A blockchain-based access control method, device, and storage medium
By adopting a blockchain-based access control method in the Internet of Vehicles system, the trust value of vehicle nodes is determined and access control policies are generated, and the existing system's multi-entity, multi-role access control and single-point failure problems are solved, achieving efficient secure access control and data protection.
Patent Information
- Application Number
- CN202211181445.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-27
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-09-27
AI Technical Summary
The existing Internet of Vehicles systems are difficult to meet when facing the needs of multi-entity and multi-role access control, and the centralized cloud model has the risk of poor scalability and single point of failure, making it difficult to effectively prevent malicious attacks.
Using a blockchain-based access control method, by determining the overall trust value of vehicle nodes, a vehicle network model is constructed and access control policies are generated to realize distributed data storage and secure access control.
Effectively respond to gray hole attacks, slander attacks and conspiracy attacks, reduce vehicle calculation and transmission overhead, meet the access needs of multiple entities and multiple roles in the Internet of Vehicles scenarios, and improve data security and reliability.
Smart Images

Figure CN115643577B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Vehicles (IoV), and particularly to an access control method, apparatus, and storage medium based on blockchain. Background Art
[0002] The Internet of Vehicles (IoV) uses wireless communication technology to share information among vehicles, which helps to achieve autonomous driving and maintain traffic safety. The IoV uses communications such as Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) to interact information such as road congestion, movement trajectories, traffic accidents, and entertainment information, creating a safe and comfortable driving environment.
[0003] To prevent criminals from eavesdropping on and tampering with information, which may endanger the traffic system, information interaction must ensure the integrity and security of data. Otherwise, it is vulnerable to malicious attacks, such as replay, spoofing, and message tampering attacks, which may lead to traffic accidents. Therefore, it is crucial to adopt effective access control means to manage the information resources in the IoV and prevent unauthorized access to the information resources in the IoV to ensure the secure sharing of information resources.
[0004] However, due to the widespread distribution and mobility characteristics of vehicles, the current centralized cloud model IoV system is difficult to scale through a large number of weak devices, and it is difficult to meet the flexible access control requirements of multiple entities and roles in the IoV. In addition, the communication distance between IoV devices and the cloud is relatively long, which may consume a large amount of bandwidth, time, and energy. The cloud server is the bottleneck of the current IoV network. A single failure of the server will interrupt the entire network, suffering from the defect of single-point failure of the centralized server. Summary of the Invention
[0005] To solve the above technical problems, embodiments of the present invention are expected to provide an access control method, apparatus, and storage medium based on blockchain, which can effectively cope with black hole attacks, slander attacks, and collusion attacks from other vehicle nodes, while reducing the computing and transmission overhead of vehicles and meeting the access requirements of multiple entities and roles in the IoV scenario.
[0006] The technical solution of the present invention is implemented as follows:
[0007] In a first aspect, an embodiment of the present invention provides an access control method based on blockchain, including:
[0008] Determine the overall trust value of all vehicle nodes in the IoV network environment, where the IoV network environment is constructed based on a local blockchain and a global blockchain;
[0009] Build a vehicle networking model, and generate an access control policy based on the vehicle networking model and the overall trust value;
[0010] Perform access control on data according to the access control policy.
[0011] Optionally, for any vehicle node, determine the overall trust value of the vehicle node in the IOV network environment, including:
[0012] Calculate the decision factors of the vehicle node respectively. The decision factors include: initial trust decision factor, historical trust decision factor, recommended trust decision factor, and RSU observation trust decision factor;
[0013] Use the CRITIC algorithm to obtain the weight values of the decision factors;
[0014] Calculate the overall trust value of the vehicle node according to the decision factors and the weight values of the decision factors.
[0015] Optionally, calculate the recommended trust decision factor of the vehicle node, including:
[0016] Calculate the direct recommended trust decision factor, indirect recommended trust decision factor, and unfamiliar recommended trust decision factor of the vehicle node respectively;
[0017] Use the CRITIC algorithm to obtain the weight value of the direct recommended trust decision factor, the weight value of the indirect recommended trust decision factor, and the weight value of the unfamiliar recommended trust decision factor;
[0018] Calculate the recommended trust decision factor of the vehicle node according to the direct recommended trust decision factor, indirect recommended trust decision factor, unfamiliar recommended trust decision factor, the weight value of the direct recommended trust decision factor, the weight value of the indirect recommended trust decision factor, and the weight value of the unfamiliar recommended trust decision factor.
