Attribute revocation encryption access control method and system based on time label
Patent Information
- Application Number
- CN202511018614.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-11-07
AI Technical Summary
Existing attribute revocation systems are inadequate in terms of timeliness, resource efficiency, and security. In particular, they are difficult to achieve high-timeliness, high-resource-efficiency, and high-security permission management in high-concurrency scenarios, and there are risks of expired permissions and data residue.
An attribute revocation encrypted access control method based on time tags is adopted. By constructing a three-level time constraint structure, generating hierarchical alarm signal queues, optimizing time window scheduling plans and encrypted revocation schemes, and combining blockchain technology, the timeliness and security of permission revocation are ensured.
It achieves fine-grained control over the lifecycle of permissions, ensures the precise triggering of revocation commands at critical time points, improves resource utilization efficiency in high-concurrency scenarios, guarantees the reliable execution of revocation commands, and eliminates the risk of data residue from a cryptographic perspective, thereby improving the system's timeliness, resource efficiency, and security.
Smart Images

Figure CN120915503A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer security, in particular to an attribute revocation encryption access control method and system based on a time label. BACKGROUND
[0002] In the field of information security, attribute revocation encryption access control technology, as the core means of dynamic permission management, dynamically associates user attributes such as department roles and security levels with data access permissions, enabling fine-grained protection of sensitive data. This technology can revoke permissions in real time when user attributes change, such as automatically terminating data access capabilities when an employee leaves or a project ends. With the popularity of cloud computing and the Internet of Things, access control scenarios are becoming increasingly complex, and there is a growing demand for time-sensitive permission management - such as the need for second-level revocation of permissions for financial transactions and automatic recovery of access rights for medical data according to treatment cycles. This dynamic permission control based on the time dimension has become a cornerstone for protecting critical business data security.
[0003] Chinese patent application publication No. CN113411297A discloses a situation awareness defense method and system based on attribute access control, which identifies user and environment attribute information in real time, matches the information security level of network nodes, solves the user identity theft and permission management problems in the prior art, and realizes the security protection and attack detection of network node data information. However, this scheme mainly focuses on identity theft and network attack and other exogenous attack prevention problems, but does not address the problem of endogenous attacks such as illegal access using permission control time differences, and fails to achieve high-concurrency, high-efficiency, and high-security attribute revocation encryption access.
[0004] In summary, existing attribute revocation systems face serious challenges in actual deployment:
[0005] (1) The revocation mechanism based on manual review has significant lag, and administrators have difficulty responding to frequent attribute change events in a timely manner, especially when dealing with a large number of permission nodes. Manual operation delays can cause critical permissions to be left for an extended period of time;
[0006] (2) Traditional timed inspection strategies lack flexibility, and fixed scanning periods cannot adapt to dynamic business load changes. In high-concurrency scenarios, system overload can cause revocation instructions to accumulate, while in low-load scenarios, resources are redundant;
[0007] (3) Most solutions only implement policy state updates and do not touch the cryptographic level of permission destruction. Attackers can still decrypt encrypted data with revoked permissions using historical keys, posing a persistent security threat.
[0008] These defects together cause the existing system to have inherent limitations in timeliness, resource efficiency and security and reliability. SUMMARY
[0009] The present application aims to overcome the above-mentioned defects of the prior art and provide a time label-based attribute revocation encryption access control method and system to solve or partially solve the problem of unsatisfactory timeliness, resource efficiency and security and reliability of attribute revocation encryption access control.
[0010] The object of the present application can be achieved by the following technical solutions:
[0011] In one aspect of the present application, a time label-based attribute revocation encryption access control method is provided, comprising the following steps:
[0012] Time label definition processing is performed on the obtained permission attribute data, a three-level time constraint structure including a warning window, an intervention window and an execution window is constructed in combination with a preset security level, and a basic time label set is generated;
[0013] Key node scanning processing is performed on the basic time label set, attribute revocation information approaching a key time node is obtained and a time label trigger condition is verified, and if the trigger condition is met, a hierarchical alarm signal queue is generated;
[0014] System load data is obtained and abnormal state detection processing is performed on the hierarchical alarm signal queue, the scanning frequency and time window offset are adjusted based on a dynamic load threshold, and an optimized time window scheduling plan is generated;
[0015] Permission risk analysis processing is performed on the optimized time window scheduling plan, time-driven mechanism failure risks are identified through threat modeling, backup trigger path configuration data is generated, an attribute revocation action execution scheme is generated in combination with the main path, and
[0016] The attribute revocation action execution scheme is subjected to encryption permission revocation processing, the decryption key is updated based on an attribute-based encryption strategy tree and a key update factor is generated, an encryption revocation scheme containing a policy update instruction and a key update factor is generated, and attribute revocation encryption access control is achieved.
[0017] As a preferred technical solution, the process of generating a basic time label set comprises the following steps:
[0018] Attribute domain analysis processing is performed on business requirement data, security level labels and failure time parameters are extracted from permission attributes, a preliminary time range is configured for each permission, and a time window configuration benchmark is generated;
[0019] A three-level time structure is constructed based on the time window configuration benchmark, a hierarchical relationship among a warning window, an intervention window and an execution window is established according to the security level label, a smaller time interval between windows is set for a higher security level permission, and a three-level time constraint framework is constructed, wherein the warning window is used for monitoring the permission state in advance, the intervention window is used for reserving time for administrator manual intervention for permission adjustment, and the execution window is used for executing permission revocation, and the length of the execution window is calculated according to the security level and the business criticality;
[0020] Based on the constraint rules of each permission attribute in the time dimension, the three-level time constraint framework is bound with a policy template, the access conditions in the attribute encryption policy are mapped to the time window, and a timestamp configuration rule set is generated;
[0021] The timestamp configuration rule set is distributed for notarization, the time constraint parameters are stored by using the tamper-proof feature of the block chain, and a basic time label set is generated.
[0022] As a preferred technical solution, the process of generating a hierarchical alarm signal queue includes the following steps:
[0023] The basic time label set is processed in the time dimension, the permission attributes of the adjacent execution window are detected through a sliding window, and a to-be-triggered attribute list is generated;
[0024] The to-be-triggered attribute list is verified by a time label, the time inclusion relationship between the current time and the execution window is analyzed, and a trigger state judgment result is generated;
[0025] The trigger state judgment result is processed by signal grading, the emergency degree of the alarm signal is divided according to the time window hierarchy, and a hierarchical alarm signal queue is generated.
[0026] As a preferred technical solution, the process of generating a hierarchical alarm signal queue according to the time window hierarchy includes the following steps:
[0027] The trigger state judgment result is quantified by the emergency degree, the signal priority weight is calculated by the time offset ratio, and emergency degree grading data is generated;
[0028] The emergency degree grading data is processed by notification channel allocation, different emergency degree signals are matched with corresponding transmission channels, and an alarm routing configuration table is generated;
[0029] The alarm routing configuration table is processed by queue sorting, the alarm signal sequence is reorganized in descending order of the emergency degree, and a hierarchical alarm signal queue is generated.
[0030] As a preferred technical solution, the process of generating an optimized time window scheduling plan includes the following steps:
[0031] The system load data is subjected to overload risk identification processing, whether the resource consumption exceeds the elastic load threshold is detected, and a system state flag is generated.
[0032] The hierarchical alarm signal queue is subjected to scanning parameter adjustment processing based on the system state flag, the time window scanning frequency is dynamically optimized, and an optimized time window scheduling plan is generated.
[0033] As a preferred technical solution, the generation process of the attribute revocation action execution scheme includes the following steps:
[0034] The optimized time window scheduling plan is subjected to failure risk analysis, potential failure points of the time driving mechanism are identified through historical failure modes, and a risk feature map is generated.
