Smart home security access control method, device and storage medium
By adopting distributed blockchain technology and trust management center in smart home systems and using smart contracts for decentralized access control, the problems of single point of failure, low security and insufficient privacy in existing systems are solved, and higher security and privacy protection are achieved.
Patent Information
- Application Number
- CN202210031267.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-01-12
AI Technical Summary
The existing smart home access control system has problems such as single point of failure, low security and insufficient privacy, especially when facing DDOS attacks, it is difficult to effectively defend.
The distributed blockchain technology and trust management center are adopted to control access through smart contracts, use identity tokens and trust capability tokens to verify the identity and permissions of the subject, and ensure the decentralization, security and privacy of the system through encrypted storage access results.
Decentralized access control of smart home systems is realized, the security and privacy of the system are enhanced, and the risks brought by single point of failure and DDOS attacks are avoided.
Smart Images

Figure CN114510731B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to Internet of Things technology, and in particular to a smart home security access control method, device and storage medium. Background Art
[0002] Smart home is a typical IoT application scenario. Smart home systems are designed to improve the quality of life by providing a variety of automated, interactive and comfortable services, such as providing medical services to family members, remotely controlling devices through mobile phones, emails, etc., or turning on the air conditioner before the user enters the door to make the user feel a comfortable temperature. However, at the same time, this convenience may bring potential risks of malicious network attacks, thereby posing risks to the safety and privacy of residents.
[0003] In the face of security issues in smart home systems, access control technology can prevent attackers from accessing and modifying data in devices, playing an important role in protecting residents' resources and information. In addition, traditional access control models, such as access control lists (ACLs), role-based access control (RBAC), capability-based access control (CapAC), and attribute-based access control (ABAC), have been widely used in the field of information technology security [8]. However, since these technologies are almost all centralized access authorization architectures, it is difficult to prevent the occurrence of single point failures. Malicious or infected centralized entities can authorize illegal requests from malicious nodes. Therefore, existing technologies cannot provide a safe and effective mechanism to meet the privacy protection and security requirements of smart home systems.
[0004] In recent years, the emerging blockchain technology is very suitable for the distributed architecture of the Internet of Things. It can solve the security, trust, privacy, scalability and reliability issues associated with the Internet of Things paradigm. Blockchain technology can also improve the security of smart home systems. Specifically, blockchain technology reduces many security issues in smart homes, such as authentication and authorization, confidentiality, integrity and single point attacks. Therefore, blockchain technology is applied to smart home access control systems to protect smart devices, personalized services and resident information in smart home systems.
[0005] At present, many access control schemes based on blockchain technology have been proposed in smart home systems. [3,4,5,6] This technology can be divided into two categories: using blockchain technology as a trusted database to store access control policies and access result information; using smart contracts to implement access control mechanism models. However, existing blockchain-based smart home access control systems generally have the following defects:
[0006] 1) Lack of distribution: The centralized blockchain access control model uses blockchain as a trusted storage platform, and its access control policy runs in a centralized authorization server. However, this approach cannot guarantee the fairness and security of the authorization server itself, and has disadvantages such as single point failure, difficulty in expansion, low reliability, and low throughput.
[0007] 2) Lack of security: When some malicious nodes launch a DDOS attack on the blockchain network by repeatedly sending access requests, the blockchain network will be blocked.
[0008] 3) Lack of privacy: Since the access records of the devices are stored on the blockchain ledger, malicious nodes can use this information to infer the daily activities of residents. Summary of the invention
[0009] The technical problem to be solved by the present invention is to provide a smart home security access control method, device and storage medium to prevent malicious devices from launching DDOS network attacks in view of the deficiencies in the existing technology.
[0010] In order to solve the above technical problems, the technical solution adopted by the present invention is: a smart home security access control method, comprising the following steps:
[0011] The subject sends an access request to the access control contract, and the access control contract determines whether the access request sent by the subject is a normal access request. If so, the access result is saved in the Hyperledger Structure ledger, and the subject sends a connection request to the object; wherein, the access control contract verifies the subject's identity token and matches the authority possessed by the subject's trust token with the requested authority in the access request sent by the subject to determine whether the access request sent by the subject is a normal access request;
[0012] The object calls the access control contract to query the access result and makes an access decision based on the access result;
[0013] The credit management center updates the trust capability tokens of the subject and object.
