Blockchain Access Control Method Based on Centralized Strategy

Through the central server terminal, the data access request of the user terminal is analyzed and permission control is generated, and a limited-time data packet is generated, which solves the data tampering security risks caused by the user terminal obtaining global access rights in the prior art, and realizes that the user terminal can only browse data without affecting blockchain data security.

CN115396145BActive Publication Date: 2025-06-24HUIZHIAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210861119.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-20
Publication Date
2025-06-24
Estimated Expiration
2042-07-20

AI Technical Summary

Technical Problem

The existing blockchain access management method based on centralized strategies poses a security risk of data tampering because user terminals gain global access to the blockchain.

Method used

The data access request from the user terminal is analyzed through the central server terminal, the blockchain network nodes and access sequences are determined to be accessed, and the access action life cycle is set based on the historical access information of the user terminal. After analyzing the access record, a copy of the target data block and its time-limited data packet are generated, and only the time-limited data packet is sent to the user terminal.

Benefits of technology

It realizes fine control of the data access rights of the user terminal, so that it can only browse data without adversely affecting the data security of the blockchain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396145B_ABST
    Figure CN115396145B_ABST
Patent Text Reader

Abstract

The present invention provides a blockchain access control method based on a centralized policy. It analyzes the data access requests of user terminals through a central server terminal, thereby granting user terminals the permission to access specific blockchain network nodes for data, enabling user terminals to only browse data, and using the central server terminal to copy and send data, ensuring that while user terminals obtain corresponding data copies, it will not have any adverse effects on the data security of the blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain data management, and in particular to a blockchain access control method based on a centralized strategy. Background Art

[0002] As a data storage technology, blockchain can provide secure, stable and confidential data storage. At present, blockchain usually manages data access based on a centralized strategy, that is, by setting up a central service terminal to centrally manage all user terminals. When a user terminal initiates a data access request to the blockchain, after the central service terminal authenticates the data access request, the user terminal is granted access to the entire blockchain, allowing the user terminal to directly read and copy data on the blockchain. However, the above method opens the access rights of the entire blockchain to the user terminal, resulting in the user terminal having the opportunity to edit the data on the blockchain, which may cause the blockchain to have a security risk of data tampering. Summary of the invention

[0003] In view of the defects of the prior art, the present invention provides a blockchain access control method based on a centralized strategy, which analyzes the data access request from the user terminal through the central server terminal to obtain the blockchain network node that is expected to be accessed and the access order of the user terminal thereto; and according to the historical access information of the user terminal to the blockchain, sets the access action life cycle of the blockchain network node to the user terminal; then analyzes the access record of the user terminal to the data block of the blockchain network node within the access action life cycle, determines the target data block from which the user terminal needs to obtain data, and generates a data copy of the target data block and its time-limited data packet through the central server terminal, thereby sending the time-limited data packet to the user terminal; the above method analyzes the data access request of the user terminal through the central server terminal, thereby granting the user terminal the right to access data to a specific blockchain network node, so that the user terminal can only browse the data, and uses the central server terminal to copy and send the data, ensuring that the user terminal obtains the corresponding data copy while not having any adverse impact on the data security of the blockchain.

[0004] The present invention provides a blockchain access control method based on a centralized strategy, which comprises the following steps:

[0005] Step S1, obtaining a data access request from a user terminal through a central server terminal, and analyzing and processing the data access request to obtain a blockchain network node that the user terminal expects to access; and determining the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node;

[0006] Step S2: Based on the historical access information of the user terminal to the blockchain by the central server terminal, determine the access duration of the user terminal to the blockchain network node; after the user terminal is assigned the access permission to the blockchain network node, set the access action lifecycle of the user terminal to the blockchain network node according to the access duration by the central server terminal.

[0007] Step S3: Obtain the access records of the user terminal to the data blocks of the blockchain network node within the access action lifecycle; analyze and process the access records to determine the target data block from which the user terminal needs to obtain data.

[0008] Step S4: Generate a data copy of the target data block by the central server terminal, generate a time-limited data packet for the data copy, and then send the time-limited data packet to the user terminal.

[0009] Furthermore, in the step S1, obtaining a data access request from the user terminal by the central server terminal and analyzing and processing the data access request to obtain the specific blockchain network node that the user terminal expects to access specifically includes:

[0010] When the central server terminal receives a data access request from the user terminal, identify the terminal identity information of the user terminal from the data access request; and determine whether the terminal identity information matches the preset terminal identity information white list. If so, determine that the data access request is a legal data access request; if not, determine that the data access request is an illegal data access request.

