Blockchain-based Permission Control Method, System, Device, and Readable Storage Medium
By generating and parsing the extended attribute information in the target certificate, and using blockchain smart contracts to determine user permissions, the problem of insufficient granularity of permission control of the Hyperledger Fabric privacy protection mechanism is solved, and more refined permission management is achieved.
Patent Information
- Application Number
- CN202210815478.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-08
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-07-08
AI Technical Summary
The privacy protection mechanism of the hyper ledger Fabric has low granularity and is difficult to meet business scenarios with relatively detailed permission control requirements in actual applications.
By generating the target certificate, the extended attribute information in the target certificate is parsed, including user type and user permissions, the blockchain smart contract analyzes this information to determine the scope of the target user's permissions, and determines the permissions for their on-chain requests based on the scope of permissions.
It improves the accuracy of permission control, solves the problem of low granularity and fineness of permission control of the hyper ledger privacy protection mechanism, and realizes more refined permission management.
Smart Images

Figure CN115348027B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of blockchain, and in particular to a permission control method, system, device and readable storage medium based on blockchain. Background Art
[0002] The current mainstream open-source consortium blockchain Hyperledger Fabric adopts a permissioned access mechanism, which provides relatively rich security and privacy protection mechanisms by itself, including consortium-level system isolation, ledger-level data isolation, policy-level application isolation, and contract-level operation isolation. However, finer-grained privacy isolation, such as fine-grained permission control of contract asset data, is not supported, and it is difficult to meet the business scenarios with relatively detailed permission control requirements in actual applications, which is not conducive to the popularization of Hyperledger Fabric in the actual enterprise production environment.
[0003] Therefore, how to solve the low fine-grained degree of permission control in the current privacy protection mechanism of Hyperledger has become an urgent technical problem to be solved. Summary of the Invention
[0004] The main purpose of the present invention is to provide a permission control method, system, device and readable storage medium based on blockchain, aiming to solve the technical problem of the low fine-grained degree of permission control in the current privacy protection mechanism of Hyperledger.
[0005] To achieve the above object, the present invention provides a permission control method based on blockchain. The permission control method based on blockchain includes: generating a target certificate based on a digital certificate application instruction sent by a target user; parsing and invoking the target certificate through a blockchain smart contract to obtain extended attribute information in the target certificate; wherein the extended attribute information includes user type and user permission; determining the permission range of the target user based on the analysis result of the extended attribute information by the blockchain smart contract, and determining the permission corresponding to the on-chain request of the target user based on the permission range.
[0006] Further, generating a target certificate based on a digital certificate application instruction sent by a target user includes:
[0007] Sending a digital certificate application to a digital identity service based on the identity information and extended attribute information of the target user included in the digital certificate application instruction;
[0008] Verifying the digital certificate application information by the digital identity service, and querying a CA service matching the digital certificate application, and generating the target certificate through the CA service.
[0009] Further, based on the analysis result of the extended attribute information by the blockchain smart contract, determining the permission scope of the target user, and based on the permission scope, determining the permission corresponding to the on-chain request of the target user, includes:
[0010] Analyzing the extended attribute information of the target certificate through the blockchain smart contract to determine the permission scope of the target user;
[0011] Based on the on-chain request of the target user and the permission scope, calling the common permission processing lib to query the permission corresponding to the on-chain request, and determining whether the target user has the permission corresponding to the on-chain request.
[0012] Further, based on the on-chain request of the target user and the permission scope, calling the common permission processing lib to query the permission corresponding to the on-chain request, and determining whether the target user has the permission corresponding to the on-chain request, includes:
[0013] If the permission corresponding to the on-chain request is within the permission scope, responding to the on-chain request and outputting the response result to the target user;
[0014] If the permission corresponding to the on-chain request is not within the permission scope, feedbacking an error reminder to the target user to prompt that the target user does not have the corresponding permission.
[0015] In addition, to achieve the above object, the present invention also provides a blockchain-based permission control system. The blockchain-based permission control system includes a CA service, a smart contract gateway service, a digital identity service, and a blockchain service; the CA service is used to generate a target certificate based on a digital certificate application instruction sent by a target user;
[0016] The smart contract gateway service is used for the unified allocation of blockchain smart contract calls;
[0017] The digital identity service is used to receive a digital certificate application instruction sent by a target user, and query and match the CA service according to the digital certificate application instruction to realize the management of digital identity certificates. The management of the digital identity certificates includes: the issuance, verification, and revocation of digital certificates;
[0018] The blockchain service is used to execute smart contracts; used to parse and call the target certificate through the blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the extended attribute information includes user type and user permission; based on the analysis result of the extended attribute information, determining the permission scope of the target user, and based on the permission scope, determining the permission corresponding to the on-chain request of the target user to realize the control of contract asset permissions.
