A blockchain permission management method, apparatus, computer device, and storage medium

By acquiring and storing access permissions and restrictions for blockchain user and resource information, the problem of low management efficiency caused by frequent blockchain creation in existing technologies is solved, and efficient permission management and access control are achieved.

CN115987981BActive Publication Date: 2025-10-31SHENZHEN HAIZHICHUANG TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211498191.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-10-31
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

Existing blockchain access control methods require the frequent creation of new blockchains, resulting in low management efficiency and an inability to effectively restrict access permissions for unauthorized users.

Method used

By acquiring target user and resource information, establishing access permissions and access restrictions, and uploading this information to blockchain storage, access management for target users and resources can be achieved, avoiding the need to rebuild the blockchain.

Benefits of technology

It improves the efficiency of blockchain permission management, restricts access permissions for non-target users, and avoids the establishment of redundant blockchains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987981B_ABST
    Figure CN115987981B_ABST
Patent Text Reader

Abstract

This application relates to a blockchain permission management method, apparatus, computer device, and storage medium. The method includes: acquiring target user information and target resource information of the blockchain; the target user information includes target user personal data and data belonging to the target user, and the target resource information includes target resource data and data belonging to the target resource; based on the target user's personal data, establishing access permissions for the target user to access the target resource data through a permission control program, and establishing access restrictions for the target user to access the target resource data based on the target user's data and the data belonging to the target resource; uploading the access permissions and access restrictions for each target user to access the target resource data to the blockchain, and storing the access permissions and access restrictions on the blockchain to complete the blockchain permission management. This method can improve the efficiency of blockchain permission management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular to a blockchain permission management method, apparatus, computer device, and storage medium. Background Technology

[0002] Blockchain technology is an advanced database mechanism that allows for the transparent sharing of information within enterprise networks. A blockchain database stores data on a blockchain, and these databases are linked together on a chain. Data is consistent over time because the chain cannot be deleted or modified without network consensus. However, since information on the blockchain is public, it is impossible to restrict access to specific groups. Therefore, access control methods for blockchain are currently a key research focus.

[0003] Traditional blockchain access control methods involve creating a new blockchain for users who need to access the system from a small group, thereby restricting access for other unauthorized users. However, this method requires repeatedly creating blockchains, making them cumbersome and difficult to manage, resulting in low efficiency in blockchain access control. Summary of the Invention

[0004] Therefore, it is necessary to provide a blockchain permission management method, device, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems.

[0005] Firstly, this application provides a blockchain permission management method. The method includes:

[0006] Obtain target user information and target resource information of the blockchain; the target user information includes target user personal data and target user belonging data, and the target resource information includes target resource data and target resource belonging data;

[0007] Based on the target user's personal data, an access control procedure is used to establish access permissions for the target user to access the target resource data, and based on the data to which the target user belongs and the data to which the target resource belongs, access restriction conditions for the target user to access the target resource data are established.

[0008] The access permissions and access restrictions for each target user to access the target resource data are uploaded to the blockchain, and the access permissions and access restrictions are stored in the blockchain to complete the access control of the blockchain.

[0009] Optionally, the step of establishing access permissions for the target user to access the target resource data through an access control procedure based on the target user's personal data includes:

[0010] By using an access control procedure, an access identifier is added to the target user's personal data, and an access identification identifier is added to the target resource data, thereby obtaining the target user's access rights to the target resource data.

[0011] Optionally, the access restrictions include scope restrictions on accessing the target resource data and information restrictions on accessing the target resource data. Establishing access restrictions for the target user to access the target resource data based on the target user's data and the target resource's data includes:

[0012] Based on the target user's data, determine the target user's belonging object, and use the target users belonging to the belonging object as information restrictions for the target resource data;

[0013] Based on the data to which the target resource data belongs, the target database to which the target resource data belongs is determined as the scope limitation of the target resource data;

[0014] Based on the scope limitations and information limitations of the target resource data, the access restrictions for the target user to access the target resource data are determined.