[0035] The risk feature map is subjected to backup path generation, a contract enforcement channel is created for a high-risk node, and a disaster recovery path configuration scheme is generated.
[0036] Based on the disaster recovery path configuration scheme, double-path integration processing is performed, the main time driving engine and the backup blockchain path are fused, and an attribute revocation action execution scheme is generated.
[0037] As a preferred technical solution, the generation process of the encryption revocation scheme includes the following steps:
[0038] The attribute revocation action execution scheme is subjected to strategy tree update processing, the access nodes of the invalid attributes in the attribute-based encryption strategy are removed, and an updated strategy tree is generated, wherein each node in the strategy tree corresponds to an attribute access condition, the leaf node represents a basic attribute, and the non-leaf node represents a logical combination relationship between attributes.
[0039] The system master key is subjected to random factor injection processing, key update parameters are generated through discrete logarithm operation, and a key update factor is generated.
[0040] The updated strategy tree and the key update factor are subjected to broadcast encapsulation processing, and an encryption revocation scheme containing a strategy update instruction and a key factor is generated.
[0041] Another aspect of the present application provides an attribute revocation encryption access control system based on time labels, which is used to implement the aforementioned attribute revocation encryption access control method based on time labels, and the system comprises:
[0042] A time label definition module is configured to perform time label definition processing on the permission attribute data, construct a three-level time constraint structure including a warning window, an intervention window and an execution window in combination with a preset security level, and generate a basic time label set.
[0043] An alarm trigger judgment module is configured to perform key node scanning processing on the basic time label set, acquire attribute revocation information of an upcoming key time node, and verify a time label trigger condition, and if the trigger condition is met, generate a hierarchical alarm signal queue.
[0044] A dynamic optimization module is configured to perform abnormal state detection processing on the hierarchical alarm signal queue based on system load data, adjust a scanning frequency and a time window offset based on a dynamic load threshold, and generate an optimized time window scheduling plan.
[0045] A disaster recovery path configuration module is configured to perform permission risk analysis processing on the optimized time window scheduling plan, identify a time-driven mechanism failure risk through threat modeling, generate backup trigger path configuration data, and generate an attribute revocation action execution scheme in combination with a main path.
[0046] An encrypted revocation execution module is configured to perform encrypted permission revocation processing on the attribute revocation action execution scheme, update a decryption key based on an attribute-based encryption policy tree and generate a key update factor, and generate an encrypted revocation scheme containing a policy update instruction and the key update factor.
[0047] A data communication module is configured to acquire the permission attribute data and the system load data, and send the encrypted revocation scheme to an execution mechanism.
[0048] In another aspect of the present application, an electronic device is provided, comprising one or more processors and a memory, the memory having stored therein one or more programs, the one or more programs including instructions for executing the aforementioned time label-based attribute revocation encryption access control method.
[0049] In another aspect of the present application, a computer-readable storage medium is provided, comprising one or more programs for execution by one or more processors of an electronic device, the one or more programs including instructions for executing the aforementioned time label-based attribute revocation encryption access control method.
[0050] Compared with the prior art, the present application has at least one of the following beneficial effects:
[0051] (1) The risk of permission overstay is small: compared with the scheme of manually revoking permissions, there is a great risk of permission overstay, and the present application performs time label definition processing on the acquired permission attribute data through a time label definition module, constructs a three-level time constraint structure including a warning window, an intervention window and an execution window in combination with a preset security level, generates a basic time label set, and the constructed three-level time constraint structure can realize fine management and control of the permission life cycle, effectively eliminating the risk of permission overstay caused by manual operation delay.
[0052] (2) Guarantee the accurate triggering of the revocation instruction at the key time node: The alarm triggering judgment module of the present application performs time dimension scanning processing on the basic time tag set, detects the permission attribute of the adjacent execution window through the sliding window, generates a list of attributes to be triggered, then performs time tag verification, analyzes the time inclusion relationship between the current time and the execution window, generates a trigger state judgment result, finally performs signal grading processing on the trigger state judgment result, divides the alarm signal urgency according to the time window level, generates a graded alarm signal queue, and guarantees the accurate triggering of the revocation instruction at the key time node.
[0053] (3) Improve resource utilization efficiency in high concurrency scenarios: The dynamic optimization module of the present application performs overload risk identification processing on system load data, detects whether the resource consumption exceeds the elastic load threshold, generates a system state flag, then performs scanning parameter adjustment processing on the graded alarm signal queue, dynamically optimizes the time window scanning frequency, generates an optimized time window scheduling plan, provides adaptive adjustment strategies, realizes the elastic scaling of the scanning frequency and the time window, and significantly improves the resource utilization efficiency in high concurrency scenarios.
[0054] (4) Guarantee the reliable execution of the revocation instruction: The disaster recovery path configuration module of the present application performs failure risk analysis on the optimized time window scheduling plan, identifies potential failure points of the time-driven mechanism through historical failure mode, generates a risk feature map, then generates a backup path, creates a contract enforcement channel for high-risk nodes, generates a disaster recovery path configuration scheme, finally performs dual-path integration processing, fuses the main time-driven engine and the backup blockchain path, generates an attribute revocation action execution scheme, through the dual-path execution mechanism, automatically enables the backup path of the smart contract of the blockchain when the main path fails, and ensures the reliable execution of the permission revocation instruction.
[0055] (5) Eliminate data residual risk: The encrypted revocation execution module of the present application performs strategy tree update processing on the attribute revocation action execution scheme, removes the access nodes of the invalid attributes in the attribute-based encryption strategy, generates an updated strategy tree, then performs random factor injection processing on the system master key, generates key update parameters through discrete logarithm operation, generates a key update factor, finally performs broadcast encapsulation processing on the updated strategy tree and the key update factor, generates an encrypted revocation scheme containing the strategy update instruction and the key factor, through the injection of the key update factor, completely blocks the decryption ability of the historical key to the revoked permission ciphertext, and eliminates the data residual risk from the perspective of cryptography.
[0056] (6) guarantee business continuity while improving timeliness, resource efficiency and security: the application realizes the triple improvement of timeliness, resource efficiency and security while guaranteeing business continuity through the cooperation and synergy of the time label definition module, the alarm trigger judgment module, the dynamic optimization module, the disaster recovery path configuration module, the encryption revocation execution module and the data communication module, and provides an access control solution that takes into account dynamic response capability and strong cryptographic security for cross-domain multi-terminal environment. BRIEF DESCRIPTION OF DRAWINGS
[0057] Figure 1 Flowchart for the attribute revocation encryption access control method based on time labels in the embodiment;
[0058] Figure 2 Flowchart for generating a set of basic time labels in the embodiment;
[0059] Figure 3 Flowchart for generating a hierarchical alarm signal queue in the embodiment;
[0060] Figure 4 Flowchart for optimizing the time window scheduling plan generation process in the embodiment;
[0061] Figure 5 Flowchart for the generation process of the attribute revocation action execution scheme in the embodiment;
[0062] Figure 6 Flowchart for the generation process of the encryption revocation scheme in the embodiment;
[0063] Figure 7 Schematic diagram of the attribute revocation encryption access control system based on time labels in the embodiment;
[0064] Figure 8 Schematic diagram of the alarm trigger judgment module in the embodiment;
[0065] Figure 9 Schematic diagram of the electronic device in the embodiment. DETAILED DESCRIPTION
[0066] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are part of the embodiments of the application, rather than all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of the application.
[0067] Embodiment 1
[0068] To address the problems existing in the aforementioned prior art, this embodiment provides a time-stamped attribute revocation encrypted access control method that can accurately coordinate timeliness control and system load, and achieve irreversible revocation of permissions at the cryptographic level. See [link to relevant documentation]. Figure 1 The method includes the following steps:
[0069] Step S1: Perform time tag definition processing on the obtained permission attribute data, and construct a three-level time constraint structure including warning window, intervention window and execution window in combination with the preset security level to generate a basic time tag set.