[0019] Further, the blockchain service includes a blockchain node service:
[0020] The blockchain node service is used to execute the smart contract of the corresponding blockchain node; one blockchain node service corresponds to one CA service, and is used to generate the digital identity certificate of the blockchain node;
[0021] The blockchain nodes are communicatively connected through a blockchain virtual network to realize information transmission between the blockchain nodes.
[0022] Further, the digital identity service includes:
[0023] A digital certificate application module, which is used to verify the digital certificate application information through the digital identity service, query the CA service matching the digital certificate application, and generate the target certificate through the CA service.
[0024] Further, the digital identity service further includes:
[0025] A user permission range determination module, which is used to analyze the extended attribute information of the target certificate through a blockchain smart contract to determine the permission range of the target user;
[0026] A requested permission judgment module, which is used to call the permission processing common lib based on the on-chain request of the target user and the permission range, query the permission corresponding to the on-chain request, and judge whether the target user has the permission corresponding to the on-chain request.
[0027] In addition, to achieve the above object, the present invention further provides a blockchain-based permission control device, which includes a processor, a memory, and a blockchain-based permission control program stored on the memory and executable by the processor. When the blockchain-based permission control program is executed by the processor, the steps of the above-mentioned blockchain-based permission control method are implemented.
[0028] In addition, to achieve the above object, the present invention further provides a computer-readable storage medium, on which a blockchain-based permission control program is stored. When the blockchain-based permission control program is executed by a processor, the steps of the above-mentioned blockchain-based permission control method are implemented.
[0029] The present invention provides a permission control method based on blockchain. The method generates a target certificate based on a digital certificate application instruction sent by a target user; parses and invokes the target certificate through a blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the user type and user permissions; based on the analysis result of the extended attribute information by the blockchain smart contract, determine the target permission of the target user. In the above manner, according to the digital certificate application instruction sent by the target user, a target certificate is generated, and the target certificate is parsed through a blockchain smart contract, so as to obtain the extended attribute information in the target certificate; the extended attribute information includes the user type and user permissions of the target user, and the blockchain smart contract can learn about the permission range of the target user for the contract asset data by parsing the extended attribute information, so that the permission of the target user can be controlled according to this permission range, improving the accuracy of permission control and solving the technical problem of low accuracy of permission control in the privacy protection mechanism of Hyperledger. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a schematic diagram of the hardware structure of a permission control device based on blockchain involved in the solution of an embodiment of the present invention;
[0031] Figure 2 It is a schematic flowchart of the first embodiment of the permission control method based on blockchain of the present invention;
[0032] Figure 3 It is a schematic flowchart of the second embodiment of the permission control method based on blockchain of the present invention;
[0033] Figure 4 It is a schematic flowchart of the third embodiment of the permission control method based on blockchain of the present invention;
[0034] Figure 5 It is a schematic diagram of the structure of the first embodiment of the permission control system based on blockchain of the present invention;
[0035] Figure 6 It is a schematic diagram of the structure of the second embodiment of the permission control system based on blockchain of the present invention.
[0036] The implementation, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0038] The permission control method based on blockchain involved in the embodiments of the present invention is mainly applied to a permission control device based on blockchain, and the permission control device based on blockchain can be a device with display and processing functions such as a PC, a portable computer, a mobile terminal, etc.
[0039] Refer to Figure 1 , Figure 1 which is a schematic diagram of the hardware structure of the permission control device based on blockchain involved in the solution of the embodiments of the present invention. In the embodiments of the present invention, the permission control device based on blockchain may include a processor 1001 (such as a CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components; the user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard); the network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface); the memory 1005 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory, and the memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.
[0040] Those skilled in the art can understand that Figure 1 the hardware structure shown in
[0041] does not constitute a limitation on the permission control device based on blockchain, and may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements. Figure 1 , Figure 1 In
[0042] the memory 1005, as a computer-readable storage medium, may include an operating system, a network communication module, and a permission control program based on blockchain. Figure 1 In
[0043] the network communication module is mainly used to connect to the server and communicate with the server for data; while the processor 1001 can call the permission control program stored in the memory 1005 and execute the permission control method provided by the embodiments of the present invention.