[0014] In the present invention, the authority that a subject can possess is calculated through the trust capability token of the subject, and the trust value of the subject is obtained through the trust capability token of the subject, thereby obtaining the authority that the subject can possess.
[0015] The method of the present invention is distributed: because of the distribution of the blockchain network itself, the subject can send an access request to the access control smart contract, and the access control contract will determine whether the subject's access request is a normal access request. If the subject's access request is a normal access request, the access control contract will automatically generate an access result. Then the subject sends a request to connect to the object. The object sends a query access result request to the access control contract to query the access result. The object decides whether to accept the subject's request to connect based on this access result. In this access control process, the method of the present invention does not require a centralized authorization server to determine whether the subject's access request is a normal access request, and does not require a centralized authorization server to decide whether the object accepts the subject's connection request. Therefore, the present invention can ensure the fairness and security of the authorization server itself, and overcome the shortcomings of single point failure, difficulty in expansion, low reliability, and low throughput in the prior art.
[0016] The method of the present invention is safe: the method adds a trust management center, which calculates the behavior reputation value and trust attribute value of the device, thereby calculating the trust value of the device. If the trust value of the device is low, then the device cannot connect to other devices. The home management center registers the identity token of the device, which ensures that the device has a real identity in the blockchain network. Therefore, the method can prevent malicious devices from launching network attacks such as DDOS.
[0017] The method of the present invention has privacy protection: the access control contract encrypts the access results of the device to prevent malicious devices from arbitrarily querying the access results of each device. Because attackers can infer the living habits of residents from the access results of these devices, this method protects the privacy data of residents from being stolen.
[0018] The specific implementation process of the access control contract to determine whether the access request sent by the subject is a normal access request includes:
[0019] The access control contract calls the trust contract to record the subject's access status. If the subject's access request is approved, it is considered a normal access request; otherwise, it is considered an abnormal access request.
[0020] The specific implementation process of the access control contract calling the trust contract to record the access status of the subject includes:
[0021] Check the device identity token in the access request. If the identity token is incorrect, the subject's access behavior is recorded as abnormal access behavior.
[0022] Determine whether the requested permissions in the subject's access request match the permissions that the subject can have. If they do not match, the subject's access behavior is recorded as abnormal access behavior; the permissions that the subject can have are calculated through the subject's trust capability token, and the subject's trust value is obtained through the subject's trust capability token, thereby obtaining the permissions that the subject can have. The calculation formula for the permissions P that the subject can have is: P is permission, TR id The credit value of the subject;
[0023] The access control contract calculates the time the object provides services to the subject, and the calculation formula is:
[0024] is the credit value of the subject at the current time point t,
[0025] is the credit value of the object at the current time point t; Represents the subject id at time point t; Represents the object id at time point t;
[0026] The access control contract encrypts the device ID and access time into a virtual ID, and the access result is stored in the Hyperledger Fabric ledger; the access result includes the device ID, the service provided by the object, and the time when the object provides the service to the subject.
[0027] The implementation process of the access control contract calling the trust contract to record the access status of the subject can ensure that the data calculated by the trust management center when calculating the trust value of the device is complete, reliable, and cannot be tampered with.
[0028] In the present invention, the identity token is obtained by calling the identity contract registration by the home management center in the smart home system, and the identity contract, trust contract and access control contract are installed in the Hyperledger Fabric blockchain network.
[0029] The specific implementation process of the credit management center updating the trust capability token of the subject and object includes:
[0030] Calculate the time point t using the following formula id The subject's behavioral reputation
[0031]
[0032] in, Indicates time point t id The device id, N(t i ) is the weight function of the subject’s normal access behavior, t i ∈[tid -T, t id ]; 0≤a<1; M(tj) is the weight function of the subject’s abnormal access behavior, t j ∈[t id -T, t id] ;ti is the time point when the subject sends an access request, and the access request is passed; t j is the time point when the subject sends an access request and the access request is not approved; T is the time period; θ is set to n and m are the total number of normal access behaviors and the total number of abnormal access behaviors of the subject in the time period T, respectively;
[0033] The trust attribute value of the object is calculated using the following formula:
[0034]
[0035] in, v is the total number of evaluation results for the object; K is the trust level; tr(D id , S id ) is the evaluation result of the subject on the service provided by the object; TR id is the credit value of the subject;
[0036] The trust management center calls the trust contract to update the trust value of the device, namely the behavior reputation value and trust attribute value.
