationship role is son or child.
[0085] The first relationship edges between personnel nodes include: the spousal relationship edge between the personnel node corresponding to the mother and the personnel node corresponding to the father, the mother-child relationship edge or parent-child relationship edge between the personnel node corresponding to the mother and the personnel node corresponding to the son, and the father-child relationship edge or parent-child relationship edge between the personnel node corresponding to the father and the personnel node corresponding to the son.
[0086] The second relationship edges between data nodes and personnel nodes include: a data ownership relationship edge between the data node corresponding to "Birthday Surprise Memo" and the personnel node corresponding to "Mom"; an access permission relationship edge between the data node corresponding to "Birthday Surprise Memo" and the personnel node corresponding to "Dad"; and a prohibition of access relationship edge between the data node corresponding to "Birthday Surprise Memo" and the personnel node corresponding to "Son".
[0087] In addition, all of the above-mentioned second relationship edges support independent configuration. Based on actual permission management needs, operations such as adding, modifying or deleting second relationship edges can be performed at any time to ensure that the relationship edges between personnel nodes and data nodes in the knowledge graph are consistent with the actual application scenarios in real time.
[0088] In some embodiments, the second relationship edge can be not only a simple data ownership relationship edge, an allowed access relationship edge, or a prohibited access relationship edge, but also a relationship edge corresponding to time-based data access permissions. That is, by adding a timestamp attribute to the second relationship edge, the second relationship edge can be made effective only within a specific time period. For example, in a chronic disease management collaboration scenario, patients can create a data node corresponding to "medication reminder" and establish an allowed access relationship edge between the personnel node corresponding to the attending physician and the personnel node corresponding to the spouse, which will be effective within a fixed time period.
[0089] As mentioned earlier, a knowledge graph includes person nodes, data nodes, a first relation edge representing the social relationship between two person nodes, and a second relation edge representing the access permissions of a person node to a data node. The following section combines... Figure 5 The implementation process of constructing this knowledge graph will be illustrated with examples.
[0090] like Figure 5 As shown, the knowledge graph is constructed through the following steps S501 to S503: S501. Obtain social relationship information between multiple users, establish a personnel node for each user, and establish a first relationship edge between personnel nodes based on the social relationship information.
[0091] For example, social relationship information can be obtained through at least one of the following methods: Method 1: During the user registration phase, multiple users actively fill in their social relationship information.
[0092] Specifically, when registering a family application account, users can fill in their social relationships with other registered users. Based on these social relationships, the first relationship edge can be established between the corresponding user's personnel nodes, quickly completing the construction of the initial social relationship.
[0093] Method 2: Multiple users manually configure social relationship information within the application.
[0094] Specifically, users can manually add, modify, or delete social relationships with other users through the "Family Relationship Management" and other functional modules within the application. For example, they can mark a user as a "spouse" or "child," or adjust existing social relationships. Then, based on the user's configuration operations, the first relationship edge between the corresponding personnel nodes is updated synchronously to ensure that the social relationship information is consistent with the actual family structure, so as to adapt to scenarios such as changes in family members and relationships.
[0095] Method 3: Automatically mine weak relationships based on user behavior habits, and use weak relationships to assist in reasoning about social relationships.
[0096] Specifically, by analyzing behavioral data such as device sharing operations, activity records in the same physical area, and high-frequency message interactions among multiple users, characteristics such as the frequency of interaction and shared behaviors among users are identified, and weak associations are generated based on these characteristics. These weak associations are not directly used as the basis for determining data access permissions, but only to assist in the reasoning of social relationships. For example, when social relationships are not explicitly set, the degree of intimacy between users can be inferred by combining weak associations, so that social relationships can be improved based on the degree of intimacy between users.
[0097] For example, in a family health setting, a weak relationship between the patient and their family member can be generated based on the frequency of their interaction.
[0098] Furthermore, this application embodiment does not limit the number of personnel nodes included in the knowledge graph or the number of first relation edges.
[0099] S502, In response to the creation information of the first data by any one of the multiple users, create a corresponding first data node for the first data.
[0100] The information creation includes at least the information of any user and the data content of the first data.
[0101] Specifically, when any user initiates the creation of the first data within the application and generates the creation information of the first data, a corresponding first data node can be established separately for the first data in the pre-built knowledge graph.
[0102] In some embodiments, the first data mentioned above may be data pre-included in a pre-built knowledge graph, or it may be newly added data to the knowledge graph during subsequent use. This application embodiment does not limit this.
[0103] S503. Establish a second relation edge for the first data based on the creation information.
[0104] In some embodiments, at least one second relation edge for the first data further includes: an access permission relation edge between the personnel node corresponding to other users and the first data node, and / or an access prohibition relation edge between the personnel node corresponding to other users and the first data node.
[0105] Specifically, when a user creates the first data, a data ownership relationship edge can be automatically established between the user node and the first data node.
[0106] If the user configures a shared permission-related intent when creating the first data, the shared permission-related intent can be parsed, and an access permission relationship edge can be established in the knowledge graph between the personnel nodes corresponding to other users with shared permissions and the first data node.
[0107] For example, if the intent related to sharing permissions includes a specific kinship term such as "wife", then in the knowledge graph, we can search for related personnel nodes that have a spouse-like social relationship with the personnel node that created the first data (that is, personnel nodes corresponding to other users with sharing permissions), and establish an access permission relationship edge between the related personnel node and the first data node.
[0108] In addition, at least one second relation edge for the first data also includes: an access permission relation edge between the personnel group node corresponding to other users and the first data node.
[0109] For example, if the intent related to sharing permissions includes specific kinship group terms such as "children", then in the knowledge graph, we can search for related personnel group nodes that have a parent-child social relationship with the personnel node that created the first data (that is, the personnel group nodes corresponding to other users with sharing permissions), and establish an access permission relationship edge between the related personnel group node and the first data node.
[0110] If the user configures a prohibition intent when creating the first data, the prohibition intent can be parsed, and prohibition access relationship edges can be established in the knowledge graph between the personnel nodes corresponding to other users with prohibition permissions and the first data node.
[0111] In addition, at least one second relation edge for the first data also includes: a prohibited access relation edge between the personnel group node corresponding to other users and the first data node.
[0112] The descriptions of the prohibited access relationship edges between the personnel nodes corresponding to other users and the first data node, and the prohibited access relationship edges between the personnel group nodes corresponding to other users and the first data node, can be understood by referring to the descriptions of the permitted access relationship edges between the personnel nodes corresponding to other users and the first data node, and the permitted access relationship edges between the personnel group nodes corresponding to other users and the first data node. They will not be repeated here.