[0070] Preferred, see Figure 2 Step S1 includes steps S101-S104:
[0071] Step S101: Perform attribute domain parsing on the business requirement data, extract the security level label and expiration time parameter from the permission attribute, configure a preliminary time range for each permission, and generate a time window configuration baseline.
[0072] Specifically, step S101 acquires business requirement data, which contains various permission information required by users in specific business scenarios. Through in-depth attribute domain parsing of the business requirement data, key information can be accurately identified and extracted, namely, security level labels and expiration time parameters. The security level label reflects the sensitivity of the data associated with the permission and the minimum security level required to access that data, while the expiration time parameter clarifies the validity period of the permission over time.
[0073] Based on the extracted security level labels and expiration time parameters, step S101 further generates a time window configuration benchmark. The time window configuration benchmark comprehensively considers the security level and expiration time of the permission and defines a preliminary time range for each permission to guide the reasonable setting of the warning window, intervention window and execution window.
[0074] Step S102: Construct a three-level time structure based on the time window configuration benchmark, establish the hierarchical relationship between the warning window, intervention window and execution window according to the security level label, set smaller time intervals between windows for permissions with higher security levels, and construct a three-level time constraint framework.
[0075] Specifically, step S102 defines the hierarchical relationship among the warning window, intervention window and execution window according to different security levels represented by the security level labels. For high-security level permissions, the time intervals of the warning window, intervention window and execution window can be relatively small, so as to respond to permission changes more timely; while for low-security level permissions, relatively larger time intervals can be set. Through such a construction manner, a complete three-level time constraint framework is generated, which not only clearly defines the specific position and role of each time window, but also embodies the differentiated management strategy of different security level permissions in the time dimension.
[0076] Step S103, based on the constraint rules of each permission attribute in the time dimension, performs policy template binding on the three-level time constraint framework, maps the access conditions in the attribute encryption policy to the time window, and generates a timestamp configuration rule set.
[0077] Specifically, step S103 classifies the security level labels, and divides different level intervals according to the security levels represented by the labels. For each permission attribute, the relative time length proportion of the corresponding warning window, intervention window and execution window is determined according to the interval where the security level label of the attribute is located. The warning window, as the initial time monitoring interval, is mainly used for early monitoring of permission status, and its time length is set relatively short to timely discover potential permission change requirements; the intervention window follows the warning window and has a moderate time length, providing an opportunity for administrators to manually intervene in permission adjustment; the execution window is the last stage of forced execution, and its time length is determined according to the security level and business criticality to ensure that the permission can be revoked in time when necessary.
[0078] Preferably, step S103 divides the invalidation time parameter in the time window configuration benchmark according to the above proportion relationship through mathematical modeling, determines the specific start time and end time of the warning window, intervention window and execution window, and constructs the hierarchical nested relationship among them. Finally, the configuration information of these time windows is integrated into a three-level time constraint framework, which records the detailed constraint rules of each permission attribute in the time dimension in a structured form, including the time range, start condition, end condition and logical association among the time windows, provides a rigorous time structure basis for subsequent policy template binding, realizes phased and fine-grained control of permission time effectiveness, and ensures that permission management can closely match business requirements and security policies.
[0079] Step S104, distributed notarization of the timestamp configuration rule set, stores the time constraint parameters using the non-tamperable characteristics of the block chain, and generates a basic time label set.
[0080] Specifically, step S104 employs blockchain technology as the underlying architecture to build a distributed storage network. The network is composed of multiple nodes, including server nodes within the organization, third-party trusted agency nodes, and cloud service provider nodes, etc. These nodes are connected and communicated through a pre-set peer-to-peer network protocol, ensuring distributed storage and synchronization of data. A special smart contract is created on the blockchain to define the storage structure and storage process of the timestamp configuration rule set. Step S104 digitizes each rule item in the timestamp configuration rule set and converts it into a data object that conforms to the blockchain storage format. These data objects contain access conditions, time window information, timestamp recording rules, and other content.
[0081] Preferably, step S104 writes these data objects into the blocks of the blockchain one by one through the invocation of the smart contract. The tamper-proof nature of the blockchain ensures that once the time constraint parameters are recorded in the blocks, they cannot be maliciously tampered with or deleted, thereby guaranteeing the authenticity and integrity of the time constraint parameters. At the same time, by utilizing the hash chain structure of the blockchain, the data in each block is encrypted to generate a unique hash value, further enhancing the security of the data. After completing the distributed storage, the time constraint parameter records of the successful storage are extracted from the blockchain, combined with the original permission attribute data, and the basic time label set is generated according to the pre-set data structure. Each time label in the set contains permission attribute identification, blockchain storage hash value of time constraint parameters, and timestamp, forming a complete record and credible proof of the time constraint of the permission attribute.
[0082] In summary, step S1 is used to define the time label of the permission attribute data, and a three-level time constraint structure including the warning window, intervention window, and execution window is constructed according to the pre-set security level to generate the basic time label set.
[0083] Specifically, user permission attribute data is collected from various information management systems within the organization. These data cover multiple dimensions such as user department, post role, security level, and record the timestamp of data generation or change for subsequent time series analysis. Step S1 sets a time label for each permission attribute based on the organization's security policy and business process characteristics. The time label adopts a three-part structure, corresponding to the warning window, intervention window, and execution window duration. These three duration parameters are initialized and configured by system administrators based on historical data statistical analysis and business risk assessment results, and can be dynamically adjusted according to actual conditions.
[0084] Specifically, the pre-warning window is relatively short in length and is mainly used to discover the expiring or abnormal permission attributes in advance; the intervention window is moderate in length and provides a time window for the administrator to manually intervene in the permission problem; and the execution window is the final enforcement interval, and the length thereof is determined according to the business criticality and security requirements. When the permission attribute enters the execution window, the system will automatically perform the corresponding revocation operation. By associating and mapping the preset security level with the three-level time constraint structure, it is ensured that the high-security-level data has more strict and fine time constraint control, thereby generating a basic time tag set covering all permission attributes.
[0085] Step S2, performing key node scanning processing on the basic time tag set, obtaining attribute revocation information of the key time node to be reached and verifying a time tag trigger condition, and generating a hierarchical alarm signal queue if the trigger condition is met.
[0086] Preferably, referring to Figure 3 Step S2 includes steps S201-S203:
[0087] Step S201, performing time dimension scanning processing on the basic time tag set, detecting the permission attribute near the execution window through a sliding window, and generating a to-be-triggered attribute list.
[0088] Specifically, in the scanning process, step S201 adopts a sliding window algorithm, and by setting a window of a fixed length, the window is sequentially slid on the time axis, and the permission attributes in each window range are processed in batches. The size of the window is dynamically adjusted according to the preset scanning accuracy and business requirements of the system, so as to ensure efficient scanning while capturing the permission attribute near the execution window.
[0089] During the movement of the sliding window, the algorithm compares the execution window start time of each permission attribute with the current system time in real time. When it is detected that the difference between the execution window start time of the permission attribute and the current time is less than the preset threshold, it is determined that the permission attribute will soon enter the execution window stage. At this time, the related information of the permission attribute is extracted, including the attribute identifier, the associated user, the corresponding data resource and the like, which are integrated into a to-be-triggered attribute record, and the to-be-triggered attribute list is gradually accumulated. The list is stored in a temporary data structure in the memory in the form of a list, so as to facilitate quick access and processing in the subsequent steps, and ensure that the system can respond to the state change of the permission attribute reaching the key time node in time
[0090] Step S202, performing time tag verification on the to-be-triggered attribute list, analyzing the time inclusion relationship between the current time and the execution window, and generating a trigger state judgment result.