[0037] The behavior reputation value of a device is associated with the device's access status: if the device access time is far away from the time of calculating the device's behavior reputation value and it is a normal access, the device's behavior reputation value will slowly increase; if the device access time is close to the time of calculating the device's behavior reputation value and it is an abnormal access, the device's behavior reputation value will drop rapidly. This prevents the device's behavior reputation value from dropping rapidly due to abnormal access status of the device caused by system failures and other reasons.
[0038] The calculation process of the trust attribute value of the device reduces the influence of malicious evaluation results of other devices and improves the authenticity and credibility of the trust attribute value of the device.
[0039] K=0.5.
[0040] The present invention also provides a computer device, comprising a memory, a processor and a computer program stored in the memory; the processor executes the computer program to implement the steps of the method of the present invention.
[0041] The present invention also provides a computer program product, comprising a computer program / instruction; when the computer program / instruction is executed by a processor, the steps of the method of the present invention are implemented.
[0042] The present invention also provides a computer-readable storage medium on which a computer program / instruction is stored; when the computer program / instruction is executed by a processor, the steps of the method of the present invention are implemented.
[0043] Compared with the prior art, the present invention has the following beneficial effects:
[0044] 1) The trust management center of the present invention can ensure the safe operation of the access control system of the smart home system;
[0045] 2) The access control scheme of the present invention has a decentralized characteristic, and the device (target) node can query the access result and make an access decision, which greatly ensures the access efficiency of the device and the security of the system;
[0046] 3) The present invention designs an access control model based on blockchain technology to provide a secure operating platform for the smart home system, and the smart contract enables the service entity to automatically execute the specifications;
[0047] 4) The present invention encrypts the access results and stores them in the ledger of blockchain technology, thus protecting the privacy of residents;
[0048] 5) The Trust Management Center solves the security risk problem caused by DDOS attacks on the blockchain network. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 This is the structure diagram of the smart home system based on blockchain technology;
[0050] Figure 2 It is the interaction process between the trust management center and the blockchain;
[0051] Figure 3 Installed on blockchain network for smart contracts;
[0052] Figure 4 Example for device A to access device B;
[0053] Figure 5 The change trend of the device behavior reputation value under normal device access behavior;
[0054] Figure 6 The changing trend of the device behavior reputation value under abnormal device access behavior;
[0055] Figure 7 The changing trend of device behavior reputation value in multiple time periods;
[0056] Figure 8 The change trend of the device trust attribute value;
[0057] Fig. 9 Call the identity contract for the home management center to add the device token result;
[0058] Fig.10 Query device token results for device clients;
[0059] Fig.11 Add trust capability token results to the trust management center;
[0060] Fig.12 Query the device trust capability token result for the device client;
[0061] Fig.13 The access control contract makes logical judgments on the access request of the device (subject);
[0062] Fig.14 Call the access control contract for the device client to query the access result;
[0063] Fig.15 Flowchart of the logical judgment of the access control contract on the access request of device A. DETAILED DESCRIPTION
[0064] The present invention is a smart home security access control method based on blockchain and trust management, including a trust management center for calculating the trust value of device nodes, and multiple smart contracts. Specifically, the smart contract in the method of the present invention includes an identity contract, a trust contract and an access control contract. The identity contract is used for device node registration. The trust contract records the access behavior and evaluation value of the device. And the access control contract performs logical judgment on the access request. The blockchain technology platform used in the method of the present invention is Hyperledger Fabric. The trust value calculation function is completed in the off-chain trust management center.
[0065] like Figure 1As shown, the present invention designs a smart home system based on blockchain technology. This smart home system includes a variety of smart devices, which are mainly divided into daily service devices, home security devices and home service robots. In this smart home system, the home management center includes a trust management center and a data storage device. The home management center is responsible for the registration, update and other functions of the device. The trust management center is responsible for the credit value management of the device. The data storage device is mainly responsible for storing some important resident data. Smart devices can have two roles: subject and object. The subject is the role when the device sends an access request. The object is the role when the device provides a service. Many service providers and home management centers form a consortium blockchain network. These entities correspond to nodes in Hyperledger Fabric. The three types of devices can be divided into three organizations and connected by channels. The following are the specific steps of this method:
[0066] like Figure 3 As shown, the identity contract, trust contract and access control contract are installed in the Hyperledger Fabric blockchain network;
[0067] The device calls the identity contract through the home management center to register an identity token. The definition of this identity token ICap is as follows: ICap = [ID|DI|CAS] ID: The virtual identity of this smart device. DI: Relevant information of the device, such as the device registration time. CAS: The signature issued by the authentication center of the home management center.