[0113] The above embodiments can define the specific construction method of the knowledge graph, that is, to establish personnel nodes and first relationship edges based on actual social relationship information, and to establish data nodes and second relationship edges based on the creation information of the first data, so that the establishment of the knowledge graph is highly consistent with the actual scenario, thereby ensuring the authenticity and validity of the data in the knowledge graph, and providing reliable data support for the subsequent determination of data access permissions based on the knowledge graph.
[0114] In some embodiments, the personnel node further includes a personnel group node, and the relationship edge further includes a third relationship edge; for any user among multiple users, the third relationship edge is used to connect the personnel node corresponding to any user with the personnel group node corresponding to the personnel group to which the user belongs, and the third relationship edge represents the affiliation relationship between any user and the personnel group to which the user belongs.
[0115] Through the above embodiments, personnel group nodes and third-party relation edges representing the affiliation between personnel and personnel groups can be added to the knowledge graph to support batch data access permission configuration operations for personnel within a personnel group. This avoids the tedious operation of configuring data access permissions for each user in a personnel group individually, thereby improving the efficiency of group data access control in multi-user family scenarios and perfectly adapting to the data access permission configuration needs of groups such as "whole family" and "children".
[0116] In some embodiments, personnel group nodes may also establish a second relationship edge with data nodes. For a description of the second relationship edge, please refer to the description of the second relationship edge established between personnel nodes and data nodes. It will not be repeated here.
[0117] For example, a personnel group node may include at least one of the following: a children group node, a spouse group node, and a family group node. The above is an exemplary description of personnel group nodes. The personnel group nodes described in this application embodiment may also include other nodes, such as a friends group node, and this application embodiment does not limit this.
[0118] In this context, child group nodes can establish third-party relationship edges with the personnel nodes corresponding to all minor children in the family. For example, when parents create a set of learning materials and want all their children to be able to view them, they only need to establish an access permission relationship edge between the data node corresponding to the materials and the child group nodes to achieve batch authorization, without having to configure an access permission relationship edge separately for each personnel node corresponding to each child.
[0119] Couple group nodes can establish third-party relationship edges with the corresponding personnel nodes of the spouses in the family. For example, when one spouse creates family financial data and wants the other spouse to manage it jointly, it is only necessary to establish a data ownership relationship edge or an access permission relationship edge between the data node corresponding to the family financial data and the couple group node to achieve batch authorization, without having to configure permission relationship edges for each spouse separately.
[0120] Family group nodes can establish third-party relationship edges with the personnel nodes corresponding to all family members. For example, when a user creates a family travel plan and wants the whole family to share it, they only need to establish an "allow access" relationship edge between the data node corresponding to the family travel plan and the family group node, and all family members will automatically gain permission to access the family travel plan. Furthermore, if they want to block a specific family member, they can additionally establish a "disallow access" relationship edge between the personnel node corresponding to that specific family member and the data node corresponding to the family travel plan.
[0121] A friend group node can establish a third-party relationship edge with the person node corresponding to the member marked as a friend. For example, when a user creates a friend party arrangement and wants all friends to share it, they only need to establish an "allow access" relationship edge between the data node corresponding to the friend party arrangement and the friend group node. All members within the friend group will automatically gain permission to access the friend party arrangement. Furthermore, if they also want to block a specific friend, they can additionally establish a "disallow access" relationship edge between the person node corresponding to that specific friend and the data node corresponding to the friend party arrangement.
[0122] As mentioned earlier, a knowledge graph includes not only personnel nodes, data nodes, first relation edges representing the social relationship between two personnel nodes, and second relation edges representing the access rights of personnel to data corresponding to data nodes, but also personnel group nodes and third relation edges representing the affiliation relationship between any user and any personnel group to which that user belongs. Furthermore, the following section supplements the implementation of knowledge graph construction, providing examples of the process of constructing personnel group nodes and third relation edges within the knowledge graph.
[0123] In some embodiments, the process of constructing personnel group nodes and third relation edges in a knowledge graph can be as follows: obtaining personnel group configuration information and creating at least one corresponding personnel group node based on the personnel group configuration information, wherein the personnel group configuration information is used to configure at least one personnel group. A third relation edge is created between the personnel node corresponding to a user in the target personnel group and the target personnel group node corresponding to the target personnel group, wherein the target personnel group is any one of the at least one personnel group.
[0124] Current access control systems generally suffer from rigid management models and heavy maintenance burdens. The permission configurations in the aforementioned access control systems adopt a static binding design, which lacks the logical inheritance attribute of social relationships and cannot dynamically and adaptively adjust permissions according to changes in interpersonal relationships.
[0125] Specifically, when family structure changes, such as the addition of new family members, children becoming adults and independent, changes in kinship, or adjustments to status, administrators need to manually modify and configure access permissions for each item in the access control system's large amount of historical data, such as previously created memos, reminders, private photos, and personal documents. This method cannot achieve synchronized linkage between interpersonal relationships and data permissions, nor can it automatically adapt data access permissions to changes in social relationships. It relies entirely on manual maintenance, which is not only tedious and labor-intensive but also prone to issues such as missing permissions and configuration errors.
[0126] To address the aforementioned maintenance challenges, the data access control method provided in this application adds a scheme for dynamically updating the knowledge graph based on social relationships. This scheme includes at least one of the following operations: Step 1: In response to the addition of a fourth user to the social relationship information, create a corresponding personnel node for the fourth user in the knowledge graph, and establish corresponding relationship edges for the personnel node. This allows for rapid completion of the personnel structure in the knowledge graph, eliminating the need for manual data entry and configuration, and reducing operational costs.
[0127] The relationship edges established for the personnel nodes corresponding to the fourth user here may include the first relationship edge and / or the second relationship edge.
[0128] For example, when a newborn or remarried family member is added to a family, the system can identify the identity information and social relationships of the new fourth user, automatically generate the corresponding personnel node in the knowledge graph, and establish corresponding first relationship edges for the personnel node corresponding to the fourth user in batches based on the social relationship between the fourth user and the original family members.
[0129] Simultaneously, a second relationship edge will be automatically established between some data nodes and the newly added fourth user. For example, for data marked as "visible to all family members," since the newly added fourth user is a family member, an access permission relationship edge can be automatically generated between the data node corresponding to the "visible to all family members" data and the personnel node corresponding to the newly added fourth user, thereby achieving automatic granting of data access permissions without manual configuration.
[0130] Step 2: In response to changes in the social relationships between the fifth user and other users in the knowledge graph, update the relationship edges corresponding to the personnel node of the fifth user based on the changed social relationships. This way, only the relationship edges corresponding to the personnel node of the fifth user need to be modified, without needing to traverse and modify all historical permission configurations associated with the fifth user, simplifying the operation and maintenance process and significantly reducing maintenance costs.