[0091] Specifically, step S202 reads each to-be-triggered attribute record in the to-be-triggered attribute list, extracts the execution window time range parameter in the to-be-triggered attribute record, and the parameter clearly defines the start time and the end time of the execution window. At the same time, the current system time is obtained as a verification reference, and the current time and the execution window time range are accurately judged by a time sequence analysis algorithm.
[0092] Specifically, if the current time is before the start time of the execution window, it indicates that the permission attribute has not yet reached the execution stage, and the trigger state judgment result is "not triggered". If the current time is between the start time and the end time of the execution window, it indicates that the permission attribute has entered the execution window, and the trigger state judgment result is "triggered and executed". If the current time exceeds the end time of the execution window, the trigger state judgment result is "overdue". In the judgment process, considering factors such as time accuracy and time zone difference, through the built-in high-precision time synchronization mechanism and time zone conversion module, the accuracy of time judgment is ensured. The verification results of each to-be-triggered attribute record are recorded, and a trigger state judgment result data set is generated by integration. The data set adopts the form of key-value pair, takes the permission attribute identifier as the key, and takes the trigger state judgment result as the value, and is stored in the system memory.
[0093] Step S203, signal grading processing is performed on the trigger state judgment result, the emergency degree of the alarm signal is divided according to the time window level, and a graded alarm signal queue is generated.
[0094] Preferably, step S203 further includes the following steps:
[0095] Step S2031, the emergency degree of the trigger state judgment result is quantified, the signal priority weight is calculated through the time offset ratio, and emergency degree grading data is generated.
[0096] Specifically, for each trigger state judgment result, step S2031 extracts the time window parameter corresponding to the trigger state judgment result, including the start time and the end time of the warning window, the intervention window and the execution window. Specifically, the time difference between the current system time and the start time of the execution window is calculated, and the time difference is defined as the time offset. The time offset ratio is obtained by the ratio of the time offset to the total length of the execution window, and the ratio value reflects the urgency of the permission attribute entering the execution window. Preferably, the embodiment presets an emergency degree quantification model, which divides the emergency degree into multiple levels according to the time offset ratio, such as low emergency degree, medium emergency degree and high emergency degree. The low emergency degree indicates that the time offset ratio is large, and the permission attribute is far away from the start time of the execution window. The high emergency degree indicates that the time offset ratio is close to zero, and the permission attribute is about to enter the execution window.
[0097] Preferably, the time offset ratio is converted into a specific urgency level by looking up the mapping relationship in the quantization model; at the same time, the initial urgency is fine-tuned in combination with the importance of the permission attribute association data and the business impact assessment, to generate more accurate urgency classification data. The urgency classification data is stored in the form of a data table, containing key fields such as permission attribute identifier, urgency level, time offset ratio, etc.
[0098] Step S2032, the urgency classification data is subjected to notification channel allocation processing, and the corresponding transmission channel is matched for different urgency signals, to generate an alarm routing configuration table.
[0099] Specifically, the present embodiment is pre-configured with multiple notification transmission channels, including but not limited to internal message queue, email system, instant messaging tool, SMS gateway, and dedicated operation and maintenance platform interface, etc. Each channel has different transmission characteristics, such as bandwidth, delay, reliability, security, and applicable urgency range. Step S2032 determines the most suitable notification transmission channel combination for each urgency level according to the urgency level in the urgency classification data, and the system calls the channel matching algorithm. For example, for high-urgency signals, the internal message queue and SMS gateway channels with high speed, reliability and security are preferentially allocated, to ensure that the alarm signal can be delivered to the administrator in the first time; medium-urgency signals are matched with the email system and instant messaging tool, taking into account timeliness and traceability; low-urgency signals are mainly notified through regular operation and maintenance reports and operation and maintenance platform interfaces.
[0100] In the matching process, the current load state of the channel is monitored in real time to avoid delay of the alarm signal due to channel congestion. The matching result is integrated into an alarm routing configuration table, which takes the urgency level as the index and records the transmission channel identifier, channel parameters and notification format requirements corresponding to each urgency. The alarm routing configuration table is stored in the configuration management center of the system, supporting dynamic updating and expansion, so as to adjust the notification channel strategy in time according to the business development and system changes, to ensure that the alarm signal can be quickly and accurately conveyed to the relevant personnel through the most suitable path, to guarantee the timely response and effective execution of the permission revocation operation.
[0101] Step S2033, the alarm routing configuration table is subjected to queue sorting processing, and the alarm signal sequence is reorganized in descending order of urgency, to generate a hierarchical alarm signal queue.
[0102] Specifically, step S2033 extracts all alarm signals to be processed from the alarm routing configuration table, which have associated corresponding emergency level and transmission channel information, step S2033 calls the sorting algorithm to rearrange the alarm signals in descending order according to the emergency level as the primary sorting key. During the sorting process, if signals with the same emergency level are encountered, a secondary sorting is further performed according to the importance of the authority attribute associated data and the business priority to ensure that the alarm signals of high priority business are processed first in the queue. The alarm signal sequence after sorting is reorganized into a hierarchical alarm signal queue, which is implemented using the data structure of a priority queue, with high emergency signals at the front of the queue, which are processed first. Each element in the queue contains complete information of the alarm signal, such as the authority attribute identifier, the emergency level, the transmission channel configuration, and the notification content template, etc.
[0103] Preferably, the embodiment sets up a hierarchical alarm signal queue monitoring mechanism, which tracks the queue length and processing progress in real time. When the queue length exceeds the preset threshold, the system resource dynamic expansion mechanism is triggered to increase the processing threads or optimize the channel bandwidth, ensuring that the alarm signals can be processed in time according to the emergency order, guaranteeing the efficient operation and business continuity of the authority management system, and realizing the precise scheduling and effective management of the authority revocation operation.
[0104] In summary, for example, step S2 adopts a scanning mechanism combining timing polling and event driving, timing polling scans the basic time tag set comprehensively according to the preset time interval, ensuring that no authority attribute approaching the critical time node is missed, event driving starts targeted scanning when receiving the authority attribute change notification or system load change signal, and focuses on identifying the start and end time of the warning window, intervention window and execution window in the authority attribute corresponding time tag and other key time nodes. When scanning finds that the authority attribute approaches or reaches the critical time node, the detailed information of the attribute is immediately extracted from the related data source, including user identification, associated data resources, current authority state, etc., and the attribute revocation information record is generated.
[0105] Specifically, in step S2, the attribute revocation information of each adjacent key node is verified according to the rules defined by the time label. The verification content includes whether the time sequence meets the expectation, whether the permission attribute is still in the valid state, whether it meets the constraint requirements of the associated business process, etc. The verification process adopts a multi-factor comprehensive judgment algorithm to ensure that only the permissions that truly meet the revocation conditions will trigger the alarm process. In this embodiment, according to the emergency degree and potential risk level of the attribute revocation information, the alarm signals are divided into different levels. High-risk and urgent revocation information generates high-level alarm signals and is placed at the front of the queue for priority processing; relatively low-risk ones generate low-level alarm signals and are arranged in turn. The alarm signal queue adopts a priority queue data structure and is dynamically adjusted in real time to ensure that the system can respond to various permission revocation events in order according to the risk priority.
[0106] Step S3, acquire system load data and perform abnormal state detection processing on the hierarchical alarm signal queue, adjust the scanning frequency and time window offset based on the dynamic load threshold, and generate an optimized time window scheduling plan.
[0107] Preferably, referring to Figure 4 Step S3 includes steps S301-S302:
[0108] Step S301, perform overload risk identification processing on the system load data, detect whether the resource consumption exceeds the elastic load threshold, and generate a system state flag.