[0068] The trust contract mainly completes the functions of registering, querying, and updating the trust capability token of the device. The trust capability token TCap contains the entity's behavioral reputation value BR and trust attribute value TA. The behavioral reputation value BR and the trust attribute value TA are two different concepts. TA is used to measure the inherent capabilities and trust attributes of the S device (object) when performing the target task, and BR uses the historical behavior data of the device (subject) accessing the device (object) to dynamically evaluate its trustworthiness. They are both important factors affecting the evaluation of the trust relationship between devices. TCap is defined as follows: TCap = [(αBR ID +βTR ID )]. BR ID :Evaluation of device access behavior. TR ID: Device trust attribute value, collected by the trust management center. α, β: According to different categories of device nodes and satisfy α+β=1. Devices can be divided into three categories: devices that only send access requests, devices that both send access requests and provide services, and devices that only provide services. Devices that only send access requests are devices that only send access requests most of the time. Devices that both send access requests and provide services are devices that send access requests and provide services most of the time. Devices that only provide services are devices that provide services most of the time. For devices that only send access requests, α is set to 0.95 and β is set to 0.05. For devices that both send access requests and provide services, α is set to 0.5 and β is set to 0.5. For devices that provide services, α is set to 0.05 and β is set to 0.90. The following are the steps for the trust management center to manage the credit values of devices:
[0069] The device node calls the trust contract through the trust management center to register the trust capability token.
[0070] When a device interacts (the device (subject) sends an access request to the device (object) or the device (object) provides a service to the device (subject)), the trust token of the device will be updated. Figure 2 As shown, the specific steps for the trust management center to call the trust contract to update the trust capability token of the device are as follows:
[0071] When the access control contract makes a logical judgment on the access request of the device (subject), the access control contract will call the trust contract to record the access status of the device (subject). If the access request of the device (subject) is passed, it is regarded as normal access to the device. Otherwise, it is regarded as abnormal access to the device (object). The access status of the device (subject) is stored in the account book of Hyperledger Fabric, providing data for the trust management center to calculate the behavior reputation value BR of the device (subject).
[0072] After the access request of the device (subject) passes the logical judgment of the access control contract, the device (object) will provide the corresponding service to the device (subject). Then the device (subject) evaluates the service provided by the device (object). The device (subject) calls the trust contract to evaluate the service of the device (object). The evaluation result of the device (object) is stored in the account book of Hyperledger Fabric, providing data for the trust management center to calculate the trust attribute value of the device (object)
[0073] The trust management center calculates the credit value of the device (subject) offline. The credit value of the device (subject) includes the device's behavior reputation value BR and trust attribute value TA.
[0074] Trust management uses a dynamic evaluation method based on probability theory to calculate the behavior reputation (BR) of a device (subject). The following is the calculation of this time point t idThe formula for the behavioral reputation value of the id device (subject).
[0075]
[0076] In the above formula, This is the time point t id The behavior reputation value of the device. It indicates the time point t of this id device id . N(t i ) is a weight function for computing the normal access behavior of a device (subject), defined as follows: Set to Indicates that recent device access behavior has a greater weight on the device's behavior reputation value. i It is the time point when the device (subject) sends an access request and the access request is approved. j ) is the weight function of the abnormal access behavior of the computing device, which is defined as follows: Set to Indicates that recent device access behavior has a greater weight on the device's behavior reputation value. id The time point when the behavior reputation value of the device (subject) is calculated. j It is the time point when the device (subject) sends an access request and the access request is not passed. T is a time period. Trust switch function f switch (x) is defined as follows:
[0077] θ is set to This formula shows that when the total weight of the abnormal behavior of the device exceeds θ, the switch function value will increase sharply. n and m are the total number of normal access behaviors and the total number of abnormal access behaviors of the device (subject) in this period T, respectively.