[0131] The relation edges corresponding to the personnel node of the fifth user here may include the first relation edge and / or the second relation edge.
[0132] For example, when a romantic relationship between users is upgraded to a marital relationship, or a guardianship relationship is adjusted, or a change in kinship status occurs, the first relationship edge corresponding to the personnel node of the aforementioned user in the knowledge graph can be automatically updated.
[0133] Furthermore, the above operations are exemplary illustrations of operations for updating a knowledge graph. Operations for updating a knowledge graph may also include other operations, which are illustrated below: In one example, in response to a change in the user who is allowed to access certain data, the relationship edge between the data node corresponding to a certain data in the knowledge graph and the personnel node corresponding to the changed user is updated based on the information of the changed user who is allowed to access certain data.
[0134] For example, in family health and remote care scenarios, the elderly’s health data (e.g., heart rate, blood pressure, etc.) is only visible to their children. When the children need to change the primary caregiver due to job transfer, the second relationship edge in the knowledge graph can be automatically adjusted according to the information of the users who are allowed to access the elderly’s health data, so as to realize the dynamic migration of data access permissions.
[0135] In another example, in response to the evolution over time, the relationship edge between a data node corresponding to a certain data and a certain person node in the knowledge graph is updated.
[0136] For example, in the context of pregnancy and childbirth health management, "prenatal check-up reminders" are visible only to the partner, and "psychological diary" is visible only to oneself. The sharing strategy can be automatically adjusted according to the stage of pregnancy, and more health data access can be automatically granted to the spouse in the late stage of pregnancy.
[0137] For example, in the scenario of controlling the use of children's devices, "learning materials" can be seen by the whole family, while "game records" can be seen only by parents. As the child gets older, the access permissions for "game records" can be adjusted accordingly.
[0138] After the knowledge graph is constructed and / or updated, it can be used to determine the target access permissions (i.e., S302) for a second user to the target data. Further, the following... Figure 6 The implementation process of S302 above will be illustrated with an example.
[0139] like Figure 6 As shown, the above-mentioned S302 implementation process can be achieved through the following S601 to S604: S601, Obtain the third person node corresponding to the third user.
[0140] In some embodiments, the implementation process of S601 described above can be as follows: based on the identity identifier of the third user carried in the data access request, a matching query is performed in a pre-built knowledge graph to obtain the third person node corresponding to the third user. Here, a unique person node is pre-established for each user in the knowledge graph, and the identity identifier includes at least one of user account, mobile phone number, ID card information, or biometric information.
[0141] If there is no personnel node corresponding to the third user in the knowledge graph, a new personnel node is created based on the identity information of the third user, and a first relationship edge is established between the newly created personnel node and the existing personnel node based on the social relationship information carried in the data access request.
[0142] S602. In the knowledge graph, based on the target social relationship, starting from the third person node and following the first relationship edge, determine the first person node corresponding to the first user and the second person node corresponding to the second user.
[0143] In some embodiments, the first user, the second user, and the third user are different from each other. The implementation process of S602 described above can be as follows: based on the target social relationship, starting from the third person node, along the first relationship edge representing the target social relationship, determine the first person node corresponding to the first user and the second person node corresponding to the second user.
[0144] For example, consider a scenario where the first user, the second user, and the third user are all different, and the target social relationships include a first social relationship between the third user and the first user, and a second social relationship between the third user and the second user: Assuming the third user is the child, the first user is the mother, and the second user is the father, and the data access request is "the child requests authorization for the father to view the report card created by the mother," meaning the target data is the "report card," and the target social relationships include "mother-child relationship" and "father-child relationship," then based on the "mother-child relationship," starting from the third user node corresponding to the child, we locate the first user node corresponding to the mother along the first relationship edge representing the "mother-child relationship"; based on the "father-child relationship," starting from the third user node corresponding to the child, we locate the second user node corresponding to the father along the first relationship edge representing the "father-child relationship."
[0145] For example, consider a scenario where the first user, the second user, and the third user are all different, and the target social relationships include a second social relationship between the third user and the second user, and a third social relationship between the first user and the second user: Assuming the third user is the child, the first user is the mother, and the second user is the father, and the data access request is "the child requests authorization for the father to view the report card created by his wife," meaning the target data is "report card," and the target social relationships include "father-child relationship" and "spouse relationship," then based on the "father-child relationship," starting from the third user node corresponding to the child, we locate the second user node corresponding to the father along the first relationship edge representing the "father-child relationship"; based on the "spouse relationship," starting from the second user node corresponding to the father, we locate the first user node corresponding to the mother along the first relationship edge representing the "spouse relationship."
[0146] In some embodiments, the first user is the same as the third user and different from the second user. The implementation process of S602 described above can be as follows: based on the target social relationship, starting from the third person node (i.e., the first person node), along the first relationship edge representing the target social relationship, determine the second person node corresponding to the second user.
[0147] For example, suppose the first user and the third user are both fathers, the second user is the mother, and the data access request is "the father requests authorization for the mother to view the family ledger he created", that is, the target data is "family ledger" and the target social relationship includes "marital relationship". Then, based on "marital relationship", starting from the third person node (that is, the first person node) corresponding to the father, along the first relationship edge representing "marital relationship", the location is located to the second person node corresponding to the mother.
[0148] In some embodiments, the first user is the same as the second user and different from the third user. The implementation process of S602 described above can be as follows: based on the target social relationship, starting from the third person node, along the first relationship edge representing the target social relationship, determine the first person node (i.e., the second person node) corresponding to the first user.
[0149] For example, suppose the first user and the second user are both children, the third user is the father, and the data access request is "the father requests authorization for the child to view his own report card", that is, the target data is "report card" and the target social relationship includes "father-child relationship". Then, based on the "father-child relationship", starting from the third person node corresponding to the father, along the first relationship edge representing the "father-child relationship", the location is located to the first person node corresponding to the child (i.e., the second person node).
[0150] S603. In the knowledge graph, based on the target data, determine the target data node corresponding to the target data from the second relation edge associated with the first personnel node, and determine the target second relation edge between the target data node and the second personnel node.
[0151] In some embodiments, in a knowledge graph, the process of determining the target data node corresponding to the target data from the second relation edge associated with the first personnel node may include: starting from the first personnel node, traversing the data nodes connected by the second relation edge associated with the first personnel node, matching the data identifier corresponding to the data node with the identifier information of the target data, and determining the successfully matched data node as the target data node.