[0015] Optionally, after establishing the access restriction conditions for the target user to access the target resource data, the method further includes:

[0016] Obtain the permission scope information of the target user; the permission scope information is the target user's operation permission information on the target resource data;

[0017] Based on the permission scope information, establish the target user's operation permissions for the target resource data.

[0018] Secondly, this application provides a blockchain user access method. The method includes:

[0019] Obtain the user's access permissions to the blockchain, as well as the access restrictions for those users;

[0020] Based on the user's access restrictions, determine the data to which the user can access the resources.

[0021] If the user's access permissions meet the preset access conditions, the resource data corresponding to the resource data is queried in the resource database through the resource data, and the resource data is transmitted to the user's display terminal.

[0022] Thirdly, this application also provides a blockchain permission management device. The device includes:

[0023] The acquisition module is used to acquire target user information and target resource information of the blockchain; the target user information includes target user personal data and target user belonging data, and the target resource information includes target resource data and target resource belonging data.

[0024] The module is used to establish access permissions for the target user to access the target resource data based on the target user's personal data and through an access control program, and to establish access restriction conditions for the target user to access the target resource data based on the data to which the target user belongs and the data to which the target resource belongs.

[0025] The upload module is used to upload the access permissions and access restrictions of each target user to the target resource data to the blockchain, and to store the access permissions and access restrictions in the blockchain to complete the access control of the blockchain.

[0026] Optionally, the establishment module is specifically used for:

[0027] By using an access control procedure, an access identifier is added to the target user's personal data, and an access identification identifier is added to the target resource data, thereby obtaining the target user's access rights to the target resource data.

[0028] Optionally, the access restrictions include scope restrictions on accessing the target resource data and information restrictions on accessing the target resource data. The establishing module is specifically used for:

[0029] Based on the target user's data, determine the target user's belonging object, and use the target users belonging to the belonging object as information restrictions for the target resource data;

[0030] Based on the data to which the target resource data belongs, the target database to which the target resource data belongs is determined as the scope limitation of the target resource data;

[0031] Based on the scope limitations and information limitations of the target resource data, the access restrictions for the target user to access the target resource data are determined.

[0032] Optionally, the device further includes:

[0033] The permission scope acquisition module is used to acquire the permission scope information of the target user; the permission scope information is the target user's operation permission information on the target resource data.

[0034] The operation permission establishment module is used to establish the target user's operation permissions for the target resource data based on the permission scope information.

[0035] Fourthly, this application also provides a blockchain user access device. The device includes:

[0036] The permission acquisition module is used to acquire the access permissions of users on the blockchain, as well as the access restrictions for those users.

[0037] The determination module is used to determine the data to which the user can access resources based on the user's access restrictions.

[0038] The transmission module is used to, when the user's access permissions meet the preset access conditions, query the resource data corresponding to the resource data in the resource database through the resource data, and transmit the resource data to the user's display terminal.

[0039] Fifthly, this application provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method described in any one of the first and second aspects.

[0040] Sixthly, this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described in any one of the first and second aspects.

[0041] In a seventh aspect, this application provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the method described in any one of the first and second aspects.

[0042] The aforementioned blockchain permission management method, apparatus, computer equipment, and storage medium acquire target user information and target resource information of the blockchain. The target user information includes target user personal data and target user-owned data; the target resource information includes target resource data and target resource-owned data. Based on the target user personal data, an access control program establishes access permissions for the target user to access the target resource data, and based on the target user-owned data and the target resource-owned data, establishes access restrictions for the target user to access the target resource data. The access permissions and access restrictions for each target user to access the target resource data are uploaded to the blockchain, and the access permissions and access restrictions are stored on the blockchain to complete the blockchain permission management. By establishing access permissions and access restrictions between target users and target resource information, the creation of a new blockchain is avoided, and access permissions for non-target users to target data are restricted, thereby improving the efficiency of blockchain permission management. Attached Figure Description