[0078] The trust management center calls the trust contract to obtain the device attributes from the Hyperledger Fabric account book. The trust management center aggregates the evaluation scores of the device (subject) to calculate the trust attribute value of the device (object). The aggregation function is defined as follows:
[0079]
[0080] In the formula, Tr i The definition is as follows:
[0081] tr(D id , S id) is the evaluation result of the service provided by the device (subject) to the device (object). The evaluation method is shown in reference [7]. This evaluation result includes the evaluation score and the scoring time. id is the credit value of the device (subject). v is the total number of evaluation results for the device (object). K is the trust level, which is generally set to 0.5. Set to
[0082] After the trust management center calculates the credit value of the device offline, it will call the trust contract to update the trust value of the device and store it as a copy of the data state in the Hyperledger Fabric ledger.
[0083] The access control contract performs logical judgment on the access request and then stores the data status of the access result in the Hyperledger structure account. The specific steps are as follows:
[0084] Check the device identity token in the access request. If the identity token is wrong, record the abnormal access behavior of the device (subject).
[0085] Determine whether the requested permissions in the access request of the device (subject) match the permissions that the device (subject) can have. If they do not match, record the abnormal access behavior of the device (subject). The requested permissions in the request can be divided into execute, read, and write operations. In order to facilitate the calculation of device permissions, 1 represents execute, 2 represents read, and 4 represents write. The formula for calculating device permissions is: P stands for permission. id The credit value of the device.
[0086] After the above steps are completed, the access control contract calculates the time that the device (object) provides services to the device (subject). The calculation formula is: is the credit value of the device (subject) at the current time point t, It is the credit value of the device (object) at the current time point t. It is the ID of the main device and the current time point t. It is the ID of the device (object) and the current time point t. The effective time of the service provided by the device (object) is related to the credit value between the devices. The higher the credit value of the device (subject) is than the credit value of the device (object), the longer the service time provided by the device (object) is.
[0087] The access control contract encrypts the vid and access time of the device (subject, target) into a virtual id, and the access result is stored in the Hyperledger Fabric ledger. The access result includes the device id (subject, object), the service provided by the device (object), and the time when the device (object) provides the service.
[0088] like Figure 4 , the specific steps for device A to access device B are as follows:
[0089] Step 1: Devices A and B call the identity contract to register identity tokens through the home management center.
[0090] Step 2: Devices A and B call the trust contract to register the trust capability token through the credit management center.
[0091] Step 3: Device A sends a request to the access control contract. Fig.15 shown.
[0092] Step 4: The access control contract judges the request.
[0093] Step 5: The access control contract saves the access result in the ledger.
[0094] Step 6: Device A sends a connection request to device B.
[0095] Step 7: Device B calls the access control contract to query the access result.
[0096] Step 8: Device B makes an access decision based on the access result.
[0097] Step 9: The credit management center updates the trust capability tokens of the subject and the object.
[0098] The present invention compares the evaluation algorithm of the behavior reputation value and the aggregation algorithm of the trust attribute value. Figure 4 , 5, 6 are the evaluation algorithm (TS-DE) and DE of the present invention [1] and AIG [2] Comparison results of the algorithms. Figure 7 The comparison results of the aggregation algorithm (Time-Aggregation-TR) of the present invention with the crude aggregation algorithm (Crude Aggregation) and the reputation iteration algorithm (RE-Aggregation). In the trust management center, the TS-DE algorithm of the present invention has the ability to resist bleaching attacks, betrayal attacks and interference compared with other algorithms. In terms of trust attribute value aggregation, the aggregation algorithm of the present invention adds two factors: interaction time and trust value of the evaluation device (subject). Therefore, compared with other aggregation algorithms, the algorithm of the present invention can resist attacks from malicious devices.
[0099] The present invention performs functional testing of smart contracts. Figure 7 , 8 As shown in Figure 9, the present invention tests the operation of the identity contract, trust contract and access control contract respectively. The results show that the smart contract of the present invention can effectively run on the Hyperledger Fabric platform.
[0100] References:
[0101] [1] Zhang Wenfang, Dong Guanqun, Wang Xiaomin, et al. Task-role based access control model based on multi-step dynamic trust evaluation [J]. Computer Integrated Manufacturing Systems, 2018, 24(8).
[0102] [2]Putra GD, Dedeoglu V, Kanhere SS, et al.Trust-based BlockchainAuthorization for IoT[J].2021.
[0103] [3] A.Dorri, SSS Kanhere, R.Jurdak, and P.Gauravaram, "Blockchain for IoTsecurity and privacy: The case study of a smart home," in 2017IEEE Intemational Conference on Pervasive Computing and Communications Workshops (PerComWorkshops), 2017, pp.618-623.