[0019] Optionally, the initial trust decision factor Among them, the attribute information affecting the vehicle safety performance is decomposed into m indicators, S i is the system security relevance corresponding to the i-th indicator, ω i is the weight of the i-th indicator;
[0020] The historical trust decision factor Among them, SF i is the weight of the information resource, m is the total number of historical interactions between vehicle i and j, Δt i is the difference between the current time and the access time, the parameter r is set by itself according to the time unit used, ES ij represents the trust evaluation of the message receiver j for the sender i;
[0021] The direct recommended trust decision factor Among them, C ik represents the recommended credibility, which is the degree of trust in the recommendation trust given by the evaluation node i to the recommended node k. C ik ∈[0, 1], m is the number of direct recommendation nodes, and M ik is the number of interactions between node i and the direct recommendation node k;
[0022] Indirect recommendation trust decision factor Among them, TR(i, k) represents the trust value of node i for node k, and p(i, k) represents the similarity of the score of node i for node k;
[0023] Strange recommendation trust decision factor Among them, the recommendation node k that has no interaction relationship with the evaluation node i is defined as a strange recommendation node, and the evaluation trust degree of the evaluation node for this type of recommendation node is tru i ;
[0024] RSU observation trust decision factor Among them, the relevant trust attributes of the vehicle are represented as λ i =[λ1, λ2, L, λ k , and each trust attribute is assigned a different trust weight, which is represented as And
[0025] Optionally, the vehicle networking network model includes five parts: TC, vehicle, RSU, global blockchain, and data visitor; among them,
[0026] TC is the trusted center, responsible for managing attributes and distributing keys; the vehicle senses data through the on-vehicle unit and communicates with the RSU; the RSU has storage space and computing functions, communicates with the vehicle, accepts the uploaded data, calculates the trust value of the vehicle, encrypts the data, and generates, verifies, and stores blocks; the global blockchain is built in the cloud, communicates with the RSU, distributes and stores the uploaded access policies and data, and decrypts and verifies when accessing the data; the data visitor is the access entity under IOV.
[0027] Optionally, generating an access control policy includes:
[0028] By mining the correlation relationship of attribute permissions among various roles, constructing a hierarchical access control policy;
[0029] Using pruning technology to optimize the hierarchical access control policy to obtain an access control policy.
[0030] Optionally, using pruning technology to optimize the hierarchical access control policy T to obtain an access control policy T α , including:
[0031] Calculate the empirical entropy of each node in the access control policy T of the computing hierarchy;
[0032] Recursively retract upward from the leaf nodes of the tree;
[0033] When the overall trees before and after a group of leaf nodes retract to their parent node are T a and T b , and their corresponding loss function values are Loss α (T a ) and Loss α (T b ), if Loss α (T a ) ≥ Loss α (T b ), then pruning is performed, and the attribute sets in the leaf nodes are merged and reorganized, and then retracted upward to replace the parent node with a new leaf node;
[0034] Return to execute the step of recursively retracting upward from the leaf nodes of the tree until it can no longer continue, and obtain the subtree T with the minimum loss function α .
[0035] Optionally, the access control policy includes an attribute-based encryption algorithm, and the encryption algorithm includes: system initialization, generating user keys, generating encrypted files, and decrypting ciphertext.
[0036] In a second aspect, an access control device based on a blockchain provided by an embodiment of the present invention includes: a processor, and the processor is used to implement the access control method based on the blockchain having any feature of the first aspect when executing a computer program.
[0037] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the access control method based on the blockchain having any feature of the first aspect.
[0038] In the embodiments of the present invention, first, the local blockchain (RSU calculates the trust value) and the global blockchain (stores data and access policies) are used together to maintain the generation, verification, and storage of blocks, realizing distributed data storage and ensuring the immutability of data. Second, an efficient trust evaluation method is designed. The overall trust value of vehicle nodes is obtained by comprehensively considering four trust decision factors: initial trust, historical experience trust, recommendation trust, and RSU observation trust. In the process of constructing the recommendation trust method, according to the interaction relationship between the recommended vehicle node and the communicator, the recommendation trust is divided into three categories. The optimal weights of the three types of recommendation trust are obtained by using CRITIC, and the optimal weights of the four trust decision factors are obtained by using CRITIC to obtain the final trust value. In addition, the NS3 simulation platform is used to verify the security and accuracy of the trust evaluation method, improving the recognition accuracy and detection rate of malicious vehicle nodes. Finally, by mining the correlation relationship between the attribute permissions of each role, a hierarchical access control strategy based on weight and trust is constructed and further optimized through pruning technology to ensure that the data on the chain can only be accessed when the attributes of the visitor meet the policy. Compared with the traditional vehicle network where data is vulnerable to tampering, leakage, and inflexible access control, the present invention can effectively cope with black hole attacks, slander attacks, and collusion attacks from other vehicle nodes, reduce the computing and transmission overhead of vehicles, and meet the access requirements of multiple entities and roles in the vehicle networking scenario. Description of the Drawings
[0039] The drawings described herein are used to provide a further understanding of the present invention and form a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0040] Figure 1 It is a schematic flow chart of an access control method based on blockchain provided by an embodiment of the present invention;
[0041] Figure 2 It is a relationship diagram between the negative scoring ratio and the change in trust under the F(*) function provided by an embodiment of the present invention;
[0042] Figure 3 It is an overall framework diagram of a vehicle networking network model provided by an embodiment of the present invention;
[0043] Figure 4 It is a schematic diagram of an access control policy provided by an embodiment of the present invention;
[0044] Figure 5(a) shows the recognition accuracy of malicious nodes with different node densities provided by an embodiment of the present invention;
[0045] Figure 5(b) shows the recognition accuracy of malicious nodes with different vehicle speeds provided by an embodiment of the present invention;
[0046] Figure 6 A comparison chart of the recognition accuracy of malicious nodes under different attacks provided by an embodiment of the present invention;
[0047] Figure 7 A comparison chart of the detection rates of malicious nodes under different attacks provided by an embodiment of the present invention;
[0048] Figure 8(a) shows the variation trend of encryption time with the number of attributes provided by an embodiment of the present invention;
[0049] Figure 8(b) shows the variation trend of ciphertext size with the number of attributes provided by an embodiment of the present invention;
[0050] Figure 9 A schematic structural diagram of an access control device based on blockchain provided by an embodiment of the present invention. Detailed implementation manners
[0051] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0052] Figure 1 A flowchart of an access control method based on blockchain provided by an embodiment of the present invention. The method disclosed in the embodiment of the present invention is applicable to an access control device based on blockchain. As Figure 1 shown, the method may include the following steps:
[0053] S110. Determine the overall trust value of all vehicle nodes in the IOV network environment, where the IOV network environment is constructed based on the local blockchain and the global blockchain.