[0152] For example, assuming the target data is "physical examination report" and the first personnel node is personnel node 1, then starting from personnel node 1, traverse the data nodes connected by the second relationship edge associated with personnel node 1 through "create relationship", and determine the data node whose name matches "physical examination report" as the target data node.
[0153] In some embodiments, the process of determining the target second relation edge between the target data node and the second personnel node may include: retrieving a second relation edge that directly connects the second personnel node and the target data node in the knowledge graph; if a second relation edge that directly connects the second personnel node and the target data node exists in the knowledge graph, then the second relation edge that directly connects the second personnel node and the target data node is determined as the target second relation edge.
[0154] If there is no second relation edge directly connecting the second person node and the target data node in the knowledge graph, then all reachable association paths from the second person node to the target data node are retrieved in the knowledge graph, and the second relation edges existing on each path are analyzed one by one to determine the target second relation edge between the second person node and the target data node.
[0155] For example, assuming the target data is a report card, the first user is the teacher, the second user is the father, and there is no direct first relationship edge between the second user and the teacher, then by using the personnel node corresponding to the second user's child (i.e., the intermediate personnel node), the first relationship edge between the second personnel node and the personnel node corresponding to the child (e.g., parent-child relationship) and the first relationship edge between the personnel node corresponding to the child and the personnel node corresponding to the teacher (e.g., teacher-student relationship) are determined. This constructs a social relationship path from the second personnel node through the personnel node corresponding to the child to the personnel node corresponding to the teacher. Then, by using the second relationship edge between the personnel node corresponding to the teacher and the data node corresponding to the report card, a complete path is constructed from the second personnel node to the data node corresponding to the report card. This determines that there is an accessible target second relationship edge between the second personnel node and the data node corresponding to the report card.
[0156] Furthermore, during the aforementioned search and analysis of reachable paths, scenarios where a second personnel node indirectly obtains access permissions through a personnel group node can also be considered. Specifically, it is determined whether the second personnel node belongs to a certain personnel group node through a third relationship edge, and it is verified whether a second relationship edge exists between the personnel group node and the target data node. If an access-allowed relationship edge exists between the personnel group node and the target data node, then, combining the access-allowed relationship edge between the personnel group node and the target data node with the second relationship edges existing on each path, the target second relationship edge connecting the second personnel node and the target data node is determined.
[0157] Furthermore, during the search and analysis of reachable paths described above, if any access-prohibited edge is found in any of the retrieved paths, the search for other paths in the knowledge graph will be terminated.
[0158] S604. Determine the target access permissions based on the target's second relation edge.
[0159] In some embodiments, if the target second relationship edge connecting the second user node and the target data node only contains a data ownership relationship edge, that is, the target second relationship edge connecting the second user node and the target data node does not contain an access permission relationship edge or an access prohibition relationship edge, then it is determined that the second user does not have permission to access the target data.
[0160] For example, a data node corresponding to the mother's personal prenatal check-up report is created. There is a data ownership relationship edge between the data node corresponding to the personal prenatal check-up report and the mother's personnel node. In the target second relationship edge associated with the prenatal check-up report data node, only the data ownership relationship edge can be retrieved. There are no allowed access relationship edges or prohibited access relationship edges. At this time, it is determined that only the mother has the right to access the prenatal check-up report.
[0161] If the target second relationship edge connecting the second user node and the target data node contains only a prohibited access edge, that is, if the target second relationship edge connecting the second user node and the target data node does not contain a permitted access edge, then it is determined that the second user does not have permission to access the target data.
[0162] For example, a data node corresponding to the family financial plan is created for the father. To prevent the child from accidentally viewing or operating it, a separate prohibited access relationship edge is created between the child's personnel node and the data node corresponding to the financial plan. That is, there is no allowed access relationship edge in the target second relationship edge between the child's personnel node and the data node corresponding to the financial plan, only the prohibited access relationship edge exists. In this case, it is determined that the child does not have the permission to access the family financial plan.
[0163] If the target second relationship edge connecting the second user node and the target data node contains only allowed access edges, that is, if the target second relationship edge connecting the second user node and the target data node does not contain prohibited access edges, then it is determined that the second user has the permission to access the target data.
[0164] For example, the mother creates a data node corresponding to the family weekend trip plan and establishes an access permission relationship edge between the father's personnel node and the data node corresponding to the family weekend trip plan. That is, there is no prohibited access relationship edge in the target second relationship edge between the father's personnel node and the data node corresponding to the family weekend trip plan, only the access permission relationship edge exists. In this case, it is determined that the father has the permission to access the family weekend trip plan.
[0165] For example, after creating a data node for the family's New Year's shopping list for the mother, an access permission relationship edge is established with the family group node. The father is a member of the family group, and there is no access permission relationship edge in the target second relationship edge between the father's corresponding personnel node and the data node corresponding to the shopping list. At this time, it is determined that the father has the permission to access the shopping list.
[0166] If a prohibited access edge exists in the target second relationship edge connecting the second user node and the target data node, then even if an allowed access table exists in the target second relationship edge connecting the second user node and the target data node, it is determined that the second user does not have permission to access the target data. In other words, when comprehensively analyzing the target second relationship edge connecting the second user node and the target data node, the rule that prohibited access edges take precedence over allowed access edges is followed.
[0167] For example, a data node corresponding to the family travel budget is created for the father, and an access permission edge is established between the family group node and the data node corresponding to the family travel budget. To prevent the child from knowing the budget, a separate access prohibition edge is established between the child's personnel node and the data node corresponding to the family travel budget. At this time, the target second relationship edge between the child's personnel node and the data node corresponding to the family travel budget contains both indirect access permission edges and direct access prohibition edges. Following the judgment rule that access prohibition edges take precedence over access permission edges, it is determined that the child does not have the right to access the family travel budget.
[0168] The above embodiments clearly define the process for determining target access permissions based on knowledge graphs, forming a practical and traceable data access permission determination process. This ensures the accuracy and standardization of automatically determining data access permissions based on knowledge graphs, and effectively improves the degree of automation in data access control.
[0169] S303. Control the second user's access to the target data according to the target access permissions.
[0170] In some embodiments, the implementation of S303 above can be as follows: in response to the target access permission only including indicating that the second user has permission to access the target data, the second user is allowed to access the target data. Thus, access authorization can be directly determined based solely on the permission to access the data, simplifying the process of controlling the second user's access to the target data and thereby improving access control efficiency.
[0171] In this embodiment of the application, the second user may include only one user or multiple users, and this embodiment of the application does not limit this.
[0172] Taking a knowledge graph that does not include personnel group nodes as an example: For any second user, when the second relationship edge between the target data node and the second personnel node in the knowledge graph only includes the allowed access relationship edge, the second user is allowed to access the target data.