[0109] Specifically, the system load data includes processor usage, memory occupancy, network bandwidth consumption, and storage I / O operation frequency, etc. In this embodiment, the elastic load threshold is dynamically set according to the system hardware configuration, business requirements, historical load data, etc. The setting of the elastic load threshold aims to ensure that the system runs stably within the normal load range and has certain elastic expansion capability to cope with sudden load peaks. Specifically, by monitoring the system load data in real time, step S301 detects whether the current resource consumption exceeds the elastic load threshold. If the resource consumption exceeds the elastic load threshold, a system state flag is generated to indicate that the current system is in an overload risk state; otherwise, if the resource consumption is within the elastic load threshold, a system state flag is generated to indicate that the current system is in a normal operating state.
[0110] Step S302, based on the system state flag, adjust the scanning parameters of the hierarchical alarm signal queue, dynamically optimize the time window scanning frequency, and generate an optimized time window scheduling plan.
[0111] Specifically, step S302 dynamically adjusts the scanning frequency of the time window according to the indication of the system state flag. When the system state flag indicates that the system is in an overload risk state, the scanning frequency is reduced to reduce resource consumption and prevent system overload. At this time, the time interval of scanning may be extended to reduce the occupation of system resources. Conversely, when the system state flag indicates that the system is in a normal operation state, the system can appropriately increase the scanning frequency to detect and handle alarm signals more timely. Through this dynamic adjustment mechanism, the system can reasonably allocate resources according to the current load condition, ensuring stable operation under high load conditions, and more efficient processing of alarm signals under low load conditions. Finally, the system generates an optimized time window scheduling plan, which specifies the scanning frequency and time window settings under different system states in detail.
[0112] Illustratively, step S3 collects system load indicator data such as CPU usage, memory occupation, network bandwidth, etc. in real time through performance monitoring modules deployed on servers, network devices, etc. infrastructure. At the same time, the load data of the business level such as database query response time, application server request quantity are statistically analyzed to comprehensively reflect the running load condition of the system. Preferably, based on anomaly detection algorithms in machine learning, such as clustering-based outlier detection, hypothesis testing based on statistical models, etc., the length variation of the hierarchical alarm signal queue, the alarm signal level distribution and the fluctuation of system load data are comprehensively analyzed. When abnormal conditions such as sudden and dramatic increase in the length of the alarm signal queue and long duration of high load state are detected, an abnormal state alarm is timely sent out.
[0113] Specifically, according to the real-time load data of the system and the business priority strategy, step S3 dynamically adjusts the load threshold. In the business peak period, the load threshold is appropriately increased to avoid frequent adjustment affecting business continuity; while in the trough period, the threshold is reduced to control resource utilization more finely. Through the sliding average algorithm combined with real-time feedback control, the load threshold is smoothly and dynamically adjusted. According to the adjusted load threshold and the current system state, the scanning frequency and the time window offset are recalculated. When the system load is high, the scanning frequency is appropriately reduced and the time window offset is increased to reduce resource occupation; conversely, the scanning frequency is increased and the offset is reduced to speed up the response. The generated optimized time window scheduling plan uses time series planning algorithm, considering factors such as task priority, resource allocation, etc. to ensure efficient and reasonable use of system resources, while ensuring the timeliness and accuracy of the authority revocation operation.
[0114] Step S4, the optimized time window scheduling plan is processed for authority risk analysis, the time-driven mechanism failure risk is identified through threat modeling, the backup trigger path configuration data is generated, and the attribute revocation action execution scheme is generated in combination with the main path.
[0115] Preferably, referring to Figure 5 Step S4 includes steps S401-S403:
[0116] Step S401, failure risk analysis is performed on the optimized time window scheduling plan, potential failure points in the time driving mechanism are identified through historical failure modes, and a risk feature map is generated.
[0117] Specifically, step S401 integrates system historical operation data, including past failure records, abnormal event reports, and maintenance logs, etc. Through data mining technology, the historical failure modes are deeply analyzed, and the repeated or potentially risky failure points in the time driving mechanism are identified, such as timer failure, task scheduling delay, dependent service response timeout, etc.
[0118] Preferably, step S401 can combine the Failure Mode and Effects Analysis (FMEA) method to evaluate the potential impact of each failure point on the revocation operation, including the impact range, severity and occurrence probability. Based on this, a risk feature map is constructed to visually present the vulnerable links of the time driving mechanism and their associated impacts. Each node in the map represents a specific failure point, the connection between nodes represents the association between failure points, and the weight of the connection reflects the closeness of the association. At the same time, each failure point is assigned a risk feature vector, including failure type, impact index, occurrence frequency, etc.
[0119] Step S402, generating backup paths for the risk feature map, creating contract enforcement channels for high-risk nodes, and generating disaster recovery path configuration schemes.
[0120] Specifically, for high-risk nodes identified in the map, such as key task scheduling nodes or network dependent nodes susceptible to external interference, step S402 develops a backup path generation strategy to create enforcement channels for these high-risk nodes by combining smart contracts. The smart contract is deployed on a blockchain platform, and its code logic predefines the automatic execution rules when the main path fails. When the main path fails, the smart contract is triggered, and the revocation operation is automatically executed according to the preset conditions, ensuring the continuity and timeliness of the task. The generation of backup paths not only involves technical implementation, but also needs to consider the adaptability of the system architecture and the rationality of resource allocation. The disaster recovery path configuration scheme specifies the start conditions, execution order, resource occupation limit, and switching mechanism with the main path. The scheme adopts a multi-copy storage strategy to ensure that configuration information can still be fully obtained when some nodes fail.
[0121] Step S403, based on the disaster recovery path configuration scheme, double-path integration processing is performed, merging the main time driving engine and the backup blockchain path, and generating an attribute revocation action execution scheme.
[0122] Specifically, step S403 deeply integrates the primary time-driven engine with the backup blockchain path according to the disaster recovery path configuration scheme. The primary time-driven engine is responsible for the scheduling of permission revocation tasks in normal circumstances, and its advantages lie in efficient task processing capability and fine control of business logic. The backup blockchain path provides redundant protection for critical tasks by virtue of the decentralized and tamper-proof characteristics of blockchain. In the integration process, an event-driven architecture is adopted to ensure seamless switching between the primary path and the backup path.
[0123] Specifically, when the primary path is running normally, the backup path is in a hot backup state, and the key state information of the primary path is synchronized in real time. Once the primary path fails, the backup path takes over and continues to perform the permission revocation operation according to the preset rules of the smart contract. To ensure the accuracy of the cooperative work of the dual paths, a strict data consistency verification mechanism is implemented to compare the data states of the primary and backup paths regularly and correct inconsistent situations in a timely manner. The attribute revocation action execution scheme integrates the operation processes, parameter configurations, execution conditions, and rollback strategies of the primary and backup paths, forming a unified execution specification.
[0124] In summary, step S4 constructs a risk matrix-based permission risk assessment model, considering factors such as the sensitivity of permission attributes, the importance of associated data, user behavior patterns, and system environment, to quantitatively assess the risk of each permission revocation task. The horizontal axis of the risk matrix represents the likelihood of risk occurrence, and the vertical axis represents the impact of risk. The specific weights and scoring standards of each factor are determined by combining expert scoring methods and historical data statistics. Preferably, combined with the DREAD threat modeling method (Damage-damage degree, Reproducibility-reproducibility, Exploitability-availability, Affected users-affected user number, Discoverability-discoverability), a comprehensive analysis of various threats that the time-driven mechanism may face is conducted, identifying risk points such as clock synchronization errors, task scheduling delays, and external attack disturbances that may cause time-driven failure, and describing each threat in detail and classifying the risk level.