[0054] The blockchain has the characteristics of distributed storage and immutability, can realize a trusted decentralized environment, and provide a system with anti-tampering, traceability, fault tolerance, and automatic execution of policies. Therefore, this application uses the local blockchain (maintained by the roadside unit RSU) and the global blockchain (maintained by the trusted center) to construct the IOV network environment, aiming to promote the secure access control of IOV and jointly address key challenges.
[0055] The Internet of Vehicles (IoV) has high dynamicity. Messages are transmitted between adjacent moving vehicles and are vulnerable to malicious attacks and security threats. When vehicles exchange information, malicious vehicle nodes may send false or incorrect messages, which can lead to traffic congestion and even traffic accidents, threatening the lives and property safety of vehicle owners. To ensure the secure transmission of data between vehicle nodes and enable vehicle owners to make correct decisions based on reliable information, it is necessary to conduct a trust assessment of communication objects before vehicles exchange messages to ensure the reliability of information.
[0056] The purpose of trust assessment is to evaluate the trust value of vehicle nodes by collecting behavioral status information, quickly and accurately identify malicious vehicle nodes in the IoV, and use the trust value as the basis for whether to establish communication with them to effectively respond to various attacks. The trust assessment method proposed in this invention comprehensively considers four core decision factors: initial trust, historical trust, recommended trust, and RSU observation trust. The following is the calculation method of trust components.
[0057] A. Initial trust
[0058] Some basic security information of the vehicle is stored in the Trusted Platform Module (TPM). These information are mainly the basic security attributes of the vehicle, such as vehicle type, year of manufacture, user information, digital certificate, etc. According to the system security policy, the attribute information affecting the vehicle safety performance is decomposed into m indicators, and the corresponding system security relevance degrees are S i ∈[0,1] (i = 1, 2,...), and weights ω i are assigned to them. Then the initial trust of the vehicle is:
[0059]
[0060] Since the vehicle is moving, its basic security attributes change accordingly. Therefore, to ensure the authenticity of the basic security attributes, the vehicle will periodically calculate and update its basic security attributes through the RSU. After verification by the RSU, they are stored in a distributed manner on the blockchain constructed by the RSU.
[0061] B. Historical trust
[0062] The historical trust of the vehicle, that is, the empirical trust, is obtained based on the historical interaction records between both parties. Due to the dynamic real-time nature of the IoV, the interaction time period needs to be used as one of the calculation factors. The calculation formula for the node historical trust is as follows:
[0063]
[0064] SF iis the weight of the information resource, and its weight is allocated according to the relevance between the information resource and security. Where m is the total number of historical interactions between vehicles i and j, and Δt i is the difference between the current time and the access time, and Δt i The larger it is, the smaller its weight. The parameter r is set by itself according to the time unit used, and ES ij represents the trust evaluation of the message receiver j for the sender i. According to the relevance between the information and security, the classification of information resources in the vehicle network is shown in Table 1 below:
[0065] Table 1 Classification of weights for calculating trust values of information resources
[0066]
[0067] C. Recommended trust
[0068] When there is no information interaction or little interaction between vehicle nodes, the node needs to collect multiple recommended nodes to calculate the recommended trust. However, for different types of recommended nodes, the criteria for judging credibility are also different. If a unified standard is used, there will be a large error. Therefore, according to the degree of association between the recommended node k and the evaluation node i, the present invention divides them into three categories and calculates their respective recommended trusts separately. Finally, the optimal weight of each type of recommended trust is determined by the CRITIC weight method, and the total recommended trust value TR is obtained ij .
[0069] C1: Direct recommended trust
[0070] The present invention defines the recommended node k that has had a direct interaction relationship with the evaluation node i as a direct recommended node, and the direct trust value TD of the evaluation node for this type of recommended node ik can directly be used as the relationship credibility of this type of node. Then the direct recommended trust is calculated as follows:
[0071]
[0072] Among them, C ik represents the recommended credibility, which is the degree of trust of the evaluation node i in the recommended trust given by the recommended node k. C ik ∈[0, 1], m is the number of direct recommended nodes, and M ik is the number of interactions between node i and the direct recommended node k.
