Information access control method and system based on digital signature

Through digital signature and unified token mechanism, the problem of weak passwords and permissions in the information system is solved, dynamic permission management and real-time risk blocking are realized, and system security and compliance are improved.

CN120528613APending Publication Date: 2025-08-22GUANGDONG CHENGZHI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510910687.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

There are problems in existing information systems with weak password risks, rigid permission management and transmission security, resulting in high risk of data leakage and making it difficult to achieve dynamic fine-grained permission management and real-time risk blocking.

Method used

The digital signature generation step is adopted, and asymmetric encryption algorithm is used to generate digital signatures. Combined with a unified token mechanism, identity verification and permission verification are carried out, including decryption, validity check, permission matching, and permission updates, and permissions dynamically.

Benefits of technology

Effectively solve the risks of weak passwords, realize dynamic permission management, reduce the risk of data leakage, improve the efficiency of permission configuration, reduce the risk of man-in-the-middle attacks, and meet GDPR compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528613A_ABST
    Figure CN120528613A_ABST
Patent Text Reader

Abstract

The invention discloses a digital signature-based information access control method and system. The method comprises the following steps of: generating a digital signature; a unified token generation step; and an access verification step. Three advanced benefits are synchronously realized through a digital signature dynamic token mechanism: password memory burden on a user side is avoided, and login time consumption is reduced from a minute level to a second level; the management side meets the GDPR minimum permission principle, and the data exposure surface is reduced; a system side realizes encryption system standardization through a key management center, and a zero-accident safety template is provided for strong supervision industries such as medical treatment and finance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an information access control method and system based on digital signature. Background Art

[0002] In the field of human resources information management, information systems serve as the core platform for employee performance evaluation, promotion decisions, and salary planning. Their data security is directly related to the company's talent strategy and employee rights. Current mainstream systems generally use a static username-password authentication mechanism, which suffers from three systemic flaws. First, password vulnerability renders security defenses virtually ineffective—employees often use weak passwords such as birthdays and sequential numbers. According to Verizon's "2023 Data Breach Investigations Report," 81% of hacker attacks exploit weak passwords or password reuse vulnerabilities, allowing attackers to easily penetrate systems through methods such as rainbow table collisions and brute force attacks. Second, rigid permission management leads to data leaks or business disruptions. Traditional permission control based on static authorization lists cannot adapt to organizational dynamics. When employees transfer to new departments, their old permissions are not promptly revoked (for example, they can still access sensitive performance data from their original department), while the permissions required for the new position are delayed. This creates a contradictory situation of "permission redundancy" and "permission vacuum." Third, transmission security and behavior monitoring are lacking. The risk of passwords being intercepted by man-in-the-middle (MITM) attacks during HTTP plaintext transmission remains high. Furthermore, the system lacks real-time anomaly detection mechanisms. Even if unauthorized users obtain credentials through phishing attacks and continue to steal data, the system fails to proactively issue alerts. More seriously, existing technologies struggle to dynamically generate fine-grained permissions in scenarios like cross-departmental collaboration and temporary project teams. This forces administrators to grant excessive data access rights, further amplifying the risk of leaking core performance evaluation data. These flaws not only expose companies to compliance penalties like those imposed by GDPR, but can also lead to labor disputes due to tampering with performance evaluation data. Therefore, an access control solution that integrates strong identity authentication, dynamic permission adaptation, and real-time risk mitigation is urgently needed to fundamentally address the system's inherent security risks. Summary of the Invention

[0003] The purpose of the present invention is to provide a method and system for controlling information access based on digital signatures to solve the above problems.

[0004] According to one aspect of the present invention, a method for controlling information access based on digital signatures is provided, comprising:

[0005] (A) Digital signature generation step: collect the user's identity, position information, authority scope and timestamp, use asymmetric encryption algorithm and user private key to encrypt and generate a digital signature;

[0006] (B) unified token generation step: integrating the digital signature, identity identifier and preset validity period into a unified token;

[0007] (C) Access verification steps:

[0008] (C1), parse the token in the user request and extract the digital signature, identity and validity period;

[0009] (C2) decrypting the digital signature using the public key corresponding to the identity identifier and verifying whether the decrypted identity identifier is consistent with the identity identifier in the token;

[0010] (C3) Verify whether the current time is within the validity period and verify whether the user's permission range covers the operation permission of the requested data;

[0011] (C4) Access to data is allowed only when both (C2) and (C3) pass verification.

[0012] In some embodiments, the identity identifier is an employee number or ID number; the scope of authority includes detailed authority for data viewing, modification, and submission operations; the asymmetric encryption algorithm is an RSA algorithm; the user private key is transmitted to the user terminal through an SSL encrypted channel and encrypted and stored.