[0011] When the data access request is a legal data access request, analyze and process the data access request to determine the data content and creation time of the data that the user terminal expects to access; and determine the blockchain network node where the data expected to be accessed is located in the blockchain according to the data content and creation time.

[0012] When the data access request is an illegal data access request, terminate the current data access process of the user terminal by the central server.

[0013] Furthermore, in the step S1, determining the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node specifically includes:

[0014] Obtain whether there is a legal data access request from other user terminals to the blockchain network node currently. If not, set the current user terminal to have the first access order to the blockchain network node.

[0015] If it exists, determine the access order of the current user terminal to the blockchain network node according to the preset terminal levels between the current user terminal and all other user terminals; wherein, the preset terminal level refers to the high and low levels of access permissions of all user terminals to the blockchain set in advance.

[0016] Further, in the step S2, the specific process of determining the access duration of the user terminal to the blockchain network node by the central server terminal according to the historical access information of the user terminal to the blockchain includes:

[0017] Obtain the historical access log information of the user terminal to the blockchain by the central server terminal according to the terminal identity information of the user terminal;

[0018] Analyze and process the historical access log information to determine the total historical access times and the total historical access duration of the user terminal to the blockchain network node;

[0019] Determine the average access duration of the user terminal to the blockchain network node according to the total historical access times and the total historical access duration.

[0020] Further, in the step S2, after the user terminal is assigned the access permission to the blockchain network node, the specific process of setting the access action life cycle of the user terminal to the blockchain network node by the central server terminal according to the access duration includes:

[0021] When the central server terminal determines that the user terminal has the first access order to the blockchain network node, assign the access permission of the blockchain network node to the user terminal;

[0022] And set the access action life cycle of the user terminal to the blockchain network node by the central server terminal, wherein the access action life cycle is not greater than the average access duration.

[0023] Further, in the step S3, the specific process of obtaining the access records of the user terminal to the data blocks of the blockchain network node during the access action life cycle includes:

[0024] Obtain the data browsing duration of each data block of the blockchain network node by the user terminal during the access action life cycle.

[0025] Further, in the step S3, the specific process of analyzing and processing the access records to determine the target data block from which the user terminal needs to obtain data includes:

[0026] If the data browsing duration corresponding to a certain data block is greater than or equal to a preset time threshold, it is determined that the data block is the target data block from which the user terminal needs to obtain data.

[0027] Further, in the step S4, generating a data copy of the target data block by the central server terminal, generating a time-limited data packet for the data copy, and then sending the time-limited data packet to the user terminal specifically includes:

[0028] Generating a data copy of all the stored data in the target data block by the central server terminal, packing and compressing the data copy to form a time-limited data packet with a certain life cycle, and then sending the time-limited data packet to the user terminal;

[0029] If the continuous retention time of the time-limited data packet in the user terminal is greater than the life cycle, it triggers the time-limited data packet to be automatically destroyed.

[0030] Compared with the prior art, the blockchain access control method based on the centralized strategy analyzes the data access requests from the user terminal through the central server terminal to obtain the expected blockchain network nodes to be accessed and the access order of the user terminal to them; and sets the access action life cycle for the user terminal to the blockchain network nodes according to the historical access information of the user terminal to the blockchain; then analyzes the access records of the user terminal to the data blocks of the blockchain network nodes during the access action life cycle to determine the target data block from which the user terminal needs to obtain data, and thus generates a data copy of the target data block and its time-limited data packet through the central server terminal, and then sends the time-limited data packet to the user terminal; the above method analyzes the data access requests of the user terminal through the central server terminal, thereby granting the user terminal the permission to access data to specific blockchain network nodes, enabling the user terminal to only browse data, and using the central server terminal to copy and send data, ensuring that the user terminal obtains the corresponding data copy without having any adverse impact on the data security of the blockchain.

[0031] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings.

[0032] The technical solutions of the present invention will be further described in detail below with reference to the drawings and embodiments. Description of the Drawings

[0033] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0034] Figure 1 It is a schematic flowchart of the blockchain access control method based on a centralized policy provided by the present invention. Specific embodiments

[0035] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0036] Refer to Figure 1 , which is a schematic flowchart of the blockchain access control method based on a centralized policy provided by the embodiments of the present invention. The blockchain access control method based on a centralized policy includes the following steps:

[0037] Step S1, obtain a data access request from a user terminal through a central server terminal, analyze and process the data access request to obtain the blockchain network node that the user terminal expects to access; determine the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node;

[0038] Step S2, determine the access duration of the user terminal to the blockchain network node through the central server terminal according to the historical access information of the user terminal to the blockchain; after the user terminal is assigned the access permission to the blockchain network node, set the access action life cycle of the user terminal to the blockchain network node through the central server terminal according to the access duration;

[0039] Step S3, obtain the access record of the user terminal to the data block of the blockchain network node during the access action life cycle; analyze and process the access record to determine the target data block from which the user terminal needs to obtain data;

[0040] Step S4, generate a data copy of the target data block through the central server terminal, generate a time-limited data packet for the data copy, and then send the time-limited data packet to the user terminal.