[0173] For example, if a first user creates a prenatal checkup memo and grants his wife viewing access to it, the knowledge graph will only generate an access permission edge between the target data node corresponding to that prenatal checkup memo and the second person node corresponding to the wife. There are no configurations that restrict access to certain relationships. At this time, all family members can access the travel plan data normally.
[0174] Taking a knowledge graph that includes personnel group nodes as an example: For any second user, when the second relationship edge between the target data node and the target personnel group node corresponding to the second user in the knowledge graph only includes the allowed access relationship edge, and the second relationship edge between the target data node and the second personnel node also only includes the allowed access relationship edge, the second user is allowed to access the target data.
[0175] For example, if a mother creates a family travel itinerary and grants viewing access to all family members, the knowledge graph will only generate access permission edges between the target data node corresponding to the family travel itinerary and the corresponding target personnel group nodes for each family member. There are no configurations that restrict access to certain relationships. At this point, all family members can access the travel plan data normally.
[0176] In other embodiments, the implementation of S303 above can be as follows: in response to the target access permission including indicating that the second user does not have permission to access the target data, the second user is prohibited from accessing the target data. This achieves explicit blocking of data access requests, avoids unauthorized access that may result from permission inheritance or indirect authorization, and enhances the security of data access control.
[0177] Taking a knowledge graph that does not include personnel group nodes as an example: For any second user, if the second relationship edge between the target data node and the personnel node corresponding to the second user in the knowledge graph only includes the prohibited access relationship edge, then the second user is directly prohibited from accessing the target data.
[0178] For example, if a father creates a private financial record and sets it to be inaccessible to his children, the knowledge graph will only have an access-restricted edge between the target data node corresponding to the private financial record and the second person node corresponding to the child. The child will be directly blocked and unable to view the private data.
[0179] When there are multiple authorization path conflicts, such as when a piece of data is configured to be visible to the whole family, but is also set to be blocked from specific relatives (e.g., the son), the Boolean logic in the current data access control method is difficult to adapt to the data access conflict caused by social priority.
[0180] Specifically, when handling multiple authorization path conflicts using access control lists (ACLs), simple Boolean logic (e.g., overwrite or append) is typically employed, rather than a knowledge graph-based rule that prioritizes prohibited access edges over permitted access edges. This approach fails to meet the complex needs of "shared access for all, isolated access for individual users" in a home setting. Furthermore, the aforementioned methods are highly susceptible to vulnerabilities when handling multiple authorization path conflicts: either excessively restricting data access permissions prevents compliant users from accessing data normally, or lax data access control leads to privacy breaches.
[0181] To address the data access permission conflict caused by the coexistence of multiple authorization paths, the data access control method provided in this application introduces a determination rule that prohibits access relationships over allows access relationships.
[0182] Specifically, taking a knowledge graph that does not include personnel group nodes as an example: for any second user, when the second relationship edge between the target data node and the personnel node corresponding to the second user in the knowledge graph includes both allowed access and prohibited access edges, the second user is prohibited from accessing the target data.
[0183] Specifically, taking a knowledge graph that includes personnel group nodes as an example: for any second user, if the second relationship edge between the target data node and the personnel node corresponding to the second user in the knowledge graph, and the second relationship edge between the target data node and the personnel group node corresponding to the second user, include at least a prohibited access relationship edge, then the second user is directly prohibited from accessing the target data.
[0184] For example, creating a family reminder record for the father and granting access to all family members would include, in the knowledge graph, an edge showing the allowed access relationship between the data node corresponding to this family reminder record and the family member group node. To protect privacy, the younger son's access permissions are blocked separately. The knowledge graph also includes a prohibited access edge between the target data node corresponding to the family reminder data and the second person node corresponding to the son. Since the data access control method provided in this application follows the rule that prohibited access edges take precedence over allowed access edges, even if the son belongs to the family group, the younger son will be denied access to the financial reminder data, effectively avoiding permission conflict vulnerabilities.
[0185] For example, if a family reminder is created for the father and access is denied to all family members, the knowledge graph will include an edge indicating the denied access relationship between the data node corresponding to the family reminder and the family member group node. At this point, if the knowledge graph also includes an access permission edge between the target data node corresponding to the family reminder data and the second person node corresponding to the son, that is... Therefore, the data access control method provided in this application follows the rule that prohibited access relationships take precedence over allowed access relationships, and will refuse the younger son from viewing the financial reminder data, effectively avoiding permission conflict vulnerabilities.
[0186] The above method allows for setting a rule that prioritizes prohibited access relationships over permitted access relationships. This effectively resolves the data access permission conflict between the same data node and the same user node caused by the coexistence of batch authorization and exception settings, ensuring the certainty and consistency of data access permission determination results. At the same time, the rule that prioritizes prohibited access relationships over permitted access relationships simplifies the data access permission verification process, avoids complex verification calculations, and improves the efficiency of data access control.
[0187] Current data access control methods often focus only on "who has the right to access the data," while neglecting the dimension of "in what physical environment the data is accessed."
[0188] Specifically, although current data access control methods include tag-based permission management mechanisms, they are usually limited to a binary correspondence between people and data, lacking a relationship between data and location. For example, even if certain private data (such as medical reports or reminders about hidden savings) is set to be visible only to a spouse, if the spouse inquires about it through a smart speaker in a public area such as the living room, it is very likely that the private data will be directly read aloud, easily leading to the information being leaked to non-target audiences (such as guests or children present).
[0189] In addition, current geofencing technology is mostly used for macro-level positioning outdoors, and lacks the ability to perform fine-grained spatial semantic recognition based on areas such as bedrooms or living rooms in indoor scenarios, making it impossible to distinguish the differences in privacy attributes between different areas such as living rooms and bedrooms.
[0190] To address the aforementioned technical problems, the access control method provided in this application introduces device nodes and their physical location information into the knowledge graph, enabling adjustments to the display of target data based on the physical location information of the device nodes. The following, in conjunction with... Figure 7The process of allowing a second user to access the target data is further detailed, specifically by illustrating the process of adjusting the way the target data is displayed based on the physical area information of the device node.
[0191] The process of allowing a second user to access target data (i.e., adjusting the display method of target data based on the physical area information of the device node) may include: obtaining information about the target device, and searching for the target device node corresponding to the target device in a knowledge graph based on the target device information to determine the physical area where the target device node is located. If the privacy level of the physical area where the target device node is located is higher than a preset level, the second user is allowed to access the anonymized target data; or, if the privacy level of the physical area where the target device node is located is lower than a preset level, the second user is allowed to access the complete target data.