[0104] [4] D.Han, H.Kim, and J.Jang, "Blockchain based smart doorlock system," in 2017International Conference on Information and Communication Technology Convergence (ICTC), 2017, pp.1165-1167.
[0105] [5] Lin C, He D, Kumar N, et al. HomeChain: A Blockchain-Based SecureMutual Authentication System for Smart Homes[J]. IEEE Internet of ThingsJournal, 2020, 7(2): 818-829.
[0106] [6]Dang T L N,Nguyen M S.An Approach to Data Privacy in Smart Homeusing Blockchain Technology[C] / / 2018International Conference on AdvancedComputing and Applications(ACOMP).2018.
[0107] [7]Jeong D H,Kim J,Hwang M,et al.Analytics Service Assessment andComparison Using Information Service Quality Evaluation Model[J].International Journal of Information Processing&Management,2013,4(4):32-43.
[0108] [8]Xu R,Chen Y,Blasch E,et al.A Federated Capability-based AccessControl Mechanism for Intemet of Things(IoTs)[C] / / Spie Defense&CommercialSensing.2018.
Claims
1. A smart home security access control method, characterized in that: The following steps are involved: The subject sends an access request to the access control contract, and the access control contract determines whether the access request sent by the subject is a normal access request. If so, the access result is saved in the Hyperledger Structure ledger, and the subject sends a connection request to the object; the access control contract verifies the subject's identity token and matches the authority calculated by the subject through the trust capability token with the requested authority in the access request sent by the subject to determine whether the access request sent by the subject is a normal access request; The object calls the access control contract to query the access result and makes an access decision based on the access result; The credit management center updates the trust capability tokens of the subject and object; The specific implementation process of the credit management center updating the trust capability token of the subject and object includes: Calculate the time point t using the following formula id The subject's behavioral reputation in, Indicates time point t id The device id, N(t i ) is the weight function of the subject’s normal access behavior, t i ∈[t id -T,ti d] ; M(t j ) is the weight function of the subject’s abnormal access behavior, t j ∈[t id -T, t id ]; t i is the time point when the subject sends an access request and the access request is approved; t j is the time point when the subject sends an access request and the access request is not approved; T is the time period; θ is set to n and m are the total number of normal access behaviors and the total number of abnormal access behaviors of the subject in the time period T, respectively; The trust attribute value of the object is calculated using the following formula: in, ν is the total number of evaluation results for the object; K is the trust level; tr(D id , S id ) is the evaluation result of the subject on the service provided by the object; TR id is the credit value of the subject; The trust management center calls the trust contract to update the trust value of the device, namely the behavior reputation value and trust attribute value.
2. The smart home security access control method according to claim 1, characterized in that: The specific implementation process of the access control contract to determine whether the access request sent by the subject is a normal access request includes: The access control contract calls the trust contract to record the subject's access status. If the subject's access request is approved, it is considered a normal access request; otherwise, it is considered an abnormal access request.
3. The smart home security access control method according to claim 2, characterized in that: The specific implementation process of the access control contract calling the trust contract to record the access status of the subject includes: Check the device identity token in the access request. If the identity token is incorrect, the subject's access behavior is recorded as abnormal access behavior. Determine whether the requested permissions in the subject's access request match the permissions that the subject can have. If they do not match, the subject's access behavior is recorded as abnormal access behavior; the calculation formula for the permissions P that the subject can have is: P is permission, TR id The credit value of the subject; The access control contract calculates the time the object provides services to the subject, and the calculation formula is: is the credit value of the subject at the current time point t, is the credit value of the object at the current time point t; Represents the subject id at time point t; Represents the object id at time point t; The access control contract encrypts the device ID and access time into a virtual ID, and the access result is stored in the Hyperledger Fabric ledger; the access result includes the device ID, the service provided by the object, and the time when the object provides the service to the subject.
4. The smart home security access control method according to claim 2, characterized in that: The identity token is obtained by calling the identity contract registration by the home management center in the smart home system, and the identity contract, trust contract and access control contract are installed in the Hyperledger Fabric blockchain network.
5. The smart home security access control method according to claim 4, characterized in that: K=0.5。 6. A computer device comprising a memory, a processor and a computer program stored in the memory; characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 5.
7. A computer program product comprising a computer program / instructions; characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium having a computer program / instruction stored thereon; characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.