[0125] For the identified time-driven mechanism failure risk, the embodiment designs multiple backup trigger paths in advance. The design of the backup path fully considers the redundancy architecture of the system and the correlation of different components, ensuring that at least one backup path can trigger the revocation action in time and reliably when the main path fails. For example, a distributed message queue is used as a backup signal transmission channel. When the main path cannot deliver the revocation instruction due to network failure or middleware failure, the system automatically switches to the message queue channel to ensure the delivery of the instruction. At the same time, the backup path is periodically checked for health and simulated for practice to ensure that it is always available.
[0126] Step S4 integrates the backup trigger path configuration data with the main path organically to build a complete attribute revocation action execution scheme. Specifically, the execution scheme adopts a main-backup switching strategy. Under normal circumstances, the revocation operation is preferentially executed through the main path. Once the main path is detected to be abnormal, it is immediately switched to the backup path according to the preset rules. During the switching process, the transaction consistency mechanism is used to ensure the integrity and accuracy of the revocation operation, avoiding abnormal situations such as partial revocation or repeated revocation.
[0127] Step S5, the attribute revocation action execution scheme is processed for encryption revocation, based on the attribute-based encryption policy tree to update the decryption key and generate a key update factor, and an encryption revocation scheme containing a policy update instruction and a key update factor is generated.
[0128] Preferably, referring to Figure 6 , step S5 includes steps S501-S503:
[0129] Step S501, the attribute revocation action execution scheme is processed for policy tree update, removing the access node of the invalid attribute in the attribute-based encryption policy, and generating an updated policy tree.
[0130] Specifically, the policy tree is represented in a tree data structure, where each node corresponds to a specific attribute access condition, and the leaf node represents a basic attribute, while the non-leaf node represents the logical combination relationship between attributes, such as AND, OR, NOT, etc. By analyzing the attribute revocation action execution scheme, the invalid attributes that need to be revoked are identified. These invalid attributes may no longer have access rights due to changes in user roles, adjustments in data sensitivity, or changes in business requirements, etc.
[0131] Preferably, step S501 can employ a depth-first search algorithm to recursively traverse the policy tree from the root node, and when a node matching the invalid attribute is detected, different processing strategies are adopted according to the node type and position; if it is a leaf node, the node is directly removed, and it is checked whether the parent node needs to be logically simplified or reconstructed due to the reduction of the number of child nodes; if it is a non-leaf node, the child nodes need to be processed first, and then the node merging or replacement is performed according to the logical combination relationship to avoid logical breakage. During the removal process, the logical validity of the policy tree is verified in real time to ensure that the updated policy tree can accurately reflect the current access control policy.
[0132] Step S502, random factor injection processing is performed on the system master key, a key update parameter is generated through discrete logarithm operation, and a key update factor is generated.
[0133] Specifically, the random factor is generated by a random number generator in a hardware security module (HSM), ensuring that it has sufficient randomness and unpredictability. The length and format of the random factor are set according to the cryptographic security standard to meet the system's requirements for key strength.
[0134] Specifically, step S502 combines the master key and the random factor through discrete logarithm operation, respectively mapping them to elements in a finite field, and generating a key update parameter through modular exponentiation operation. The parameter contains two parts: one is the public key part calculated based on the master key and the random factor, used for subsequent encryption and verification operations; the other is the private key part stored only in the secure environment, used for the final key update factor generation.
[0135] Step S502 generates a key update factor with uniqueness and timeliness by hashing the key update parameter with dynamic information such as the current timestamp and system unique identifier. The factor not only contains the core information required for key update, but also integrates the dynamic state of the system, making each key update non-reproducible and resistant to replay attacks. The key update factor will be securely stored in the key management system and distributed to related nodes through a secure channel, ensuring that only authorized entities can use the factor for key update operations, thereby effectively preventing key leakage and unauthorized access, and ensuring the security of the system master key and the reliability of the entire encryption system.
[0136] Step S503, broadcast encapsulation processing is performed on the updated policy tree and the key update factor, generating an encrypted revocation scheme containing policy update instructions and key factors.
[0137] Specifically, step S503 serializes the updated policy tree and the key update factor, converts them into a transmissible data format, and constructs a broadcast message data packet, the main part of which encapsulates the updated policy tree and the key update factor, as well as the policy update instructions related thereto. These instructions detail the execution steps, effective time, rollback mechanism, and other key contents of the update operation, ensuring that the receiving party can accurately understand and apply the update information. To protect the integrity and security of the data, the data packet is calculated for an integrity check value (such as HMAC) before transmission, and a digital signature is attached. The digital signature uses the system's private key to sign the data packet, and the receiving party can verify the authenticity of the signature through the system's public key, ensuring that the data has not been tampered with and comes from a trusted sender.
[0138] In summary, the attribute revocation action execution scheme is received, and the encryption permission revocation process is started. Preferably, in combination with attribute-based encryption (ABE), the decryption key is updated so that the user whose permission is revoked cannot decrypt the corresponding data resource even if he holds the old key, thereby realizing the encryption revocation of the permission. Compared with the way of directly deleting the key or modifying the access control list, the encryption permission revocation can finely control the user permission change without affecting the overall encryption system of the system. Among them, the attribute-based encryption policy tree updates the nodes related to the revoked permission in the policy tree according to the requirements of the attribute revocation action execution scheme. The update process includes adding new attribute restriction conditions, deleting expired or invalid attributes, and adjusting the logical relationship between attributes. A bottom-up update algorithm is used to ensure that the update of the policy tree does not unnecessarily affect the permissions of existing legal users, while ensuring that the updated policy tree can accurately reflect the current system permission policy. In the update process, a hash operation is performed on each node of the policy tree, and the change of the hash value is recorded for subsequent data consistency and integrity verification.
[0139] Based on the updated attribute-based encryption policy tree, a key update factor is generated for each user affected by the permission revocation. The generation of the key update factor uses a bilinear mapping technique to map and calculate the user's original key and the new policy tree parameters to generate an update factor with uniqueness and unpredictability. These update factors not only contain the necessary information required for user key update, but also integrate the current timestamp, random number, and other dynamic elements of the system, enhancing the security and attack resistance of the key. At the same time, the key update factor is digitally signed to ensure its integrity and non-repudiation during transmission and storage.
[0140] The encryption revocation scheme is encapsulated twice by the policy update instruction and the key update factor, adopts a standard encryption protocol format, and ensures compatibility and interoperability between different system components. The encryption revocation scheme is distributed to relevant data servers, client devices, key management systems and the like through a secure communication channel. In the distribution process, an end-to-end encryption transmission mechanism is adopted to prevent data from being stolen or tampered with during transmission. At the same time, detailed log records are kept during the distribution process, including distribution time, target node, scheme version and the like, so as to facilitate subsequent auditing and troubleshooting. After receiving the encryption revocation scheme, the data server and the client device update the local encrypted data and user key according to the instructions and factors in the scheme, complete the final execution of the permission revocation, and ensure that the system permission state is consistent with the latest access control policy.
[0141] Embodiment 2
[0142] On the basis of Embodiment 1, this embodiment provides an attribute revocation encryption access control system based on a time label. This embodiment takes the system applied to a terminal as an example. It can be understood that the system can also be applied to a server, and can also be applied to a system including a terminal and a server, and is realized through the interaction of the terminal and the server. As shown in Figure 7 The application provides an efficient attribute revocation encryption access control system based on a time label 100, which includes a time label definition module 110, an alarm triggering judgment module 120, a dynamic optimization module 130, a disaster recovery path configuration module 140, an encryption revocation execution module 150 and a data communication module 160.
[0143] (1) The time label definition module 110 is used for time label definition processing of the permission attribute data, and a three-level time constraint structure including a warning window, an intervention window and an execution window is constructed in combination with a preset security level to generate a basic time label set.