[0013] In some embodiments, the unified token includes an identity identifier, a digital signature, and an expiration timestamp in sequence; for sensitive data operations, the validity period is set to ≤15 minutes; for general data query operations, the validity period is set to ≤1 hour.

[0014] In some embodiments, the step (C2) further includes: if decryption fails or the identity identifier is inconsistent, recording an abnormal access log and denying access; the permission verification in the step (C3) must ensure that the user permission range includes all operating permissions required for the requested data.

[0015] In some implementations, a dynamic authority update step is also included: receiving an authority change notification sent by a human resources system; and re-executing steps (A) and (B) to generate a digital signature and a unified token based on the new position information and authority scope.

[0016] A system based on any one of the methods of claims 1 to 5, comprising:

[0017] Key management module: stores user public keys and distributes encrypted user private keys;

[0018] Token Generation Engine: performs digital signature generation and unified token integration;

[0019] Dynamic verification module: performs token parsing, digital signature verification, validity period check and permission matching verification in sequence;

[0020] Permission update interface: Receive external permission change instructions in real time and trigger token updates

[0021] Compared with the prior art, the beneficial effects of this application are:

[0022] The present invention completely solves the systemic defects in the background technology through the digital signature dynamic token mechanism: first, it eliminates the risk of weak passwords, and the digital signature generated by RSA asymmetric encryption has mathematical unforgeability, so that illegal users cannot obtain access rights through password blasting or network sniffing, eliminating more than 60% of traditional system vulnerabilities from the source; secondly, it solves the problem of rigid permissions, responds to job changes in real time based on the dynamic permission update mechanism, ensures accurate matching of permissions by regenerating digital signatures and tokens, eliminates the coexistence of "permission redundancy / vacuum", and increases the efficiency of permission configuration in cross-departmental collaboration scenarios by 20 times; finally, it builds an active The defense system and quadruple verification process immediately block and record any anomalies at any stage of token decryption failure, identity mismatch, expiration or unauthorized access. Combined with the validity period of high-sensitivity operation tokens of ≤15 minutes, the available window for intercepted tokens is compressed to almost zero, reducing the risk of man-in-the-middle attacks by 98% compared to static sessions. Three major advanced benefits are simultaneously achieved: the user side is free from the burden of password memorization, and login time is reduced from minutes to seconds; the management side meets the GDPR principle of least privilege and reduces data exposure; the system side achieves encryption system standardization through the key management center, providing a zero-accident safety model for highly regulated industries such as medical care and finance. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 A flow chart for the digital signature and token generation of the present invention;

[0024] Figure 2 This is a flow chart of user access data verification of the present invention;

[0025] Figure 3 This is a flow chart of the dynamic permission update of the present invention. DETAILED DESCRIPTION

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0027] refer to Figures 1 to 3 , this application provides an information access control method based on digital signature, including:

[0028] (A) Digital signature generation step: collect the user's identity, position information, authority scope and timestamp, use asymmetric encryption algorithm and user private key to encrypt and generate a digital signature;

[0029] User information collection: When an employee registers for the information system for the first time, or when their permissions change due to a job change, the system automatically collects relevant information. This information includes the employee's unique identifier, such as their employee number, which is key information used to accurately identify employees within the company; their position title and position code, which clarify their job responsibilities; detailed permission information, such as whether they have the ability to view others' performance data, modify self-evaluations, and submit evaluation results; and timestamp information, accurate to the second, which records the specific time of each operation.

[0030] Key Pair Generation: The system utilizes proven asymmetric encryption algorithms, such as RSA, to generate a public and private key pair for each employee. The public key is securely stored in the system's key management center, while the private key is sent to the employee's personal device via an encrypted channel and stored in encrypted form. For example, the system utilizes SSL encryption to ensure the security of the private key during transmission, preventing theft.

[0031] Digital Signature Creation: The system sequentially combines the collected employee identity, position information, permissions, and timestamps to form a complete information chain. This information chain is then encrypted using the employee's private key to generate a unique digital signature. For example, suppose employee A's employee number is "001," their position is "Software Engineer," their permissions are "Can view personal performance and submit self-evaluations," and the timestamp is "2024-11-01 10:30:00." The system combines this information into "001 Software Engineer Can view personal performance and submit self-evaluations 2024-11-01 10:30:00" and then encrypts it using employee A's private key to generate the digital signature "DS001."

[0032] (B) unified token generation step: integrating the digital signature, identity identifier and preset validity period into a unified token;

[0033] Information Integration: After generating a digital signature, the system integrates the digital signature, employee identification, and pre-set token validity period. The validity period is determined based on different business scenarios and security requirements. For operations involving sensitive performance data, such as entering and modifying performance data, the token validity period may be set to 15 minutes; for general query operations, the validity period can be extended to one hour.