[0073] C2: Indirect recommended trust
[0074] The present invention defines the recommended node k that has had an indirect interaction relationship with the evaluation node i as an indirect recommended node. The traditional recommended trust model uses the trust value of the node as the weight, and the formula is as follows:
[0075]
[0076] TR(i, k) represents the trust value of node i in node k. The higher the trust value of node i in node k, the more important its recommendation opinion is. However, the possibility of collusion attacks and slander attacks is ignored. For example, malicious nodes may obtain a high trust value through disguise and spread false information to normal nodes. The present invention uses the Pearson correlation coefficient to describe the difference in views of the two on the issue of jointly rated items. The successful interaction scores [r a1 , r a2 , L, r am given by vehicle node i to m nodes within a period of time t, and the successful transaction scores [r o1 , r o2 , L, r om given by vehicle k to these m vehicles. Then the similarity formula for the scores of node i on node k is as follows:
[0077]
[0078] P(i, k) ∈ [0, 1]. The larger the value of P(i, k), the higher the score similarity between the two, indicating that the scores of node i and node k on other nodes in the network are more consistent. Then the indirect recommendation trust is calculated as follows:
[0079]
[0080] C3: Stranger recommendation trust
[0081] The present invention defines the recommendation node k that has no interaction relationship with the evaluation node i as a stranger recommendation node. The evaluation trust degree of the evaluation node for this type of recommendation node is tru i . To prevent slander attacks, the feedback satisfaction degree is added. The feedback satisfaction degree FC i ∈ [0, 1]. If FC i < 0.5, it is considered that this recommendation node is not trustworthy and its recommendation trust is discarded. Otherwise, it is considered that the recommendation information of this node is trustworthy. The filtered recommendation trust set B = [tru1, tru2, L, tru N . Then the calculation formula for the stranger recommendation trust is as follows:
[0082]
[0083] On the basis of the above C1 - C3, the present invention adopts the CRITIC weight method to determine the optimal weights of the three recommended trusts. The CRITIC weight method is an objective weighting method better than the entropy weight method, mainly calculating weights by using the volatility of data or the correlation relationship between data. Let n represent the number of vehicle node samples and m represent the number of evaluation indicators of recommended trust. For example, the evaluation indicators of recommended trust are direct, indirect, and unfamiliar recommended trust respectively, that is, m = 3, and the original index data matrix X is formed:
[0084]
[0085] Among them, x ij represents the value of the i - th sample for the j - th evaluation indicator.
[0086] (1) Dimensionless processing
[0087] To eliminate the influence of different dimensions on the evaluation results, it is necessary to perform dimensionless processing on each indicator. For indicators with larger values being better (processed with positive indicators), it is expressed as follows:
[0088]
[0089] (2) Index variability
[0090] The difference and fluctuation of the internal values of each indicator are expressed in the form of standard deviation. The larger the standard deviation, the stronger the evaluation intensity of the indicator itself, and more weights should be assigned to the indicator. The calculation formula is as follows:
[0091]
[0092] Among them, s j represents the standard deviation of the j - th evaluation indicator.
[0093] (3) Index conflict
[0094] The correlation between indicators is represented by the correlation coefficient. The stronger the correlation with other indicators, the smaller the conflict with other indicators, the more the same information is reflected, and the more repetitive the evaluation content that can be reflected. The weights assigned to this indicator should be reduced. The calculation formula is as follows:
[0095]
[0096] Among them, r ij represents the correlation coefficient between evaluation indicators i and j.
[0097] (4) Information content
[0098]
[0099] Among them, Cj The larger it is, the greater the role of the j-th evaluation index in the entire evaluation index system, and more weight should be assigned to it.
[0100] (5) Weight
[0101]
[0102] The weights assigned to each evaluation index are calculated by the method of weighted summation. Thus, the optimal weight allocation scheme can be determined, and the total recommended trust is calculated as follows:
[0103] TR i,j = ω1TR d i,j + ω2TR in i,j + ω3TR u i,j (14)
[0104] Among them, ω1, ω2, and ω3 are the weights of direct, indirect, and unfamiliar recommended trust, respectively.
[0105] D. Observation trust of RSU
[0106] RSU can be used as an observer to detect the behavior status of vehicles for trust evaluation and transmit vehicle trust in real time between RSUs. The relevant trust attributes of the vehicle can be expressed as: λ i = [λ1, λ2, L, λ k , and because different trust attributes play different roles in the credibility calculation, different trust weights need to be assigned to each trust attribute, which can be expressed as: And The observation trust of the vehicle is calculated as follows:
[0107]
[0108] Since RSU is semi-trusted and is usually distributed on the road without any strong security measures and is vulnerable to attacks by attackers, in order to ensure the authenticity and credibility of RSU, positive and negative evaluations are carried out on RSU to obtain a set of trustworthy RSUs, and the recommended trust value of RSU is obtained by using the stage trust of RSU and the latest trust value of RSU. a + is the vehicle's positive score for RSU, and conversely, a - is the vehicle's negative score for RSU. θ n is the credibility determination of the n-th RSU, and the formula is as follows:
[0109]
[0110] Among them, θ n∈[-1,1], θ1 and θ2 are the weights of a + and a - respectively, as follows:
[0111]
[0112]
[0113] where F(*) is the sensitivity to the score. It can be seen from formula (16) that the proportion of negative scores and different F(*) will both affect the changing trend of θ n . Considering the time complexity and space complexity, within the range of error selection, F(x) = x, F(x) = x 2 , F(x) = x 3 , F(x) = x 4 , F(x) = e x and F(x) = e 2x are used to evaluate the influence of F(*) on θ n . Figure 2 is a relationship diagram between the proportion of negative scores and the change of trust degree under a kind of F(*) function provided by an embodiment of the present invention. As Figure 2 shown, when the proportion of negative scores is less than 50%, F(x) = x 4 is higher than other function curves. A small proportion of negative scores has little influence on the evaluation result, which is in line with the evaluation results of most vehicles. Therefore, F(x) = x 4 function is selected to control the change of the RSU trust degree θ n . When the trust degree of the RSU is lower than the lower limit of the trust degree, it is considered that the RSU is untrustworthy. At the next moment, the RSU is removed from the set of trustworthy RSUs and does not need to be identified again, improving the algorithm efficiency. When the vehicle drives into the communication range of the adjacent RSU and then drives out of the communication range, the RSU observes the behavior state of the vehicle during this period and calculates the stage trust value of the vehicle, and uploads it to the blockchain constructed by the RSU to update the trust value list, as shown in Table 2
[0114] Table 2 RSU Trust Value Update List
[0115]
[0116] The calculation method of the RSU observed trust value for updating the target node is as follows:
[0117]
[0118] When the vehicle approaches the RSU, the stage trust value is calculated by detecting the various behavior attributes of the vehicle through formula (15), and then the latest trust value RT i is calculated according to formula (19).