[0192] The target device is the device that feeds back the target data to the second user.
[0193] The target device information is identification information that can uniquely identify the target device. For example, the target device information includes at least one of the following: device name, device unique serial number, hardware address, and bound account identification code, so that the target device information can be used as the basis for retrieving the device node corresponding to the target node in the knowledge graph.
[0194] The physical area information of the target device node refers to the annotation information (e.g., the annotation name of the area) of the target device node that is stored in the knowledge graph in advance, and the annotation information of the area is associated with the preset privacy level of the corresponding space. For example, the knowledge graph pre-labels the physical area corresponding to the smart speaker node in the living room as the living room, and the living room is a low privacy public area; as another example, the physical area corresponding to the tablet node in the master bedroom is the master bedroom, and the master bedroom is a high privacy private area.
[0195] In some embodiments, the privacy level can be set jointly based on the privacy of the physical area where the device node is located. For example, areas such as the living room and dining room, where family members frequently move around and are easily perceived by others, can be set to a low privacy level, while areas such as the master bedroom and study, which are only used by specific members, can be set to a high privacy level.
[0196] In this embodiment, the aforementioned preset level can be pre-configured based on daily usage experience and general privacy protection standards, and can also be dynamically updated according to changes in family privacy preferences and usage scenarios. This embodiment does not limit this.
[0197] Furthermore, the privacy level can be further determined by combining the types of devices within the area. For example, within the same master bedroom area, a smart speaker with voice broadcasting capabilities is considered a high-risk privacy exposure device, and the privacy level of the physical area where the smart speaker is located is correspondingly increased. Conversely, a smart lamp used only for lighting control has a lower privacy level in the physical area where the smart speaker is located. Through this approach, the setting of privacy levels is no longer limited to the area name itself, but integrates multiple factors such as the area's functional attributes, usage scenario characteristics, and device interaction methods. This makes subsequent data display strategies based on privacy levels more targeted and reasonable, achieving a deep integration of spatial dimensions and data access control.
[0198] Furthermore, the above method can be applied to scenarios where the target data is highly private. For example, health data such as medical examination reports can be set as highly private data, while family travel plans can be set as less private data.
[0199] In some embodiments, the specific implementation of the above-mentioned desensitization process can be configured differently according to the type of target data, privacy protection requirements, and interactive device form.
[0200] For text-based target data, anonymization can include: displaying only a summary or title of the target data while hiding its specific content; or obfuscating key information, for example, replacing "the medical examination report shows high blood pressure" with "there is a new medical examination report"; or replacing the complete content of the target data with a preset prompt text, for example, "please view details on a private terminal".
[0201] For voice broadcast scenarios, desensitization processing can include: replacing the full content reading with a prompt tone or a short voice broadcast, for example, only broadcasting "You have a private reminder, please view it on your mobile phone"; or, replacing sensitive information with a general expression to avoid directly exposing specific content in public areas.
[0202] Furthermore, the aforementioned data anonymization process can implement tiered anonymization strategies based on the data's sensitivity level. For example, for highly sensitive data, the full content can be displayed only in designated areas, while in areas with low privacy levels, it can be completely prohibited from being displayed or only a message indicating that information is available for review can be displayed. For moderately sensitive data, some non-critical information can be retained after anonymization. In this way, while ensuring data availability, the degree of information exposure can be dynamically adjusted according to the physical environment, achieving a balance between privacy protection and user experience.
[0203] For example, when a second user requests a reminder through a smart speaker, that smart speaker becomes the target device. The knowledge graph can then be used to determine whether the smart speaker is located in the living room or master bedroom. If the target device is located in a public area such as the living room, only a message such as "There is a private reminder" or "There is a medical report; please check the bedroom for details" is broadcast, without directly broadcasting the specific content of the target data. If the target device is located in a private space such as the master bedroom, the full content of the target data can be broadcast or displayed. The code in this case can be as follows: IF (User_Role has_permission) AND (Device_Location == Private_Space)THEN Return (Full_Content) ELSE IF (User_Role has_permission) AND (Device_Location == Public_Space) AND (Data_Sensitivity == High) THEN Return (Desensitized_Summary) ELSE Return (Access_Denied) The above solution effectively addresses the technical shortcomings of general technologies that focus solely on "who has the right to access the data" while neglecting "the physical environment in which the data is accessed." By incorporating device nodes and their physical locations into a knowledge graph, it breaks through the traditional permission model that only focuses on the correspondence between people and data. By comprehensively considering people, data, and the physical location of the devices, the way data is displayed is no longer limited to the user's identity but incorporates the privacy attributes of the current physical environment for comprehensive decision-making, achieving more accurate permission determination and more comprehensive privacy protection.
[0204] Furthermore, compared to the shortcomings of the aforementioned geofencing technology, which is mostly used for outdoor macro-positioning, this application introduces spatial recognition capabilities based on room or area granularity. This allows for the precise differentiation of privacy attributes in different areas such as living rooms and bedrooms, and the dynamic adjustment of data display methods according to the actual physical environment. This avoids the risk of privacy data being leaked through smart devices in public areas, significantly improving the precision and security of data access control in indoor scenarios.
[0205] As mentioned earlier, a knowledge graph can also include device nodes and information about the physical regions where those devices are located. Furthermore, the following section will supplement the implementation of knowledge graph construction, providing examples of the process of constructing device nodes and their physical regions within the knowledge graph.
[0206] In some embodiments, the process of constructing device nodes and the physical area information of the device nodes in the knowledge graph can be as follows: obtaining device deployment information and spatial layout information within the home, creating a corresponding device node for each device, and storing the physical area information of the device as an attribute of the device node when creating the device node.
[0207] Device deployment information can be obtained through device registration, network scanning, or manual addition by users. For example, the device deployment information includes at least one of the following: device identifier and device type (e.g., smart speaker, smart screen, etc.).
[0208] Spatial layout information can be obtained through user manual annotation, indoor positioning systems, or by linking with a home map. This spatial layout information is used to determine the physical area where each device is located. For example, the smart speaker in the living room is located in the "living room", and the smart screen in the master bedroom is located in the "master bedroom".
[0209] Create a device node D_001 for the "Living Room Smart Speaker" and set its physical area attribute to "Living Room"; create a device node D_002 for the "Master Bedroom Smart Screen" and set its physical area attribute to "Master Bedroom".