[0044] Refer to Figure 2 , Figure 2 which is a schematic flowchart of the first embodiment of the permission control method based on blockchain of the present invention.
[0045] In this embodiment, the permission control method based on blockchain includes:
[0046] Step S10: Generate a target certificate based on the digital certificate application instruction sent by the target user.
[0047] In this embodiment, the identity information of the target user and the X.509 extension attribute information are entered into the decentralized application (DAPP), and a digital identity application is submitted to the digital identity service. The DAPP generates a target certificate corresponding to the permissions of the target user according to the digital certificate application instruction sent by the target user.
[0048] Step S20: Parse and call the target certificate through the blockchain smart contract to obtain the extension attribute information in the target certificate; wherein, the extension attribute information includes the user type and user permissions.
[0049] In this embodiment, after pre-chain processing by the DAPP, the blockchain smart contract is called through the smart contract gateway service, and the X.509 extension attribute information of the target user is parsed and called through the blockchain smart contract to obtain the certificate extension attribute auths.
[0050] Among them, pre-chain processing means that the business data needs to be processed and the information needs to be signed before being uploaded to the chain, that is, a digital certificate is generated. These processes can be completed through corresponding tools, such as serialization tools and signature tools for various elliptic curves, or through an SDK integrating various tools.
[0051] Specifically, the X.509 extension attribute information includes: user type (type) and user permissions (auths).
[0052] In a specific embodiment, examples of the user permissions (auths) of the X.509 extension attribute information are as follows:
[0053]
[0054]
[0055] Specifically, the user type (type) is the user type of the user in the blockchain platform, including: organizational administrator, enterprise administrator, enterprise user, etc.; the user permissions (auths) are the permissions of the user in the blockchain platform for various asset data, stored in the form of a json array, including permission object (target), asset data row permission (rowauth), and asset data column permission (colauths).
[0056] Specifically, the permission object (target) is a string, which is the object in the contract asset that requires permission control, including asset identification sub, asset certain attribute identification sub, etc.
[0057] Specifically, the asset data row permission (rowauth) is a JSON object that contains the identification sub-ids and the permission mode. Here, ids is a comma-separated string (e.g., ids = "1001, 1003, 1004"), and mode is the permission for this data, stored in the form of Linux file permissions, namely read (r / 4), write (w / 2), and reserved (x / 1) (e.g., full rwx permission: mode = 7, read-only r permission: mode = 4, no permission: mode = 0).
[0058] Specifically, the asset data column permissions (colauths) is an array of JSON objects that contains the permission information for the asset-related attributes, including two fields: item and mode. Here, item is the identifier of the specific attribute, and mode is the permission for this attribute.
[0059] In step S30, based on the analysis result of the extended attribute information by the blockchain smart contract, determine the permission range of the target user, and based on the permission range, determine the permission corresponding to the on-chain request of the target user.
[0060] In this embodiment, based on the extended attribute information auths (authorization) in the target certificate, according to the purpose of the user's on-chain processing, call the common permission processing lib to judge the user's permission and perform corresponding processing.
[0061] Among them, the common permission processing lib is a permission control process for the extended attributes of the X.509 digital certificate, provided in the form of a common lib for the business smart contract to call, and includes the following interfaces:
[0062] Function name: getRowAuth
[0063] Input parameters: Auth, id
[0064] Return result: mode
[0065] Processing flow: Serialize the parameter Auth, query the mode result corresponding to the parameter id from it and return. If no result is found, return 0 to indicate no permission.
[0066] Function name: getColAuth
[0067] Input parameters: Auth, item
[0068] Return result: mode
[0069] Processing flow: Serialize the parameter Auth, query the mode result corresponding to the parameter item from it and return. If no result is found, return 0 to indicate no permission.
[0070] In this embodiment, a blockchain-based permission control method is provided. Based on a digital certificate application instruction sent by a target user, a target certificate is generated; the target certificate is parsed and called through a blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the user type and user permissions; based on the analysis result of the extended attribute information by the blockchain smart contract, the target permission of the target user is determined. In the above manner, according to the digital certificate application instruction sent by the target user, a target certificate is generated, and the target certificate is parsed through a blockchain smart contract, so as to obtain the extended attribute information in the target certificate; the extended attribute information includes the user type and user permissions of the target user, and the blockchain smart contract can learn about the permission range of the target user for the contract asset data by parsing the extended attribute information, so as to be able to control the permissions of the target user according to this permission range, improve the accuracy of permission control, and solve the technical problem of low accuracy of permission control in the privacy protection mechanism of Hyperledger.