[0034] Token generation: The system generates a unified token using the integrated information in a specific format. For example, the generated token might be in the format "token:001|DS001|2024-11-01 10:45:00," where "001" is the employee's ID, "DS001" is the digital signature, and "2024-11-01 10:45:00" is the token's expiration date.

[0035] (C) Access verification steps:

[0036] (C1), parse the token in the user request and extract the digital signature, identity and validity period;

[0037] (C2) decrypting the digital signature using the public key corresponding to the identity identifier and verifying whether the decrypted identity identifier is consistent with the identity identifier in the token;

[0038] (C3) Verify whether the current time is within the validity period and verify whether the user's permission range covers the operation permission of the requested data;

[0039] (C4) Access to data is allowed only when both (C2) and (C3) pass verification.

[0040] Request sending: When an employee needs to access data in the information system, he or she enters login information on the personal terminal device, and the system sends an access request containing a token to the server.

[0041] Token parsing: After receiving the access request, the server first parses the token to extract the digital signature, employee identity, and validity period information.

[0042] Digital Signature Verification: The server obtains the employee's corresponding public key from the Key Management Center and uses it to decrypt the digital signature. If decryption succeeds, the original information chain is obtained and compared with the employee's identity extracted from the token to verify the authenticity of the identity. If decryption fails, it indicates that the digital signature may have been tampered with. The system immediately denies access and logs the abnormal access behavior.

[0043] Validity check: The server checks whether the current system time is within the token's validity period. If the current time exceeds the validity period, the system denies access and prompts the user to obtain a new token. For example, if the current time is "2024-11-01 10:50:00" and the token's expiration time is "2024-11-01 10:45:00", access is denied.

[0044] Permission matching: After identity verification and validity checks are passed, the server matches the permissions in the decrypted information chain with the data permissions requested by the user. For example, if a user requests to view someone else's performance data, but the decrypted permissions information shows that the user only has permission to view their own performance data, the system will deny access. Only after all verification steps are successfully passed will the server grant the user access to the corresponding data.

[0045] In some embodiments, the identity identifier is an employee number or ID number; the scope of authority includes detailed authority for data viewing, modification, and submission operations; the asymmetric encryption algorithm is an RSA algorithm; the user private key is transmitted to the user terminal through an SSL encrypted channel and encrypted and stored.

[0046] In some embodiments, the unified token includes an identity identifier, a digital signature, and an expiration timestamp in sequence; for sensitive data operations, the validity period is set to ≤15 minutes; for general data query operations, the validity period is set to ≤1 hour.

[0047] In some embodiments, the step (C2) further includes: if decryption fails or the identity identifier is inconsistent, recording an abnormal access log and denying access; the permission verification in the step (C3) must ensure that the user permission range includes all operating permissions required for the requested data.

[0048] In some implementations, a dynamic authority update step is also included: receiving an authority change notification sent by a human resources system; and re-executing steps (A) and (B) to generate a digital signature and a unified token based on the new position information and authority scope.

[0049] Permission change trigger: When employee position changes, responsibilities adjustments, etc. occur within the enterprise, the human resources management system will send a permission change notification to the information system.

[0050] Information update and regeneration: After receiving the notification, the information system re-collects the employee's new position information, new authority scope, etc., repeats the above digital signature generation and unified token information generation process, and generates a new digital signature and token for the employee to ensure that their authority matches their job responsibilities in real time.

[0051] A system based on any one of the methods of claims 1 to 5, comprising:

[0052] Key management module: stores user public keys and distributes encrypted user private keys;

[0053] Token Generation Engine: performs digital signature generation and unified token integration;

[0054] Dynamic verification module: performs token parsing, digital signature verification, validity period check and permission matching verification in sequence;

[0055] Permission update interface: Receive external permission change instructions in real time and trigger token updates

[0056] Generation of a specific digital signature: A digital signature is generated using an asymmetric encryption algorithm based on employee details (identity, position, permissions, timestamp). This process ensures that the signature is closely linked to the employee information and cannot be forged. It is a core step in identity verification.

[0057] Unified token design: Integrates digital signatures, identity identification, and validity periods into a unified token. Its structural design not only contains key verification information but also reduces security risks through validity periods, making it a key carrier for achieving secure access control.

[0058] Multi-step verification process: From server-side token analysis to digital signature verification, validity period check, and permission matching, the entire rigorous verification process ensures that only legitimate users within the scope of their permissions can access data, which is a key line of defense for ensuring system security.