[0210] Furthermore, in some embodiments, based on the association between devices and users (e.g., device login accounts, frequently used device settings, or user-initiated binding), a fourth relationship edge can be constructed in the knowledge graph between device nodes and personnel nodes and / or personnel group nodes. This fourth relationship edge is used to indicate the primary user (or primary user group) or the user (or user group) to which the device belongs. For example, if a smart screen in the master bedroom is typically bound for shared use by the couple, then a fourth relationship edge is established between the device node corresponding to the smart screen in the master bedroom and the personnel nodes (or couple group nodes) corresponding to each spouse. As another example, if a smart speaker in the children's room is bound for the child's use, then a fourth relationship edge is established between the device node corresponding to the smart speaker in the children's room and the personnel node (or personnel group node) corresponding to the child.
[0211] Furthermore, the physical region attribute of device nodes supports dynamic updates. For example, when a device is moved from the living room to the master bedroom, only the physical region attribute value of the device node needs to be modified; there is no need to add or delete nodes, thus ensuring the accuracy and timeliness of the information.
[0212] In addition, in some embodiments, physical region nodes (or location nodes) can be created in the knowledge graph based on the physical region information where the device is located, and a fifth relation edge between the device node and the physical region node can be established in the knowledge graph. This fifth relation edge is used to characterize the affiliation between the device and its physical space, thereby clarifying the binding relationship between the deployment locations of each device and providing graph association support for subsequent permission reasoning and access control based on spatial privacy levels.
[0213] This application provides a data access control method that addresses data access requests carrying at least two of the following social relationships: the social relationship between a first user and a second user, the social relationship between a second user and a third user, and the social relationship between a first user and a third user. It leverages a pre-constructed knowledge graph that integrates social relationships and data access permissions, enabling direct perception of user relationships. This solves the technical problem of traditional access control schemes that can only identify physical identities but cannot understand social relationships. Furthermore, based on the target data and target social relationships, it automatically matches the second user's target access permissions to the target data within the knowledge graph and executes access control accordingly. This method eliminates the limitations of preset fixed roles, avoids complex manual configuration processes, and effectively bridges the semantic gap between natural language interaction and backend permission logic. While improving the accuracy and flexibility of access control, it significantly lowers the barrier to entry for smart homes and effectively enhances the interactive experience in multi-user smart home scenarios.
[0214] It is understood that, in order to achieve the above-mentioned functions, electronic devices include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the algorithm steps of the examples described in conjunction with the embodiments of this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in a hardware-driven or software-driven manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0215] This application embodiment can divide an electronic device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one functional module. The integrated module can be implemented in hardware or software. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the example of dividing each functional module according to each function.
[0216] Figure 7 This is a schematic diagram of the structure of an electronic device provided in some embodiments of this application, which can execute the data access control method provided in the above method embodiments. For example... Figure 7 As shown, the electronic device 70 includes a communication unit 701 and a processing unit 702.
[0217] The communication unit 701 is used for a data access request initiated by a third user. The data access request is used to request authorization for the second user to access target data created by the first user. The data access request includes target social relationships, which include at least two of the following: the social relationship between the first user and the second user, the social relationship between the second user and the third user, and the social relationship between the first user and the third user. Processing unit 702 is used to determine the target access permission of a second user to the target data in a pre-built knowledge graph based on the target data and the target social relationship; wherein, the knowledge graph includes social relationships between multiple users and access permissions of each of the multiple users to at least one piece of data, the multiple users include a second user and a third user, the at least one piece of data includes the target data, and the access permission is used to indicate whether the user has the permission to access the corresponding data. The processing unit 702 is also used to control the second user's access to target data according to the target access permissions.
[0218] In some embodiments, the knowledge graph includes personnel nodes corresponding to each user among multiple users, data nodes corresponding to each data in at least one data, and relation edges. The relation edges include a first relation edge and a second relation edge. The first relation edge is used to connect two personnel nodes and represents the social relationship between the users corresponding to the two personnel nodes. The second relation edge is used to connect personnel nodes and data nodes and represents the access rights of the user corresponding to the personnel node to the data corresponding to the data node.
[0219] In some embodiments, for any data node in the knowledge graph, the second relation edge includes at least one of the following: a data ownership relation edge connecting any data node and a personnel node corresponding to a target user, wherein the target user is the user who created the data of any data node; an access permission relation edge connecting the personnel node corresponding to each user in the first user group and any data node, wherein each user in the first user group is a user who is allowed to access the data corresponding to any data node; and a prohibition relation edge connecting the personnel node corresponding to each user in the second user group and any data node, wherein each user in the second user group is a user who is prohibited from accessing the data corresponding to any data node.
[0220] In some embodiments, the personnel node further includes a personnel group node, and the relationship edge further includes a third relationship edge; for any user among multiple users, the third relationship edge is used to connect the personnel node corresponding to any user with the personnel group node corresponding to the personnel group to which the user belongs, and the third relationship edge represents the affiliation relationship between any user and the personnel group to which the user belongs.
[0221] In some embodiments, the communication unit 701 is further configured to obtain the third person node corresponding to the third user; the processing unit 702 is specifically configured to: in the knowledge graph, based on the target social relationship, determine the first person node corresponding to the first user and the second person node corresponding to the second user along the first relationship edge starting from the third person node; in the knowledge graph, based on the target data, determine the target data node corresponding to the target data from the second relationship edge associated with the first person node, and determine the target second relationship edge between the target data node and the second person node; and determine the target access permission based on the target second relationship edge.
[0222] In some embodiments, the communication unit 701 is further configured to acquire social relationship information among multiple users, establish a personnel node for each user, and establish a first relationship edge between the personnel nodes based on the social relationship information; the processing unit 702 is further configured to respond to the creation information of any user among the multiple users for the first data, create a corresponding first data node for the first data, and establish a second relationship edge for the first data based on the creation information, wherein the creation information includes at least the information of any user and the data content of the first data.
[0223] In some embodiments, the processing unit 702 is further configured to: in response to the addition of a fourth user to the social relationship information, establish a personnel node corresponding to the fourth user in the knowledge graph and establish a corresponding relationship edge for the personnel node corresponding to the fourth user; in response to a change in the social relationship between the fifth user among the multiple users and other users among the multiple users, update the relationship edge corresponding to the personnel node corresponding to the fifth user in the knowledge graph based on the changed social relationship.
[0224] In some embodiments, the processing unit 702 is specifically configured to: allow the second user to access the target data in response to the target access permission only including indicating that the second user has permission to access the target data; or, prohibit the second user from accessing the target data in response to the target access permission including indicating that the second user does not have permission to access the target data.