[0119] In summary, the initial trust value, historical trust value, recommended trust value, and RSU observation trust value of the vehicle node are calculated. The CRITIC weight method is used again to determine the optimal weights of the four trust decision factors. At this time, the number of evaluation indicators m = 4, and the corresponding weights ω i =[ω i (1) , ω i (2) , ω i (3) , ω i (4) are calculated. The overall trust value formula is as follows:
[0120] Tr i =ω i (1) IT i +ω i (2) HT i +ω i (3) TR i +ω i (4) RT i (20)
[0121] S120. Build a vehicle networking model, and generate an access control policy according to the vehicle networking model and the overall trust value.
[0122] Figure 3 This is the overall framework diagram of a vehicle networking model provided by an embodiment of the present invention. As Figure 3 shown, the vehicle networking model includes five parts: TC, vehicle, RSU, global blockchain, and data visitor. 1) TC is the trusted center, responsible for managing attributes and distributing keys. 2) The vehicle mainly senses data through the on-vehicle unit and communicates with the RSU. 3) The RSU has storage space and good computing functions, communicates with the vehicle, accepts the uploaded data, calculates the trust value of the vehicle, encrypts the data, and generates, verifies, and stores blocks. 4) The global blockchain is built in the cloud, communicates with the RSU, and distributes and stores the uploaded access policies and data. When accessing data, decryption and verification are required. 5) The data visitor is mainly an access entity under IOV, such as insurance companies, traffic law enforcement departments, and vehicle owners. Smart contracts are deployed on the blockchain edge layer and the blockchain network layer, and node consensus is achieved based on the Practical Byzantine Fault Tolerance (PBFT) algorithm to ensure the security of block nodes.
[0123] When a vehicle encounters a traffic accident, the vehicle uploads the perceived data to the blockchain, and then the data will be accessed by different entities. The traffic law enforcement department uses this data to investigate the cause of the accident and determine the liability for the accident, while the insurance company uses this data as the basis for claims settlement. Other vehicle owners will re-plan their driving routes based on the data to avoid traffic jams. However, the set of data visitor attributes is complex and the access rights division is overly redundant. To ensure data security, the access rights of the data are divided not only by entity, department and position attributes, but also by adding trust attributes to achieve a trustworthy judgment of the entity. Since there is an inclusion relationship among the position attributes of the same department of the entity, the access right range of a higher position includes the access right range of a lower position. For example, in the business department of an insurance company, there are insurance agents team leader manager general manager, with an attribute hierarchy relationship. Therefore, a hierarchical access control policy T is formulated through Algorithm 1.
[0124] Algorithm 1:
[0125] 1: Input AttrSet i , Credit i
[0126] 2: Output T
[0127] 3: Assign different trust values Credit to each entity i ∈C (set the trust threshold trust). If the entity is a vehicle and its trust value Credit i > trust, then mark AttrFlag i = 1, otherwise AttrFlag i = 0. If the entity is a transportation department, law enforcement agency and insurance company, AttrFlag i = True.
[0128] 4: For each attribute AttrSet i ∈U do
[0129] 5: / / Classify the attributes into M types of attributes S = {S A , S B , S C , …, S M} according to entity, vehicle type, department and position
[0130] 6: Classify(AttrSet i ) → S i
[0131] 7: End
[0132] 8: Sort the attributes according to the access rights. If there is an inclusion relationship among the access rights of the same type of attributes, that is Assign weights to these attributes
[0133] 9: For i = 1 to M
[0134] 10: For j = 1 to N
[0135] 11: S i,j .ω = j / / ω starts from 1
[0136] 12: End
[0137] 13: End
[0138] 14: / / Represent the same type of attributes with continuous inclusion relationships of access rights in the attribute set using weighted attributes
[0139] For i = 1 to AttrSet.length
[0140] 15:
[0141] 16: S i,j .ω = m, S i,j →S i :ω i , j ∈ [1, m]
[0142] 17: End
[0143] 18: Connect different entities with OR, and connect different department and position attributes and trust values under the same entity with AND.