[0043] Figure 1 This is a flowchart illustrating a blockchain permission management method in one embodiment;

[0044] Figure 2 This is a schematic diagram of the NGCA access control procedure in one embodiment;

[0045] Figure 3 This is a flowchart illustrating a blockchain user access method in one embodiment;

[0046] Figure 4 This is a flowchart illustrating a blockchain permission management example in one embodiment;

[0047] Figure 5 This is a structural block diagram of a blockchain permission management device in one embodiment;

[0048] Figure 6 A structural block diagram of a blockchain user access device in one embodiment;

[0049] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0051] The blockchain permission management method provided in this application can be applied to terminals, servers, and systems including both terminals and servers, and is implemented through interaction between the terminal and the server. The terminal can include, but is not limited to, various personal computers, laptops, tablets, etc. By establishing access permissions and access restrictions between target users and target resource information on the blockchain, this method avoids the need to rebuild a new blockchain and restricts access permissions for non-target users to target data, thereby improving the efficiency of blockchain permission management.

[0052] In one embodiment, such as Figure 1 As shown, a blockchain permission management method is provided. Taking the application of this method to a terminal as an example, the method includes the following steps:

[0053] Step S101: Obtain the target user information and target resource information of the blockchain.

[0054] The target user information includes the target user's personal data and the data to which the target user belongs, while the target resource information includes the target resource data and the data to which the target resource belongs.

[0055] In this embodiment, with the authorization of the target user, the terminal downloads the target user's personal data and the target user's ownership data from the blockchain, and uses the target user's personal data and ownership data as the target user information. With the authorization of the blockchain database, the terminal obtains target resource data and the ownership data of the target resource from the blockchain database, and uses the target resource data and the ownership data of the target resource as the target resource data of the blockchain. The target user's personal data includes personal information such as the target user ID, name, gender, age, and identity information. The target user's ownership data includes data information about the organization to which the target user belongs, such as the target user's employer, the blockchain to which the target user belongs, and the organization category to which the target user belongs. The target resource data is resource data for which access needs to be restricted to certain users on the blockchain, and this resource data is stored in the blockchain database. The target resource ownership data is the storage location data of the target resource, such as the folder where the target resource is stored, the storage partition where the target resource is stored, and the database where the target resource is stored.

[0056] Step S102: Based on the target user's personal data, establish access permissions for the target user to access the target resource data through the access control program, and establish access restriction conditions for the target user to access the target resource data based on the data to which the target user belongs and the data to which the target resource belongs.

[0057] In this embodiment, the terminal presets an access control program on the blockchain and establishes an encrypted access channel between the target user's personal data and the target resource data based on the target user's personal data. The terminal uses the user's access to this encrypted access channel as the target user's access permission to access the target resource data. The preset access control program can be, but is not limited to, any type of access control program, such as NGAC (Next Generation Access Control). The specific access permission establishment process will be described in detail later. The terminal establishes access restrictions for the target user's access to the target resource data based on the data belonging to the target user and the data belonging to the target resource. The specific process of establishing these access restrictions will be described in detail later.

[0058] Step S103: Upload the access permissions and access restrictions of each target user to the target resource data to the blockchain, and complete the blockchain permission management by storing the access permissions and access restrictions.

[0059] In this embodiment, the terminal uploads the access permissions and access restrictions for each target user to the target resource data to the blockchain. After these permissions and restrictions are uploaded, when a user requests access to the target resource data, the blockchain requests the necessary permissions and restrictions from the requesting user. If the requesting user lacks the required permissions and restrictions, the blockchain denies access to the target resource data. Furthermore, when users on the blockchain view these permissions and restrictions, the blockchain only displays the target resource data for users who are authorized to access it. The terminal manages blockchain permissions by storing access permissions and restrictions.

[0060] Based on the above scheme, by establishing access permissions and access restrictions between target users and target resource information in the blockchain, the creation of a new blockchain is avoided, and access permissions for non-target users to target data are restricted, thereby improving the efficiency of blockchain permission management.