[0225] In some embodiments, the knowledge graph further includes: device nodes and information about the physical regions where the device nodes are located; the communication unit 701 is further configured to acquire information about a target device, wherein the target device is a device that feeds back target data to a second user; the processing unit 702 is further configured to search for a target device node corresponding to the target device in the knowledge graph based on the information of the target device, so as to determine the physical region where the target device node is located; the processing unit 702 is further configured to allow the second user to access the de-identified target data if the privacy level corresponding to the physical region where the target device node is located is higher than a preset level; or, the processing unit 702 is further configured to allow the second user to access the complete target data if the privacy level corresponding to the physical region where the target device node is located is lower than a preset level.
[0226] In cases where the functionality of the integrated modules described above is implemented in hardware, some embodiments of this application provide another possible structure for the electronic device involved in the above embodiments. For example... Figure 8 As shown, the electronic device 80 includes a processor 802 and a bus 804. In one possible implementation, the electronic device 80 may further include a memory 801; optionally, the electronic device 80 may further include a communication interface 803.
[0227] Processor 802 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this application. Processor 802 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this application. Processor 802 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0228] The communication interface 803 is used to connect to other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.
[0229] The memory 801 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0230] As one possible implementation, the memory 801 can exist independently of the processor 802. The memory 801 can be connected to the processor 802 via a bus 804 and is used to store instructions or program code. When the processor 802 calls and executes the instructions or program code stored in the memory 801, it can implement the data access control method provided in the embodiments of this application.
[0231] In another possible implementation, the memory 801 can also be integrated with the processor 802.
[0232] The 804 bus can be an extended industry standard architecture (EISA) bus, etc. The 804 bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0233] Some embodiments of this application provide an electronic device that can execute the data access control method as described in any of the above embodiments.
[0234] Some embodiments of this application provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) storing computer program instructions that, when executed on a computer, cause the computer to perform a data access control method as described in any of the above embodiments.
[0235] Exemplary examples show that the aforementioned computer-readable storage media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical discs (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memory (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described herein may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0236] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the data access control method of any of the above embodiments.
[0237] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data access control method, characterized in that, The method includes: Receive a data access request initiated by a third user. The data access request is used to request authorization for the second user to access target data created by the first user. The data access request includes target social relationships, which include at least two of the following: the social relationship between the first user and the second user, the social relationship between the second user and the third user, and the social relationship between the first user and the third user. Based on the target data and the target social relationships, the target access permissions of the second user to the target data are determined in a pre-constructed knowledge graph; wherein, the knowledge graph includes social relationships among multiple users and access permissions of each of the multiple users to at least one piece of data, the multiple users include the first user, the second user, and the third user, the at least one piece of data includes the target data, and the access permissions are used to indicate whether the user has permission to access the corresponding data; Based on the target access permissions, control is exercised over the second user's access to the target data.
2. The method according to claim 1, characterized in that, The knowledge graph includes personnel nodes corresponding to each of the plurality of users, data nodes corresponding to each of the at least one data, and relationship edges. The relationship edges include a first relationship edge and a second relationship edge. The first relationship edge is used to connect two personnel nodes and represents the social relationship between the users corresponding to the two personnel nodes. The second relationship edge is used to connect the personnel node and the data node and represents the access rights of the user corresponding to the personnel node to the data corresponding to the data node.
3. The method according to claim 2, characterized in that, For any data node in the knowledge graph, the second relation edge includes at least one of the following: This is used to connect the data ownership relationship edge between any data node and the personnel node corresponding to the target user, wherein the target user is the user who created the data of any data node; This is used to connect the access permission relationship edge between the personnel node corresponding to each user in the first user group and any of the data nodes, where each user in the first user group is a user who is allowed to access the data corresponding to any of the data nodes; This is used to connect the personnel node corresponding to each user in the second user group with any of the data nodes, where each user in the second user group is prohibited from accessing the data corresponding to any of the data nodes.
4. The method according to claim 2, characterized in that, The personnel node also includes personnel group nodes, and the relationship edge also includes a third relationship edge; For any one of the multiple users, the third relation edge is used to connect the personnel node corresponding to the user and the personnel group node corresponding to the personnel group to which the user belongs. The third relation edge represents the affiliation relationship between the user and the personnel group to which the user belongs.
5. The method according to claim 2, characterized in that, The step of determining the second user's target access permissions to the target data in a pre-constructed knowledge graph based on the target data and the target social relationships includes: Obtain the third person node corresponding to the third user; In the knowledge graph, based on the target social relationship, starting from the third person node and following the first relationship edge, the first person node corresponding to the first user and the second person node corresponding to the second user are determined; In the knowledge graph, based on the target data, a target data node corresponding to the target data is determined from the second relation edge associated with the first personnel node, and a target second relation edge between the target data node and the second personnel node is determined; Based on the target's second relation edge, the target's access permissions are determined.
6. The method according to any one of claims 2-5, characterized in that, The knowledge graph is constructed in the following way: Obtain social relationship information among the multiple users, establish a personnel node for each user, and establish the first relationship edge between the personnel nodes based on the social relationship information; In response to the creation information of any of the plurality of users for the first data, a corresponding first data node is created for the first data, and a second relation edge for the first data is established based on the creation information, wherein the creation information includes at least the information of any of the users and the data content of the first data.
7. The method according to claim 6, characterized in that, The method further includes at least one of the following: In response to the addition of a fourth user to the social relationship information, a personnel node corresponding to the fourth user is established in the knowledge graph, and a corresponding relationship edge is established for the personnel node corresponding to the fourth user. In response to a change in the social relationship between the fifth user among the plurality of users and the other users among the plurality of users, the relationship edges corresponding to the personnel node corresponding to the fifth user in the knowledge graph are updated based on the changed social relationship.
8. The method according to claim 1, characterized in that, The step of controlling the second user's access to the target data according to the target access permissions includes: In response to the target access permission only including instructing the second user to have permission to access the target data, the second user is allowed to access the target data; or, In response to the target access permission including instructing the second user not to have permission to access the target data, the second user is prohibited from accessing the target data.
9. The method according to claim 8, characterized in that, The knowledge graph also includes: device nodes, and information about the physical regions where the device nodes are located; The provision allowing the second user to access the target data includes: Obtain information about the target device, wherein the target device is the device that feeds back the target data to the second user; Based on the information of the target device, the target device node corresponding to the target device is searched in the knowledge graph to determine the physical region where the target device node is located; If the privacy level of the physical area where the target device node is located is higher than a preset level, the second user is allowed to access the de-identified target data; or... If the privacy level of the physical area where the target device node is located is lower than a preset level, the second user is allowed to access the complete target data.
10. An electronic device, characterized in that, Memory and processor; The memory stores instructions that the processor can execute; When the processor is configured to execute the instructions, the electronic device performs the method as described in any one of claims 1-9.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-9.
12. A computer program product, characterized in that, include: Computer instructions; When the computer instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-9.