[0144] Preferably, the time label definition module 110 includes:
[0145] 1) An attribute domain analysis unit is used for attribute domain analysis processing of business requirement data, extracts a security level label and an invalid time parameter from the permission attribute, and generates a time window configuration benchmark.
[0146] 2) A three-level time structure construction unit is used for three-level time structure construction of the time window configuration benchmark, defines the hierarchical relationship of the warning window, the intervention window and the execution window according to the security level label, and generates a three-level time constraint framework.
[0147] 3) A policy template binding unit is used for policy template binding of the three-level time constraint framework, maps the access condition in the attribute encryption policy to the time window, and generates a timestamp configuration rule set.
[0148] 4) Distributed storage processing unit, for distributed storage of timestamp configuration rule set, storing time constraint parameters by using the tamper-proofing characteristics of block chain, and generating a basic time tag set.
[0149] (2) Alarm trigger judgment module 120 is used for key node scanning processing of the basic time tag set, obtaining attribute revocation information of the key time node to be reached and verifying the time tag trigger condition, and if the trigger condition is met, a hierarchical alarm signal queue is generated.
[0150] Preferably, referring to Figure 8 , the alarm trigger judgment module 120 comprises:
[0151] 1) Time dimension scanning unit 121, for time dimension scanning processing of the basic time tag set, calling a sliding window algorithm to detect the permission attribute of the adjacent execution window, and generating a to-be-triggered attribute list.
[0152] 2) Time tag verification unit 122, for time tag verification of the to-be-triggered attribute list, analyzing the time inclusion relationship between the current time and the execution window, and generating a trigger state judgment result.
[0153] 3) Signal hierarchical processing unit 123, for signal hierarchical processing of the trigger state judgment result, dividing the alarm signal urgency according to the time window level, and generating a hierarchical alarm signal queue.
[0154] Preferably, the signal hierarchical processing unit 123 comprises:
[0155] 1、Emergency quantification sub-unit 1231, for emergency quantification of the trigger state judgment result, calculating signal priority weight through time offset ratio, and generating emergency degree hierarchical data.
[0156] 2、Notification channel allocation sub-unit 1232, for notification channel allocation processing of the emergency degree hierarchical data, matching corresponding transmission channels for different emergency degree signals, and generating an alarm routing configuration table.
[0157] 3、Queue sorting processing sub-unit 1233, for queue sorting processing of the alarm routing configuration table, reorganizing the alarm signal sequence in descending order of emergency degree, and generating a hierarchical alarm signal queue.
[0158] (3) Dynamic optimization module 130 is used for abnormal state detection processing of the hierarchical alarm signal queue based on system load data, adjusting the scanning frequency and time window offset based on the dynamic load threshold, and generating an optimized time window scheduling plan.
[0159] Preferably, the dynamic optimization module 130 comprises:
[0160] 1) overload risk identification unit, for overload risk identification processing on system load data, detecting whether resource consumption exceeds the elastic load threshold, generating system state flag.
[0161] 2) scanning parameter adjustment unit, for scanning parameter adjustment processing on hierarchical alarm signal queue based on system state flag, dynamically optimizing time window scanning frequency, generating optimized time window scheduling plan.
[0162] (4) disaster recovery path configuration module 140 is used for permission risk analysis processing on the optimized time window scheduling plan, identifying time-driven mechanism failure risk through threat modeling, generating backup trigger path configuration data, and combining the main path to generate attribute revocation action execution scheme.
[0163] Preferably, the disaster recovery path configuration module 140 includes:
[0164] 1) failure risk analysis unit, for failure risk analysis on the optimized time window scheduling plan, identifying potential failure points of the time-driven mechanism through historical failure modes, and generating risk feature map.
[0165] 2) disaster recovery path generation unit, for backup path generation on the risk feature map, creating an intelligent contract enforcement channel for high-risk nodes, and generating a disaster recovery path configuration scheme.
[0166] 3) dual-path integrated execution unit, for dual-path integration processing based on the disaster recovery path configuration scheme, merging the main time-driven engine and the backup blockchain path, and generating the attribute revocation action execution scheme.
[0167] (5) encryption revocation execution module 150 is used for encryption permission revocation processing on the attribute revocation action execution scheme, updating the decryption key based on the attribute-based encryption policy tree and generating the key update factor, and generating the encryption revocation scheme containing the policy update instruction and the key update factor.
[0168] Preferably, the encryption revocation execution module 150 includes:
[0169] 1) policy tree update unit, for policy tree update processing on the attribute revocation action execution scheme, removing access nodes of invalid attributes in the attribute-based encryption policy, and generating an updated policy tree.
[0170] 2) key update factor generation unit, for random factor injection processing on the system master key, generating a key update parameter through discrete logarithm operation, and generating a key update factor.
[0171] 3) encryption revocation scheme packaging unit, for broadcast packaging processing on the updated policy tree and the key update factor, generating the encryption revocation scheme containing the policy update instruction and the key factor.
[0172] (6) The data communication module 160 is used to obtain the permission attribute data and system load data, and send the encryption revocation scheme to the execution mechanism.
[0173] In summary, the system sends broadcast message data packets to all relevant nodes such as data servers, client devices, and key management systems through a secure communication protocol such as TLS / SSL. During data transmission, end-to-end encryption technology is used to prevent data from being stolen or tampered with during transmission. After receiving the broadcast message, the receiving node first verifies the digital signature and integrity check value to ensure the integrity and authenticity of the data. After verification, the data packet is parsed, the updated policy tree and key update factor are extracted, and the local policy and key update operation is performed according to the policy update instruction.
[0174] The time label-based efficient attribute revocation encryption access control system provided in this embodiment performs fine processing on the permission attribute data through the time label definition module 110, constructs a three-level time constraint structure, introduces a precise control framework with a time dimension from the source for permission management, and the alarm trigger judgment module 120 can acutely capture the state change of the permission attribute approaching the key time node, verify the trigger condition in a timely manner, and generate a hierarchical alarm signal queue, effectively alleviating the problem of manual review lag and ensuring the timeliness of permission revocation. The dynamic optimization module 130 intelligently adjusts the scanning frequency and time window offset based on system load data, generates a time optimization window scheduling plan, overcomes the rigid drawbacks of traditional timing check strategies, enables the system to operate efficiently under different load scenarios, and avoids resource redundancy or instruction accumulation. The disaster recovery path configuration module 140 relies on threat modeling technology to deeply analyze potential risks of the time-driven mechanism, pre-plans backup trigger paths and integrates them with the main path, constructs a highly reliable permission revocation execution scheme, and greatly reduces the security risks caused by mechanism failure. The encryption revocation execution module 150 starts from the cryptography level, updates the decryption key based on the attribute-based encryption policy tree, generates a key update factor, forms an encryption revocation scheme, completely eliminates the risk of attackers decrypting revoked permission data using historical keys, and comprehensively improves the security and reliability of permission revocation. The data communication module 160 is responsible for stable acquisition of various data and accurate distribution of encryption revocation schemes, ensuring smooth data flow and unblocked instruction transmission throughout the process.
[0175] The time label-based efficient attribute revocation encryption access control system provided in this embodiment can achieve a response to permission change requirements within seconds in terms of timeliness, meeting the stringent requirements of key businesses such as finance and healthcare; in terms of resource efficiency, it can achieve precise matching of load and resource consumption to ensure the sustained stability of system performance; in terms of security and reliability, it fundamentally eliminates the threat of historical keys and effectively fortifies the data security line, providing comprehensive and highly reliable technical support for complex and variable access control scenarios in the cloud and Internet of Things era.