[0041] The beneficial effects of the above technical solution are as follows: The blockchain access control method based on the centralized policy analyzes the data access requests from the user terminal through the central server terminal to obtain the blockchain network nodes expected to be accessed by the user terminal and the access order of the user terminal to them; and according to the historical access information of the user terminal to the blockchain, sets the access action life cycle of the user terminal to the blockchain network nodes; then analyzes the access records of the user terminal to the data blocks of the blockchain network nodes within the access action life cycle to determine the target data blocks from which the user terminal needs to obtain data, and thus generates a data copy of the target data block and its time-limited data packet through the central server terminal, and then sends the time-limited data packet to the user terminal; the above method analyzes the data access requests of the user terminal through the central server terminal, thereby granting the user terminal the permission to access data on specific blockchain network nodes, enabling the user terminal to only browse data, and using the central server terminal to copy and send data, ensuring that the user terminal obtains the corresponding data copy without having any adverse impact on the data security of the blockchain.

[0042] Preferably, in step S1, obtaining the data access request from the user terminal through the central server terminal and analyzing and processing the data access request to obtain the blockchain network nodes expected to be accessed by the user terminal specifically includes:

[0043] When the central server terminal receives a data access request from the user terminal, the terminal identity information of the user terminal is identified from the data access request; and it is judged whether the terminal identity information matches the preset terminal identity information white list. If so, it is determined that the data access request is a legal data access request; if not, it is determined that the data access request is an illegal data access request;

[0044] When the data access request is a legal data access request, the data access request is analyzed and processed to determine the data content and creation time of the data expected to be accessed by the user terminal; and according to the data content and creation time, the blockchain network node where the data expected to be accessed is located is determined from the blockchain;

[0045] When the data access request is an illegal data access request, the current data access process of the user terminal is terminated through the central server.

[0046] The beneficial effects of the above technical solution are as follows: Through the above method, first, the data access request from the user terminal is identified and authenticated regarding the terminal identity information to determine whether the current data access request comes from a legitimate user terminal in the preset terminal identity information whitelist. This can prevent illegal user terminals from obtaining access to the blockchain, thereby improving the data security of the blockchain. In addition, the data content and creation time of the data that the user terminal expects to access are also extracted from the data access request from the user terminal. This can accurately locate the blockchain network node that the user terminal expects to access, thereby improving the data access efficiency of the user terminal to the blockchain and avoiding data access congestion.

[0047] Preferably, in this step S1, determining the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node specifically includes:

[0048] Obtain whether there is a legitimate data access request from other user terminals to the blockchain network node currently. If not, set the current user terminal to have the first access order to the blockchain network node;

[0049] If there is, determine the access order of the current user terminal to the blockchain network node according to the preset terminal levels between the current user terminal and all other user terminals; wherein, the preset terminal level refers to the high and low levels of the access permissions of all user terminals to the blockchain set in advance.

[0050] The beneficial effects of the above technical solution are as follows: Through the above method, when multiple user terminals access the blockchain simultaneously, the data access order of each user terminal to the blockchain is arranged orderly, thereby preventing the data access channel of the blockchain from being overloaded due to multiple user terminals accessing data simultaneously.

[0051] Preferably, in this step S2, determining the access duration of the user terminal to the blockchain network node by the central server terminal according to the historical access information of the user terminal to the blockchain specifically includes:

[0052] Obtain the historical access log information of the user terminal to the blockchain by the central server terminal according to the terminal identity information of the user terminal;

[0053] Analyze and process the historical access log information to determine the total historical access times and the total historical access duration of the user terminal to the blockchain network node;

[0054] Determine the average access duration of the user terminal to the blockchain network node according to the total historical access times and the total historical access duration.

[0055] The beneficial effects of the above technical solution are as follows: In the above manner, based on the total historical access times and the total historical access durations of the user terminal to the blockchain network node, the average access duration of the user terminal to the blockchain network node is determined, so as to provide a suitable standard for the upper limit of the currently allowed access duration of the user terminal to the blockchain.