[0144] 19: T = (Car A AND(CarType A …OR…)AND AttrFlag A )OR(Entity B AND(Department B …OR…)AND(S B :ω1…OR…)AND AttrFlag B )OR(Entity C AND(Department C …OR…)AND(S C :ω2…OR…)AND AttrFlag C )OR…
[0145] 20: Final
[0146] This algorithm takes as input the set of attributes and the set of vehicle trust values defined by different entities, vehicle types, departments, and positions, and outputs the formulated hierarchical access control policy T. The attributes are divided into different attribute classes S = {S A , S B , S C , L, S M} according to entities, vehicle types, departments, and positions. If there is an inclusion relationship in the access permissions of the same type of attributes, that is and a weight ω is assigned to it, incrementing successively from 1, and then traversing. If there is a ω continuity in the position attributes under the same entity department, these attributes are replaced with S i : ω i . Connect different entities with OR, and connect different department, position attributes, and trust values under the same entity with AND to generate the hierarchical access control policy T. The attributes in policy T are reduced to 1 / m of the total attributes. However, the set of data visitor attributes is complex, and there may be a risk of attribute redundancy. It is necessary to perform pruning and recombination optimization on T through Algorithm 2 to obtain the final access control policy T α , and the access control policy structure is as Figure 4 shown.
[0147] Algorithm 2:
[0148] 1: Input: Access control policy T, parameter α
[0149] 2: Output: Pruned tree T α
[0150] 3: Step (1) Calculate the empirical entropy of each node.
[0151] 4: Step (2) Recursively retract from the leaf nodes of the tree upwards.
[0152] 5: When the overall trees before and after a group of leaf nodes retract to their parent node are T a and T b respectively, and their corresponding loss function values are Loss α (T a ) and Loss α (T b ), if Loss α (T a ) ≥ Loss α (T b ) then pruning is performed, and then the attribute sets in the leaf nodes are merged and recombined, and retracted upwards, replacing the parent node with a new leaf node.
[0153] 6: Step (3) Return to Step (2) until it cannot continue, and obtain the subtree T α with the minimum loss function.
[0154] Let the number of leaf nodes of the tree be |T|, and m be a leaf node of tree T. This leaf node has N m sample points, among which there are N mk sample points of class k, and E m (T) is the empirical entropy on leaf node m. If α > 0, the loss function of the tree is defined as:
[0155]
[0156] Among them, the empirical entropy is:
[0157]
[0158] S130. Perform access control on data according to the access control policy.
[0159] Among them, the access control policy includes an attribute-based encryption algorithm, and the encryption algorithm includes: system initialization, generating user keys, generating encrypted files, and decrypting ciphertexts.
[0160] (1) System initialization
[0161] Setup: Take the security parameter γ and the attribute set U as inputs. γ is public, and output the system public key PK and the master secret key MSK. For the bilinear group G1 of prime order p, g is the generator of G1, and Z p is the multiplicative group of integers modulo p, and perform the bilinear pairing operation e: G1×G1→G T . Generate the hash function H: {0,1} * →G1. The attribute set U = {α1, α2, α3L, α n}, assign weighted attributes {s|s∈S i} to entities, select random numbers α, β∈Z p , and calculate e(g,g) α and g β . The generated public key PK and master secret key MSK are as follows:
[0162] PK = {G1, g, g β , e(g,g) α} (23)
[0163] MSK = g α (24)
[0164] (2) Generate user keys
[0165] Keygen(MSK, S, Tr) takes the master secret key MSK, a set of weighted attributes S, and the trust value Tr as inputs, and outputs the key SK related to S and Tr. Randomly select t∈Z p , for each weighted attribute i∈S, it has a weighted value ωi , for each attribute i in the attribute set, calculate Finally, generate the secret key SK of the data visitor as follows:
[0166] SK = {D = g α g βt , g t , {D i} i∈S , Tr} (25)
[0167] To ensure the confidentiality and security of data and achieve an effective access control effect, the present invention adopts a hybrid encryption mechanism, encrypts the data content using the symmetric encryption standard (AES), and executes the Encrypt(PK, CK, M, T) algorithm to encrypt the symmetric key CK and embed the access control policy T.
[0168] (3) Encryption
[0169] Encrypt(PK, CK, M, T): Input the public key PK, plaintext M, symmetric key CK, and access control policy T, and output the ciphertext CT. Select a polynomial f for each node x in T x . For each node in T, select d x = k x - 1 degree polynomial. Starting from the root node R, f R (0) = s (s ∈ Z p ), s is a random number. For the leaf node x, set f x (0) = f parent(x) (index(x)) and randomly select d x defined f x , each leaf node represents a weighted attribute, ω i is the minimum weight of each leaf node. Calculate C = M · e(g, g) αs , C0 = g s . Take s as the secret and split it along the access tree, so that for the leaf node attribute i, the corresponding secret shard is f x (0). Calculate Finally, generate the ciphertext CT:
[0170] CT = {T, C, C0, C T , {C i} i∈[1,n]} (26)
[0171] (4) Decryption and verification
[0172] Decryption can only be performed when the attribute set S of the secret key and the trust value Tr satisfy the ciphertext access tree T policy. Calculate Starting from the root node, perform recursive calculations. After performing exponential operations on the shards of each child node based on the Lagrange interpolation factors, perform consecutive multiplication operations. Construct the decryption component:
[0173]
[0174] Then Obtain the decrypted ciphertext M.