[0061] Optionally, based on the target user's personal data, an access control procedure can be used to establish access permissions for the target user to access the target resource data, including:

[0062] By using an access control program, an access identifier is added to the target user's personal data, and an access identification identifier is added to the target resource data, thereby obtaining the target user's access rights to the target resource data.

[0063] In this embodiment, the terminal adds an access identifier to the target user's personal data and an access identification identifier to the target resource data through a preset access control procedure. When a user requests access to the target resource data, the terminal determines whether the access identifier in the target user's personal data corresponds to the access identification identifier in the target resource data. If the access identifier in the target user's personal data corresponds to the access identification identifier in the target resource data, the terminal allows the target user to access the target resource data and sends the target resource data to the target user's display terminal via an encrypted transmission channel. The terminal uses the aforementioned access identifier and access identification identifier as the target user's access permission to access the target resource data.

[0064] Based on the above scheme, by adding access identifiers to the target user's personal data and access identification identifiers to the target resource data, access permissions for the target user to access the target resource data are established, avoiding modification of the target resource data on the blockchain and improving the efficiency of blockchain permission management.

[0065] Optionally, access restrictions include scope restrictions on accessing target resource data and information restrictions on accessing target resource data. Based on the data to which the target user belongs and the data to which the target resource belongs, access restrictions for the target user to access the target resource data are established, including: determining the object to which the target user belongs based on the data to which the target user belongs, and using the target user belonging to that object as the information restriction for the target resource data; determining the target database to which the target resource data belongs based on the data to which the target resource data belongs as the scope restriction for the target resource data; and determining the access restrictions for the target user to access the target resource data based on the scope restriction and the information restriction for the target resource data.

[0066] In this embodiment, the terminal determines the object to which the target user belongs based on the target user's data, and uses the target users belonging to the object as information restrictions on the target resource data. The step of using the target users belonging to the object as information restrictions on the target resource data is used to uniformly manage the permissions of each target user when different target users belong to the same object. The terminal determines the target database to which the target resource data belongs based on the object's data, as a scope restriction on the target resource data. The terminal uses the scope restriction and the information restriction of the target resource data as access restriction conditions for the target user to access the target resource data.

[0067] Based on the above scheme, by establishing access restrictions for target users to access target resource data, the system can further control users from arbitrarily accessing other target resources through access permissions, thereby improving the efficiency of blockchain permission management.

[0068] Optionally, after establishing access restrictions for target users to access target resource data, the following also applies:

[0069] Obtain the target user's permission scope information; the permission scope information is the target user's operation permission information on the target resource data; based on the permission scope information, establish the target user's operation permissions on the target resource data.

[0070] In this embodiment, the terminal obtains the permission scope information of the target user. The permission scope information refers to the range of operation permissions each target user has for the target resource data, such as read-only, partial read / write, or full read / write. Based on the obtained permission scope information, the terminal establishes operation permissions for each target user for the target resource data. For example, ... Figure 2 The ` / hr-docs` folder shown represents the resource ownership data for the target resource data. This folder contains two files: `resume` (the target resource data) and `contract` (also the target resource data), defined in the contract layer. Each file is linked to a class (`public / confidential`). There are also instances of the contract layer, `FileSystem` and `Scope`, where objects in the diagram are linked—these conditions must be met to gain access to each file. User Allice is an external object, not stored in the contract layer. Assume she has read and write access to both files because there's a path linking Allice to each file, and this path grants permissions to both policy classes. User Bob is also an external object, but only has access to the `resume` file. This is because while there's a path from Bob to the `contract` file that satisfies the `Read` permission of the `FileSystem` policy class, there isn't a path that grants permissions to the `Scope` policy class. Therefore, Bob's access to the `contract` file is denied.

[0071] In one embodiment, such as Figure 3 As shown, a blockchain user access method is provided. Taking the application of this method to a terminal as an example, the method includes the following steps:

[0072] Step S301: Obtain the user's access permissions and access restrictions for the blockchain.