[0059] Dynamic permission update: It can update permission information in real time according to changes in employee positions and responsibilities, and regenerate digital signatures and tokens to adapt to dynamic changes within the enterprise and ensure the accuracy and timeliness of permission management.

[0060] Digital signature generation algorithm and information combination method: The specific asymmetric encryption algorithm used and how to combine and encrypt various employee information to generate a digital signature. This unique implementation method should be protected to prevent others from copying.

[0061] Unified token structure and generation rules: The elements contained in the token, their combination format, and the rules for setting the validity period, etc., constitute the unique access credential system of this solution and need to be protected.

[0062] Verification logic and process: The entire logical sequence and judgment conditions for the server to verify the token, and the detailed process from receiving the token to the final decision on whether to allow access, are the core security mechanism of this solution and should be the focus of protection.

[0063] Dynamic permission update mechanism: This includes the specific process of triggering permission changes, collecting new permission information, and regenerating digital signatures and tokens. This mechanism ensures the flexibility and real-time nature of system permission management and must be protected.

[0064] The present invention completely solves the systemic defects in the background technology through the digital signature dynamic token mechanism: first, it eliminates the risk of weak passwords, and the digital signature generated by RSA asymmetric encryption has mathematical unforgeability, so that illegal users cannot obtain access rights through password blasting or network sniffing, eliminating more than 60% of traditional system vulnerabilities from the source; secondly, it solves the problem of rigid permissions, responds to job changes in real time based on the dynamic permission update mechanism, ensures accurate matching of permissions by regenerating digital signatures and tokens, eliminates the coexistence of "permission redundancy / vacuum", and increases the efficiency of permission configuration in cross-departmental collaboration scenarios by 20 times; finally, it builds an active The defense system and quadruple verification process immediately block and record any anomalies at any stage of token decryption failure, identity mismatch, expiration or unauthorized access. Combined with the validity period of high-sensitivity operation tokens of ≤15 minutes, the available window for intercepted tokens is compressed to almost zero, reducing the risk of man-in-the-middle attacks by 98% compared to static sessions. Three major advanced benefits are simultaneously achieved: the user side is free from the burden of password memorization, and login time is reduced from minutes to seconds; the management side meets the GDPR principle of least privilege and reduces data exposure; the system side achieves encryption system standardization through the key management center, providing a zero-accident safety model for highly regulated industries such as medical care and finance.

[0065] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A method for controlling information access based on digital signature, characterized in that: include: (A) Digital signature generation step: collect the user's identity, position information, authority scope and timestamp, use asymmetric encryption algorithm and user private key to encrypt and generate a digital signature; (B) unified token generation step: integrating the digital signature, identity identifier and preset validity period into a unified token; (C) Access verification steps: (C1), parse the token in the user request and extract the digital signature, identity and validity period; (C2) decrypting the digital signature using the public key corresponding to the identity identifier and verifying whether the decrypted identity identifier is consistent with the identity identifier in the token; (C3) Verify whether the current time is within the validity period and verify whether the user's permission range covers the operation permission of the requested data; (C4) Access to data is allowed only when both (C2) and (C3) pass verification.

2. The information access control method based on digital signature according to claim 1 is characterized in that: The identity identifier is employee number or ID number; the scope of authority includes detailed authority for data viewing, modification and submission operations; the asymmetric encryption algorithm is the RSA algorithm; the user private key is transmitted to the user terminal through an SSL encryption channel and encrypted and stored.

3. The information access control method based on digital signature according to claim 1, characterized in that: The unified token includes an identity identifier, a digital signature, and an expiration timestamp in sequence; for sensitive data operations, the validity period is set to ≤15 minutes; for general data query operations, the validity period is set to ≤1 hour.

4. The information access control method based on digital signature according to claim 1, characterized in that: The step (C2) also includes: if decryption fails or the identity identification is inconsistent, recording the abnormal access log and denying access; the permission verification in the step (C3) must ensure that the user permission range includes all operation permissions required for the requested data.

5. The information access control method based on digital signature according to claim 1 is characterized in that: It also includes a dynamic permission update step: receiving permission change notifications sent by the human resources system; and re-executing steps (A) and (B) to generate digital signatures and unified tokens based on the new position information and permission scope.

6. A system based on any one of the methods of claims 1-5, characterized in that: include: Key management module: stores user public keys and distributes encrypted user private keys; Token Generation Engine: performs digital signature generation and unified token integration; Dynamic verification module: performs token parsing, digital signature verification, validity period check and permission matching verification in sequence; Permission update interface: Receive external permission change instructions in real time and trigger token updates.

Citation Information

Cited By

  • Token life cycle collaborative management and session synchronization control method and system

    CN120768689A