[0056] Preferably, in step S2, after the user terminal is assigned the access right to the blockchain network node, the central server terminal sets an access action life cycle for the user terminal to the blockchain network node according to the access duration, which specifically includes:

[0057] When the central server terminal determines that the user terminal has the first access order to the blockchain network node, the access right to the blockchain network node is assigned to the user terminal;

[0058] And the central server terminal sets an access action life cycle for the user terminal to the blockchain network node, where the access action life cycle is not greater than the average access duration.

[0059] The beneficial effects of the above technical solution are as follows: In the above manner, the access action life cycle set by the user terminal to the blockchain network node is set to be not greater than the above average access duration, so that while ensuring that the user terminal has sufficient time to access and browse the data of the blockchain network node, it can avoid the user terminal occupying a long time and compressing the normal access time of other user terminals to the blockchain.

[0060] Preferably, in step S3, obtaining the access records of the user terminal to the data blocks of the blockchain network node during the access action life cycle specifically includes:

[0061] Obtaining the data browsing duration of the user terminal to each data block of the blockchain network node during the access action life cycle.

[0062] The beneficial effects of the above technical solution are as follows: In the above manner, when the user terminal obtains the permission to access the corresponding blockchain network node, the user terminal can browse the data of the corresponding blockchain network node during the access action life cycle. The above browsing action is only limited to the user terminal to view and browse the data of the blockchain network node, and it cannot perform operations such as copying, cutting, and editing the data. And when the overall data browsing duration of the user terminal on the blockchain network node exceeds the access action life cycle, the user terminal will automatically lose the corresponding access right and be forced to exit the current blockchain network node.

[0063] Preferably, in step S3, analyzing and processing the access record to determine the specific target data block from which the user terminal needs to obtain data specifically includes:

[0064] If the data browsing duration corresponding to a certain data block is greater than or equal to a preset time threshold, then determine that this data block is the target data block from which the user terminal needs to obtain data.

[0065] The beneficial effect of the above technical solution is: By the above method, based on the data browsing duration corresponding to each data block of the user terminal, quantitatively judge whether the data block belongs to the target data block from which the user terminal needs to obtain data, which is convenient for accurately extracting the data information stored in the target data block subsequently.

[0066] Preferably, in step S4, generating a data copy of the target data block by the central server terminal, generating a time-limited data packet for the data copy, and then sending the time-limited data packet to the user terminal specifically includes:

[0067] Generating a data copy of all the stored data in the target data block by the central server terminal, packing and compressing the data copy to form a time-limited data packet with a certain life cycle, and then sending the time-limited data packet to the user terminal;

[0068] If the continuous retention time of the time-limited data packet in the user terminal is greater than the life cycle, trigger the automatic destruction of the time-limited data packet.

[0069] The beneficial effect of the above technical solution is: By the above method, generating a data copy of all the stored data in the target data block by the central server terminal and packing and compressing the data copy to form a time-limited data packet with a certain life cycle, so that only the central server terminal is allowed to read and copy the data of the blockchain, avoiding potential security risks to the blockchain data caused by the user terminal directly reading the blockchain data; in addition, if the continuous retention time of the time-limited data packet in the user terminal is greater than the life cycle, trigger the automatic destruction of the time-limited data packet, which can prevent the time-limited data packet from being illegally used by the user terminal.

[0070] As can be seen from the content of the above embodiments, the blockchain access control method based on the centralized policy analyzes the data access requests from the user terminals through the central server terminal to obtain the blockchain network nodes expected to be accessed and the access order of the user terminals thereto; and sets the access action life cycle for the user terminals to the blockchain network nodes according to the historical access information of the user terminals to the blockchain; then analyzes the access records of the user terminals to the data blocks of the blockchain network nodes during the access action life cycle to determine the target data blocks from which the user terminals need to obtain data, and thus generates data copies of the target data blocks and their time-limited data packets through the central server terminal, and sends the time-limited data packets to the user terminals; the above method analyzes the data access requests of the user terminals through the central server terminal, thereby granting the user terminals the permission to access data of specific blockchain network nodes, enabling the user terminals to only browse data, and using the central server terminal to perform data replication and sending, ensuring that the user terminals obtain the corresponding data copies without having any adverse impact on the data security of the blockchain.