[0175] Based on the above embodiments, the present invention can utilize the network emulator NS3 and the traffic simulation tool SUMO to simulate the vehicle networking environment. Verify and compare the security and performance of the design solution provided by the present invention. The simulation parameters are shown in Table 3.
[0176] Table 3 Simulation Parameters
[0177]
[0178] To ensure timely and reliable information interaction between vehicles, it is necessary to improve the recognition of malicious nodes, that is, to improve the recognition accuracy of untrusted nodes. The trust evaluation scheme of the present invention is simulated and compared with the schemes without trust evaluation and traditional trust evaluation. The experimental results are shown in Figure 5. Figure 5(a) shows the malicious node recognition accuracy at different node densities. Figure 5(b) shows the malicious node recognition accuracy at different vehicle speeds.
[0179] As can be seen from Figure 5(a) and Figure 5(b), the greater the vehicle node density, the higher the recognition accuracy. The traditional trust evaluation scheme combines direct trust and indirect trust to improve the recognition accuracy of malicious vehicle nodes, but ignores the collection and calculation of vehicle experience trust and behavior observation information. Therefore, the recognition accuracy of the trust evaluation scheme of the present invention is higher than that of the other two models.
[0180] The present invention simulates and realizes a network with black hole attacks, on-off attacks, and slander attacks, compares the trust evaluation scheme of the present invention with the trust models ART, CAT, and TSMRP, and uses the malicious node detection rate and the malicious node recognition accuracy as two evaluation indicators. Set the total number of nodes to 100, and the number of malicious nodes to 10, 20, and 30 respectively. The network attack scenarios are set as shown in Table 4.
[0181] Table 4 Network Attack Scenario Settings
[0182]
[0183] When facing different attacks, the comparison of the recognition accuracy and detection rate of malicious nodes is as Figure 6 and Figure 7 shown.
[0184] Since CAT focuses on vehicle behavior detection and insufficiently considers the trust in historical experience and the trust information recommended by other vehicles; ART relies on indirect trust, ignores the collection and calculation of direct trust, and neither ART nor CAT can effectively respond to timing attacks. TSMRP combines direct trust and indirect trust and proposes a feedback mechanism to deal with timing attacks, but it insufficiently considers the collection and calculation of vehicle experience trust and behavior observation information. The new trust evaluation method combines direct trust, indirect trust, historical experience trust, and behavior observation trust, making the accuracy of trust calculation higher. Therefore, the recognition accuracy and detection rate of the new trust evaluation method are higher than those of the other three models.
[0185] By judging the credibility of vehicle nodes, the security and reliability of information transmission are ensured, and the effect of secure access control of data is achieved. The present invention uses the Java Pairing-Based Cryptography (JPBC) to implement comparative experiments of traditional CP-ABE, weighted CP-ABE, and the new access control model. The number of attributes set in the experiment is incremented from 1 to 100 one by one. In the access control policy T without pruning and recombination processing, each attribute class S contains an average of 5 attributes. After optimization processing, each attribute class S contains an average of 6 attributes. The experimental results are shown in Figure 8. Figure 8(a) shows the change trend of encryption time with the number of attributes, and Figure 8(b) shows the change trend of ciphertext size with the number of attributes. It can be seen that the solution of the present invention adds the credible judgment of entities to further ensure the effect of secure access control, and effectively reduces the complexity of the access policy through pruning technology, saving the computational overhead.
[0186] In the embodiments of the present invention, first, the local blockchain (RSU calculates the trust value) and the global blockchain (stores data and access policies) are used together to maintain the generation, verification, and storage of blocks, realizing distributed data storage and ensuring the immutability of data. Second, an efficient trust evaluation method is designed. The overall trust value of vehicle nodes is obtained by comprehensively considering four trust decision factors: initial trust, historical experience trust, recommendation trust, and RSU observation trust. In the process of constructing the recommendation trust method, according to the interaction relationship between the recommended vehicle node and the communicator, the recommendation trust is divided into three categories. The optimal weights of the three types of recommendation trust are obtained using CRITIC, and the optimal weights of the four trust decision factors are also obtained using CRITIC to obtain the final trust value. In addition, the NS3 simulation platform is used to verify the security and accuracy of the trust evaluation method, improving the recognition accuracy and detection rate of malicious vehicle nodes. Finally, by mining the correlation relationship between the attribute permissions of each role, a hierarchical access control policy based on weight and trust is constructed and further optimized through pruning technology to ensure that the data on the chain can only be accessed when the attributes of the visitor meet the policy. Compared with the traditional vehicle network where data faces problems such as being easily tampered with, leaked, and having inflexible access control, the present invention can effectively cope with black hole attacks, slander attacks, and collusion attacks from other vehicle nodes, reduce the computing and transmission overhead of vehicles, and meet the access requirements of multiple entities and roles in the vehicle networking scenario.
[0187] The embodiments of the present invention also provide an access control device based on blockchain, including: a processor, which is used to implement the method with any feature of the above embodiments when executing a computer program.
[0188] Figure 9 FIG. shows a schematic structural diagram of an access control device 10 based on blockchain that can be used to implement the embodiments of the present invention. The access control device based on blockchain is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The access control device based on blockchain can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0189] As Figure 9As shown, the blockchain-based access control device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores computer programs executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 12 or the computer programs loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the blockchain-based access control device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0190] Multiple components in the blockchain-based access control device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the blockchain-based access control device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0191] The processor 11 can be various general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the blockchain-based access control method.