[0176] Embodiment 3
[0177] On the basis of the foregoing embodiments, the present embodiment provides an electronic device, comprising: one or more processors and a memory, the memory having stored therein one or more programs, the one or more programs including instructions for performing the time label based attribute revocation encryption access control method as described in Embodiment 1.
[0178] As Figure 9 described, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course can also include other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs to implement the above Figure 1 described method.
[0179] The memory can include non-permanent memory in a computer readable medium, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer readable medium.
[0180] The computer readable medium includes permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic disk storage or other magnetic storage device, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer readable medium does not include transitory computer readable media, such as modulated data signals and carriers.
[0181] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A time label based attribute revocation encryption access control method, characterized by, The method comprises the following steps: The acquired permission attribute data is subjected to time tag definition processing, and a three-level time constraint structure including a warning window, an intervention window and an execution window is constructed in combination with a preset security level to generate a basic time tag set; The basic time tag set is subjected to key node scanning processing to acquire attribute revocation information of a key time node to be reached and verify a time tag trigger condition, and a hierarchical alarm signal queue is generated if the trigger condition is met; System load data is acquired and the hierarchical alarm signal queue is subjected to abnormal state detection processing, the scanning frequency and time window offset are adjusted based on a dynamic load threshold, and an optimized time window scheduling plan is generated; The optimized time window scheduling plan is subjected to permission risk analysis processing, a time-driven mechanism failure risk is identified through threat modeling, backup trigger path configuration data is generated, and an attribute revocation action execution scheme is generated in combination with a main path; The attribute revocation action execution scheme is subjected to encrypted permission revocation processing, a decryption key is updated based on an attribute-based encryption strategy tree and a key update factor is generated, an encrypted revocation scheme containing a policy update instruction and the key update factor is generated, and attribute revocation encrypted access control is achieved.
2. The time label based attribute revocation encryption access control method according to claim 1, characterized in that, The process of generating the basic time tag set comprises the following steps: The business requirement data is subjected to attribute domain analysis processing, security level tags and failure time parameters are extracted from the permission attributes, a preliminary time range is configured for each permission, and a time window configuration benchmark is generated; A three-level time structure is constructed based on the time window configuration benchmark, a hierarchical relationship of the warning window, the intervention window and the execution window is established according to the security level tags, a smaller window interval is set for a permission with a higher security level, and a three-level time constraint framework is constructed, wherein the warning window is used for monitoring the permission state in advance, the intervention window is used for reserving time for administrator manual intervention for permission adjustment, and the execution window is used for executing permission revocation, and the length of the execution window is calculated according to the security level and the business criticality; Based on the constraint rules of each permission attribute in the time dimension, the three-level time constraint framework is subjected to policy template binding, the access conditions in the attribute encryption policy are mapped to the time window, and a time stamp configuration rule set is generated; The time stamp configuration rule set is subjected to distributed notarization, the time constraint parameters are stored by utilizing the tamper-proof feature of the block chain, and a basic time tag set is generated.
3. The time label based attribute revocation encryption access control method according to claim 1, wherein, The process of generating the hierarchical alarm signal queue comprises the following steps: The basic time tag set is subjected to time dimension scanning processing, the permission attributes of the adjacent execution window are detected through a sliding window, and a list of attributes to be triggered is generated; The list of attributes to be triggered is subjected to time tag verification, the time inclusion relationship between the current time and the execution window is analyzed, and a trigger state judgment result is generated; The trigger state judgment result is subjected to signal hierarchical processing, the alarm signal urgency is divided according to the time window hierarchy, and a hierarchical alarm signal queue is generated.
4. The attribute revocation encryption access control method based on time label according to claim 3, characterized in that, The process of generating the hierarchical alarm signal queue according to the time window hierarchy to divide the alarm signal urgency comprises the following steps: The trigger state judgment result is subjected to urgency quantification, the signal priority weight is calculated through a time offset ratio, and urgency hierarchical data is generated; The emergency classification data is subjected to notification channel allocation processing, corresponding transmission channels are matched for different emergency signals, and an alarm routing configuration table is generated; The alarm routing configuration table is subjected to queue sorting processing, alarm signal sequences are reorganized in descending order of emergency, and a hierarchical alarm signal queue is generated.
5. The time label based attribute revocation encryption access control method according to claim 1, wherein, The optimization time window scheduling plan generation process includes the following steps: The system load data is subjected to overload risk identification processing, whether resource consumption exceeds the elastic load threshold is detected, and a system state flag is generated; Based on the system state flag, the hierarchical alarm signal queue is subjected to scanning parameter adjustment processing, the time window scanning frequency is dynamically optimized, and an optimized time window scheduling plan is generated.
6. The time label based attribute revocation encryption access control method according to claim 1, wherein, The generation process of the attribute revocation action execution scheme includes the following steps: The optimized time window scheduling plan is subjected to failure risk analysis, potential failure points of the time driving mechanism are identified through historical failure mode, and a risk feature map is generated; The risk feature map is subjected to backup path generation, a contract enforcement channel is created for high-risk nodes, and a disaster recovery path configuration scheme is generated; Based on the disaster recovery path configuration scheme, double-path integration processing is performed, the main time driving engine and the backup blockchain path are fused, and an attribute revocation action execution scheme is generated.
7. The time label based attribute revocation encryption access control method according to claim 1, wherein, The generation process of the encryption revocation scheme includes the following steps: The attribute revocation action execution scheme is subjected to strategy tree update processing, the access nodes of the invalid attributes in the attribute-based encryption strategy are removed, and an updated strategy tree is generated, wherein each node in the strategy tree corresponds to an attribute access condition, the leaf node represents a basic attribute, and the non-leaf node represents a logical combination relationship between attributes; The system master key is subjected to random factor injection processing, key update parameters are generated through discrete logarithm operation, and a key update factor is generated; The updated strategy tree and the key update factor are subjected to broadcast encapsulation processing, and an encryption revocation scheme containing the strategy update instruction and the key factor is generated.
8. A time label based attribute revocation encryption access control system, characterized by, The system for implementing the time label-based attribute revocation encryption access control method according to any one of claims 1-7 includes: A time label definition module for performing time label definition processing on the permission attribute data, constructing a three-level time constraint structure including a warning window, an intervention window and an execution window in combination with a preset security level, and generating a basic time label set; An alarm trigger judgment module for performing key node scanning processing on the basic time label set, obtaining attribute revocation information approaching a key time node and verifying a time label trigger condition, and generating a hierarchical alarm signal queue if the trigger condition is met; A dynamic optimization module for performing abnormal state detection processing on the hierarchical alarm signal queue based on system load data, adjusting the scanning frequency and the time window offset based on a dynamic load threshold, and generating an optimized time window scheduling plan; A disaster recovery path configuration module for performing permission risk analysis processing on the optimized time window scheduling plan, identifying the failure risk of the time driving mechanism through threat modeling, generating backup trigger path configuration data, and generating an attribute revocation action execution scheme in combination with the main path; The encryption revocation execution module is configured to perform encryption permission revocation processing on the attribute revocation action execution scheme, update a decryption key based on an attribute-based encryption policy tree, and generate a key update factor, and generate an encryption revocation scheme containing a policy update instruction and the key update factor; The data communication module is configured to acquire the permission attribute data and the system load data, and send the encryption revocation scheme to an execution mechanism.
9. An electronic device, comprising: The system comprises: One or more processors and a memory, the memory storing one or more programs, the one or more programs comprising instructions for performing the time label-based attribute revocation encryption access control method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The system comprises one or more programs for execution by one or more processors of an electronic device, the one or more programs comprising instructions for performing the time label-based attribute revocation encryption access control method according to any one of claims 1-7.
Citation Information
Patent Citations
Situation awareness defense method and system based on attribute access control
CN113411297A