[0071] Refer to Figure 3 , Figure 3 It is a schematic flowchart of the second embodiment of the blockchain-based permission control method of the present invention.
[0072] Based on the above Figure 2 As shown, in this embodiment, the step S10 specifically includes:
[0073] Step S11, based on the identity information and extended attribute information of the target user included in the digital certificate application instruction, send a digital certificate application to the digital identity service;
[0074] Step S12, verify the digital certificate application information through the digital identity service, query the CA service matching the digital certificate application, and generate the target certificate through the CA service.
[0075] In this embodiment, each blockchain node corresponds to a CA service. When a target user submits a digital certificate application through a DAPP, the digital identity service verifies the relevant application information in the digital certificate application and queries the CA service matching the target user's application information; if there is a CA service that is exactly the same as the extended attribute in the digital certificate application, it means that the verification is passed, so as to generate the target certificate of the target user through the CA service, and call the CA service interface to obtain the target certificate, upload the target certificate to the blockchain, and then return to the DAPP.
[0076] Among them, the digital identity service manages the CA service information, the public key of the issuing account, the ID of the issuing account, and the special public and private keys of the digital identity certificate of all organizations.
[0077] Refer to Figure 4 , Figure 4Schematic flowchart of the third embodiment of the blockchain-based permission control method of the present invention.
[0078] Based on the above Figure 2 As shown, in this embodiment, step S30 specifically includes:
[0079] Step S31: Analyze the extended attribute information of the target certificate through a blockchain smart contract to determine the permission scope of the target user;
[0080] Step S32: Based on the on-chain request of the target user and the permission scope, call the permission processing common library to query the permission corresponding to the on-chain request, and determine whether the target user has the permission corresponding to the on-chain request.
[0081] Further, step S32 specifically includes:
[0082] If the permission corresponding to the on-chain request is within the permission scope, respond to the on-chain request and output the response result to the target user;
[0083] If the permission corresponding to the on-chain request is not within the permission scope, feedback an error reminder to the target user to prompt that the target user does not have the corresponding permission.
[0084] In this embodiment, the extended attribute information in the target certificate is parsed through a blockchain smart contract to obtain the user type and user permissions of the target user, that is, the permission scope of the target user; then, according to the on-chain request of the target user, the permission of the target user's on-chain request is verified to determine whether the target user has the permission corresponding to this request; if the target user has the permission corresponding to this request, it passes the verification, responds to this request, and outputs the processing result corresponding to this on-chain request. If the target user does not have the permission corresponding to this on-chain request, an error is feedback to remind the target user that it does not have the corresponding permission for this request. For example, after the target user completes the user registration in the blockchain contract asset system and determines the user type and user permissions of the target user in this system, when the user makes a request to view a certain asset bill in this system, the system will verify the identity information of the target user, determine the user permissions of the target user, and at the same time, the system will verify the user permissions of the target user according to the query permission requirements of this asset bill to determine whether the target user has the query permission for this asset bill. If the user permissions of the target user can pass the verification, the asset bill will be feedback to the user for the user to view; otherwise, the target user will be refused to view this asset bill.
[0085] In addition, an embodiment of the present invention also provides a blockchain-based permission control system.
[0086] Refer toFigure 5 , Figure 5 This is a schematic structural diagram of the first embodiment of the blockchain-based permission control system of the present invention.
[0087] In this embodiment, the blockchain-based permission control system includes: a CA service, a smart contract gateway service, a digital identity service, and a blockchain service;
[0088] The CA service is used to generate a target certificate based on a digital certificate application instruction sent by a target user;
[0089] The smart contract gateway service is used for the unified allocation of blockchain smart contract calls;
[0090] The digital identity service is used to receive a digital certificate application instruction sent by a target user, and query and match the CA service according to the digital certificate application instruction to implement the management of digital identity certificates. The management of the digital identity certificates includes: the issuance, verification, and revocation of digital certificates;
[0091] The blockchain service is used to execute smart contracts; used to parse and call the target certificate through a blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the extended attribute information includes user type and user permission; based on the analysis result of the extended attribute information, determine the permission range of the target user, and based on the permission range, determine the permission corresponding to the on-chain request of the target user to implement the control of contract asset permissions.