[0192] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories and optical memories, etc.) containing computer-usable program codes.
[0193] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one flow Figure 1 one flow or more flows and / or blocks Figure 1 or means for implementing the functions specified in one block or more blocks.
[0194] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or more flows and / or blocks Figure 1 or means for implementing the functions specified in one block or more blocks.
[0195] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or more flows and / or blocks Figure 1 or means for implementing the functions specified in one block or more blocks.
[0196] The above is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention.
Claims
1. A blockchain-based access control method, characterized in that, Including: Determine the overall trust value of all vehicle nodes in the IOV network environment, where the IOV network environment is constructed based on a local blockchain and a global blockchain; For any one of the vehicle nodes, determining the overall trust value of the vehicle node in the IOV network environment includes: Calculate the decision factors of the vehicle node respectively, where the decision factors include: an initial trust decision factor, a historical trust decision factor, a recommendation trust decision factor, and an RSU observation trust decision factor; The initial trust decision factor ; among them, the attribute information affecting the vehicle safety performance is decomposed into indicators, is the system safety relevance corresponding to the i th indicator, is the weight of the i th indicator; The historical trust decision factor ; where is the weight of the information resource, is the total number of historical interactions between the vehicle and ; is the difference between the current time and the access time, and the parameter is set according to the time unit used, represents the trust evaluation of the message receiver for the sender . Direct recommendation trust decision factor ; among them, indicates that the recommendation credibility is the degree of trust of the evaluation node in the recommendation trust given by the recommendation node . , is the number of direct recommendation nodes, is the node and the direct recommendation node 's interaction times; Indirect recommendation trust decision factor ; where represents the trust value of node in respect of node ; represents the similarity of the score of node in respect of node ; Trust decision factor for unfamiliar recommendations ; Among them, the recommendation node that has no interaction relationship with the evaluation node is defined as an unfamiliar recommendation node, and the evaluation trust degree of the evaluation node for this type of recommendation node is ; The RSU observation trust decision factor ; among which, the relevant trust attributes of the vehicle are expressed as , Each trust attribute is assigned a different trust weight, denoted as , and ; Calculating the recommendation trust decision factor of the vehicle node includes: Calculate the direct recommendation trust decision factor, the indirect recommendation trust decision factor, and the stranger recommendation trust decision factor of the vehicle node respectively; Using the CRITIC algorithm, obtain the weight value of the direct recommendation trust decision factor, the weight value of the indirect recommendation trust decision factor, and the weight value of the stranger recommendation trust decision factor; According to the direct recommendation trust decision factor, the indirect recommendation trust decision factor, the stranger recommendation trust decision factor, the weight value of the direct recommendation trust decision factor, the weight value of the indirect recommendation trust decision factor, and the weight value of the stranger recommendation trust decision factor, calculate the recommendation trust decision factor of the vehicle node; Using the CRITIC algorithm, obtain the weight value of the decision factor; According to the decision factor and the weight value of the decision factor, calculate the overall trust value of the vehicle node; Construct an IOV network model, and generate an access control policy according to the IOV network model and the overall trust value; Perform access control of data according to the access control policy.
2. The method according to claim 1, characterized in that, The IOV network model includes five parts: TC, vehicle, RSU, global blockchain, and data visitor; where The TC is a trusted center responsible for managing attributes and distributing keys; the vehicle senses data through an on-vehicle unit and communicates with the RSU; the RSU has a storage space and a computing function, communicates with the vehicle, accepts the uploaded data, calculates the trust value of the vehicle, encrypts the data, and generates, verifies, and stores blocks; the global blockchain is built in the cloud, communicates with the RSU, distributes and stores the uploaded access policies and data, and decrypts and verifies when accessing data; the data visitor is an access entity under IOV.
3. The method according to claim 1 or 2, characterized in that, Generating the access control policy includes: Construct a hierarchical access control policy by mining the association relationship of attribute permissions among roles; Use pruning technology to optimize the hierarchical access control policy to obtain the access control policy.
4. The method according to claim 3, characterized in that, Using the pruning technique to optimize the hierarchical access control policy to obtain the access control policy , including: calculating the empirical entropy of each node of the hierarchical access control policy ; Recursively retract from the leaf node of the tree upwards; Before and after a set of leaf nodes retract to their parent node, the overall trees are respectively and The corresponding loss function values are respectively and , if then pruning is performed, and then the attribute sets in the leaf nodes are merged and reorganized, and retracted upward to replace the parent node with a new leaf node; Return and execute the step of recursively retracting upward from the leaf nodes of the tree until it can no longer continue, and obtain the subtree with the minimum loss function .
5. The method according to claim 1, wherein The access control policy includes an attribute-based encryption algorithm, and the encryption algorithm includes: system initialization, generating a user key, generating an encrypted file, and decrypting the ciphertext.
6. An access control device based on blockchain, characterized in that, Including: A processor, where the processor is used to implement the blockchain-based access control method according to any one of claims 1-5 when executing a computer program.
7. A computer-readable storage medium storing a computer program, characterized in that, The computer program, when executed by the processor, implements the blockchain-based access control method according to any one of claims 1-5.