[0071] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A blockchain access control method based on a centralized strategy, characterized in that It includes the following steps: Step S1: Obtain a data access request from a user terminal through a central server terminal, analyze and process the data access request to obtain a blockchain network node expected to be accessed by the user terminal; determine the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node; Step S2: Determine the access duration of the user terminal to the blockchain network node through the central server terminal according to the historical access information of the user terminal to the blockchain; After the user terminal is assigned the access permission to the blockchain network node, set an access action life cycle for the user terminal to the blockchain network node by the central server terminal according to the access duration; Step S3: Obtain the access record of the user terminal to the data block of the blockchain network node within the access action life cycle; analyze and process the access record to determine the target data block from which the user terminal needs to obtain data; wherein, when the user terminal obtains the permission to access the corresponding blockchain network node, the user terminal can browse the data of the corresponding blockchain network node within the access action life cycle, and the above browsing action is only limited to the user terminal to view and browse the data of the blockchain network node, and it cannot copy, cut, and edit the data; Step S4: Generate a data copy of the target data block through the central server terminal, generate a time-limited data packet for the data copy, and then send the time-limited data packet to the user terminal; Among them, in the step S4, generating a data copy of the target data block through the central server terminal, generating a time-limited data packet for the data copy, and then sending the time-limited data packet to the user terminal specifically includes: Generate a data copy of all the stored data in the target data block through the central server terminal, pack and compress the data copy to form a time-limited data packet with a certain life cycle, and then send the time-limited data packet to the user terminal; If the continuous retention time of the time-limited data packet in the user terminal is greater than the life cycle, trigger the automatic destruction of the time-limited data packet.

2. The blockchain access control method based on a centralized strategy according to claim 1, characterized in that: In the step S1, obtaining a data access request from a user terminal through a central server terminal and analyzing and processing the data access request to obtain a blockchain network node expected to be accessed by the user terminal specifically includes: When the central server terminal receives a data access request from a user terminal, identify the terminal identity information of the user terminal from the data access request; and determine whether the terminal identity information matches a preset terminal identity information white list. If so, determine that the data access request is a legal data access request; if not, determine that the data access request is an illegal data access request; When the data access request is a legitimate data access request, analyze and process the data access request to determine the data content and creation time of the data that the user terminal expects to access; and determine the blockchain network node where the data to be accessed is located in the blockchain according to the data content and creation time. When the data access request is an illegal data access request, terminate the current data access process of the user terminal through the central server.

3. The blockchain access control method based on a centralized policy according to claim 2, wherein: In the step S1, determining the access order of the user terminal to the blockchain network node according to the current access status of the blockchain network node specifically includes: Obtain whether there is a legitimate data access request from other user terminals in the blockchain network node currently. If not, set the current user terminal to have the first access order to the blockchain network node. If so, determine the access order of the current user terminal to the blockchain network node according to the preset terminal levels between the current user terminal and all other user terminals; wherein, the preset terminal level refers to the high and low levels of the access permissions of all user terminals to the blockchain set in advance.

4. The blockchain access control method based on a centralized policy according to claim 3, wherein: In the step S2, determining the access duration of the user terminal to the blockchain network node by the central server terminal according to the historical access information of the user terminal to the blockchain specifically includes: Obtain the historical access log information of the user terminal to the blockchain by the central server terminal according to the terminal identity information of the user terminal. Analyze and process the historical access log information to determine the total historical access times and the total historical access duration of the user terminal to the blockchain network node. Determine the average access duration of the user terminal to the blockchain network node according to the total historical access times and the total historical access duration.

5. The blockchain access control method based on a centralized policy according to claim 4, wherein: In the step S2, after the user terminal is assigned the access permission to the blockchain network node, setting the access action life cycle of the user terminal to the blockchain network node by the central server terminal according to the access duration specifically includes: When the central server terminal determines that the user terminal has the first access order to the blockchain network node, assign the access permission of the blockchain network node to the user terminal. And set the access action life cycle of the user terminal to the blockchain network node by the central server terminal, wherein the access action life cycle is not greater than the average access duration.

6. The blockchain access control method based on a centralized policy according to claim 5, wherein: In the step S3, obtaining the access record of the user terminal to the data block of the blockchain network node within the access action life cycle specifically includes: Obtain the data browsing duration of each data block of the blockchain network node by the user terminal during the life cycle of the access action.

7. The blockchain access control method based on a centralized policy according to claim 6, characterized in that: In the step S3, analyzing and processing the access record to determine the specific target data block from which the user terminal needs to obtain data includes: If the data browsing duration corresponding to a certain data block is greater than or equal to a preset time threshold, it is determined that the data block is the target data block from which the user terminal needs to obtain data.

Citation Information

Patent Citations

  • Memory cache management method and system, storage medium and electronic equipment

    CN111078585A

  • Dynamic hot data caching method

    CN111752902A