[0073] In this embodiment, the terminal responds to the user's access data operation to obtain the user's access permissions and access restrictions.

[0074] Step S302: Determine the data to which the user can access resources based on the user's access restrictions.

[0075] In this embodiment, the terminal queries the blockchain to find the data of the resource corresponding to the user's access restriction conditions.

[0076] Step S303: If the user's access permissions meet the preset access conditions, query the resource data corresponding to the resource data in the resource database through the resource ownership data, and transmit the resource data to the user's display terminal.

[0077] In this embodiment, the terminal queries the blockchain for a corresponding access identifier based on the user's access identifier in the access permissions. If an access identifier corresponding to the access identifier exists, the terminal uses the resource ownership data obtained in step S302 to query the databases in the blockchain that contain the resource data associated with the access identifier. This database is then designated as the resource database. Within the resource database, the terminal queries the resource data corresponding to the access identifier that identifies the access identifier, and transmits the resource data corresponding to the access identifier to the user's display device.

[0078] Based on the above scheme, access to data resources on the blockchain is improved by using access permissions and user access restrictions.

[0079] This application also provides an example of blockchain permission management, such as... Figure 4 As shown, the specific processing procedure includes the following steps:

[0080] Step S401: Obtain the target user information and target resource information of the blockchain.

[0081] Step S402: Through the access control procedure, an access identifier is added to the target user's personal data and an access identification identifier is added to the target resource data to obtain the target user's access rights to the target resource data.

[0082] Step S403: Based on the data to which the target user belongs, determine the object to which the target user belongs, and use the target user belonging to the object as the information restriction of the target resource data.

[0083] Step S404: Based on the data to which the target resource data belongs, determine the target database to which the target resource data belongs as the scope limitation of the target resource data.

[0084] Step S405: Determine the access restrictions for the target user to access the target resource data based on the scope restrictions and information restrictions of the target resource data.

[0085] Step S406: Obtain the target user's permission scope information; the permission scope information is the target user's operation permission information on the target resource data.

[0086] Step S407: Based on the permission scope information, establish the target user's operation permissions for the target resource data.

[0087] Step S408: Upload the access permissions and access restrictions of each target user to the target resource data to the blockchain, and complete the blockchain permission management by storing the access permissions and access restrictions.

[0088] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0089] Based on the same inventive concept, this application also provides a blockchain permission management device for implementing the blockchain permission management method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more blockchain permission management device embodiments provided below can be found in the limitations of the blockchain permission management method described above, and will not be repeated here.

[0090] In one embodiment, such as Figure 5 As shown, a blockchain permission management device is provided, including: an acquisition module 510, an establishment module 520, and an upload module 530, wherein:

[0091] The acquisition module 510 is used to acquire target user information of the blockchain and target resource information of the blockchain; the target user information includes target user personal data and target user belonging data, and the target resource information includes target resource data and target resource belonging data;

[0092] The module 520 is used to establish access permissions for the target user to access the target resource data based on the target user's personal data and through an access control program, and to establish access restriction conditions for the target user to access the target resource data based on the data to which the target user belongs and the data to which the target resource belongs.

[0093] The upload module 530 is used to upload the access permissions of each target user to the target resource data and the access restriction conditions of each target user to the target resource data to the blockchain, and to store the access permissions and the access restriction conditions through the blockchain to complete the access permission management of the blockchain.

[0094] Optionally, the establishment module 520 is specifically used for:

[0095] By using an access control procedure, an access identifier is added to the target user's personal data, and an access identification identifier is added to the target resource data, thereby obtaining the target user's access rights to the target resource data.

[0096] Optionally, the access restrictions include scope restrictions on accessing the target resource data and information restrictions on accessing the target resource data. The establishment module 520 is specifically used for:

[0097] Based on the target user's data, determine the target user's belonging object, and use the target users belonging to the belonging object as information restrictions for the target resource data;

[0098] Based on the data to which the target resource data belongs, the target database to which the target resource data belongs is determined as the scope limitation of the target resource data;

[0099] Based on the scope limitations and information limitations of the target resource data, the access restrictions for the target user to access the target resource data are determined.