[0092] Furthermore, the blockchain service includes a blockchain node service:
[0093] The blockchain node service is used to execute the smart contract of the corresponding blockchain node; one blockchain node service corresponds to one CA service, and is used to generate the digital identity certificate of the blockchain node;
[0094] The blockchain nodes are communicatively connected through a blockchain virtual network to realize information transmission between the blockchain nodes.
[0095] Furthermore, the digital identity service specifically includes:
[0096] A digital certificate application module, which is used to verify the digital certificate application information through the digital identity service, query the CA service that matches the digital certificate application, and generate the target certificate through the CA service.
[0097] Furthermore, the digital identity service specifically further includes:
[0098] A user permission scope determination module, which is used to analyze the extended attribute information of the target certificate through a blockchain smart contract to determine the permission scope of the target user;
[0099] A request permission judgment module, which is used to call a common permission processing lib based on the on-chain request of the target user and the permission scope, query the permission corresponding to the on-chain request, and judge whether the target user has the permission corresponding to the on-chain request.
[0100] Further, the smart contract gateway service specifically includes:
[0101] A permission scope determination unit, which is used to analyze the extended attribute information of the target certificate through a blockchain smart contract to determine the permission scope of the target user;
[0102] An on-chain request permission query unit, which is used to call a common permission processing lib based on the on-chain request of the target user and the permission scope, query the permission corresponding to the on-chain request, and judge whether the target user has the permission corresponding to the on-chain request.
[0103] Further, the on-chain request permission query unit specifically includes:
[0104] A permission response subunit, which is used to respond to the on-chain request and output the response result to the target user if the permission corresponding to the on-chain request is within the permission scope;
[0105] A permission rejection subunit, which is used to feedback an error reminder to the target user to prompt that the target user does not have the corresponding permission if the permission corresponding to the on-chain request is not within the permission scope.
[0106] In this embodiment, the user enters identity information and X.509 extended attribute information in the business system, and then sends a digital identity certificate application to the digital identity service; the digital identity service is used for identity frame management, verifies the digital identity certificate application, determines the digital identity certificate corresponding to the digital identity certificate application by querying the CA service system, generates the user's digital identity certificate, and feeds it back to the business system through the digital identity service; after obtaining the digital identity certificate, through blockchain operations, an on-chain request is sent, the smart contract gateway service calls the blockchain system to execute the smart contract, parses the user's digital identity certificate, discriminates the user's permissions, and feeds back the on-chain request, thereby completing the control of the contract asset permissions.
[0107] Refer to Figure 6 , Figure 6 This is the structural schematic diagram of the second embodiment of the permission control system based on blockchain of the present invention.
[0108] Based on the above Figure 5 As shown, this embodiment demonstrates a deployment method of a permission control system based on blockchain. The system includes three different organization servers, a trusted third-party server, and a blockchain virtual network.
[0109] Blockchain node services and their respective CA services are deployed in all three organization servers; a digital identity service and a smart contract gateway service are deployed inside the trusted third-party server; the blockchain virtual network is used for communication between the blockchain systems of all three organizations. By opening fixed ports in the firewall of each organization, the nodes of the blockchain virtual network are allowed to access each other.
[0110] In this embodiment, communication between blockchain nodes is achieved through the blockchain virtual network. One blockchain node corresponds to one CA service. The blockchain node is used to execute smart contracts; the CA service is used to generate digital certificates corresponding to the blockchain nodes; the smart contract gateway service is used to call the blockchain nodes to execute smart contracts; and the digital identity service is used to manage the CA service information, the public keys of the certificate-issuing accounts, the certificate-issuing account IDs, and the special public and private keys of the digital identity credentials of all organizations.
[0111] In addition, an embodiment of the present invention also provides a computer-readable storage medium.
[0112] A permission control program based on blockchain is stored on the computer-readable storage medium of the present invention. When the permission control program based on blockchain is executed by a processor, the steps of the permission control method based on blockchain as described above are implemented.
[0113] Among them, the method implemented when the permission control program based on blockchain is executed can refer to the various embodiments of the permission control method based on blockchain of the present invention, which will not be elaborated here.
[0114] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or system including that element.
[0115] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0116] This application can be used in numerous general or specific computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0117] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0118] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A blockchain-based permission control method, characterized in that, The blockchain-based permission control method includes the following steps: Generate a target certificate based on a digital certificate application instruction sent by a target user; Parse and call the target certificate through a blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the extended attribute information includes user type and user permissions, and the user permissions are the permissions of the user for various asset data in the blockchain platform, stored in the form of a json array, including permission objects, asset data row permissions, and asset data column permissions; Based on the analysis result of the extended attribute information by the blockchain smart contract, determine the permission range of the target user, and based on the permission range, determine the permission corresponding to the target user's on-chain request.
2. The blockchain-based permission control method according to claim 1, wherein The generating of the target certificate based on the digital certificate application instruction sent by the target user includes: Send a digital certificate application to the digital identity service based on the identity information and extended attribute information of the target user included in the digital certificate application instruction; Verify the digital certificate application information through the digital identity service, query the CA service that matches the digital certificate application, and generate the target certificate through the CA service.
3. The blockchain-based permission control method according to claim 1, wherein The determining of the permission range of the target user based on the analysis result of the extended attribute information by the blockchain smart contract and the determining of the permission corresponding to the target user's on-chain request based on the permission range include: Analyze the extended attribute information of the target certificate through the blockchain smart contract to determine the permission range of the target user; Based on the on-chain request of the target user and the permission range, call the permission processing common lib, query the permission corresponding to the on-chain request, and determine whether the target user has the permission corresponding to the on-chain request.
4. The blockchain-based permission control method according to claim 3, wherein The calling of the permission processing common lib based on the on-chain request of the target user and the permission range, querying the permission corresponding to the on-chain request, and determining whether the target user has the permission corresponding to the on-chain request includes: If the permission corresponding to the on-chain request is within the permission range, respond to the on-chain request and output the response result to the target user; If the permission corresponding to the on-chain request is not within the permission range, feedback an error reminder to the target user to prompt that the target user does not have the corresponding permission.
5. A blockchain-based permission control system, characterized in that, The system includes a CA service, a smart contract gateway service, a digital identity service, and a blockchain service; The CA service is used to generate a target certificate based on a digital certificate application instruction sent by a target user; The smart contract gateway service is used for the unified allocation of blockchain smart contract calls; The digital identity service is used to receive a digital certificate application instruction sent by a target user, query and match the CA service according to the digital certificate application instruction to implement the management of digital identity certificates, and the management of digital identity certificates includes: issuance, verification, and revocation of digital certificates; The blockchain service is used to execute smart contracts; to parse and call the target certificate through the blockchain smart contract to obtain the extended attribute information in the target certificate; wherein, the extended attribute information includes user type and user permissions; wherein, the user permissions are the permissions of the user for various asset data in the blockchain platform, stored in the form of a json array, including permission objects, asset data row permissions, and asset data column permissions; Based on the analysis result of the extended attribute information, determine the permission range of the target user, and based on the permission range, determine the permission corresponding to the on-chain request of the target user to implement the control of contract asset permissions.
6. The blockchain-based permission control system according to claim 5, wherein The blockchain service includes a blockchain node service: The blockchain node service is used to execute the smart contract of the corresponding blockchain node; one blockchain node service corresponds to one CA service, which is used to generate the digital identity certificate of the blockchain node; The blockchain nodes are communicatively connected through a blockchain virtual network to realize the information transmission between the blockchain nodes.
7. The blockchain-based permission control system according to claim 5, wherein The digital identity service includes: A digital certificate application module, which is used to verify the digital certificate application information through the digital identity service, query the CA service matching the digital certificate application, and generate the target certificate through the CA service.
8. The blockchain-based permission control system according to claim 5, wherein The digital identity service further includes: A user permission range determination module, which is used to analyze the extended attribute information of the target certificate through the blockchain smart contract to determine the permission range of the target user; A request permission judgment module, which is used to call the permission processing common lib based on the on-chain request of the target user and the permission range, query the permission corresponding to the on-chain request, and judge whether the target user has the permission corresponding to the on-chain request.
9. A blockchain-based permission control device, characterized in that, The blockchain-based permission control device includes a processor, a memory, and a blockchain-based permission control program stored on the memory and executable by the processor. When the blockchain-based permission control program is executed by the processor, the steps of the blockchain-based permission control method according to any one of claims 1 to 4 are implemented.
10. A computer-readable storage medium, characterized in that, A blockchain-based permission control program is stored on the computer-readable storage medium. When the blockchain-based permission control program is executed by a processor, the steps of the blockchain-based permission control method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Fusion and authentication method and system of identity and authority in industrial control system
CN102420690A
High-security-level access control method and system based on block chain
CN113722722A