[0100] Optionally, the device further includes:

[0101] The permission scope acquisition module is used to acquire the permission scope information of the target user; the permission scope information is the target user's operation permission information on the target resource data.

[0102] The operation permission establishment module is used to establish the target user's operation permissions for the target resource data based on the permission scope information.

[0103] Based on the same inventive concept, this application also provides a blockchain user access device for implementing the blockchain user access method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more blockchain user access device embodiments provided below can be found in the limitations of the blockchain user access method described above, and will not be repeated here.

[0104] In one embodiment, such as Figure 6 As shown, a blockchain user access device is provided, comprising: a permission acquisition module 610, a determination module 620, and a transmission module 630, wherein:

[0105] The permission acquisition module 610 is used to acquire the access permissions of the blockchain user and the access restriction conditions of the user;

[0106] The determining module 620 is used to determine the data to which the user can access resources based on the user's access restrictions.

[0107] The transmission module 630 is used to query the resource data corresponding to the resource data in the resource database through the resource data, and transmit the resource data to the user's display terminal when the user's access permissions meet the preset access conditions.

[0108] The modules in the aforementioned blockchain permission management device and blockchain user access device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0109] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a blockchain-based access control method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device's casing, or an external keyboard, touchpad, or mouse.

[0110] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0111] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in any one of the first and second aspects.

[0112] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, wherein the computer program, when executed by a processor, comprises the steps of the method described in any one of the first and second aspects.

[0113] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, comprises the steps of the method described in any one of the first and second aspects.

[0114] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0115] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0116] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0117] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A blockchain permission management method, characterized in that, The method includes: Obtain target user information and target resource information of the blockchain; the target user information includes target user personal data and target user belonging data, and the target resource information includes target resource data and target resource belonging data; Based on the target user's personal data, an access control procedure is used to establish access permissions for the target user to access the target resource data, and based on the data to which the target user belongs and the data to which the target resource belongs, access restriction conditions for the target user to access the target resource data are established. The access permissions and access restrictions for each target user to access the target resource data are uploaded to the blockchain, and the access permissions and access restrictions are stored in the blockchain to complete the access control of the blockchain. The access restrictions include scope restrictions on accessing the target resource data and information restrictions on accessing the target resource data. The step of establishing access restrictions for the target user to access the target resource data based on the data to which the target user belongs and the data to which the target resource belongs includes: determining the object to which the target user belongs based on the data to which the target user belongs, and using the target users belonging to the object as the information restrictions of the target resource data. Based on the data to which the target resource data belongs, the target database to which the target resource data belongs is determined as the scope limitation of the target resource data; Based on the scope limitations and information limitations of the target resource data, the access restrictions for the target user to access the target resource data are determined.

2. The method according to claim 1, characterized in that, The step of establishing access permissions for the target user to access the target resource data based on the target user's personal data through an access control program includes: adding an access identifier to the target user's personal data and adding an access identification identifier to the target resource data through the access control program, thereby obtaining the target user's access permissions to the target resource data.

3. The method according to claim 1, characterized in that, After establishing the access restriction conditions for the target user to access the target resource data, the method further includes: obtaining the permission scope information of the target user; the permission scope information is the operation permission information of the target user on the target resource data; Based on the permission scope information, establish the target user's operation permissions for the target resource data.

4. A blockchain user access method, applying the blockchain permission management method as described in claim 1, characterized in that, The method includes: Obtain the user's access permissions to the blockchain, as well as the access restrictions for those users; Based on the user's access restrictions, determine the data to which the user can access the resources. If the user's access permissions meet the preset access conditions, the resource data corresponding to the resource data is queried in the resource database through the resource data, and the resource data is transmitted to the user's display terminal.

5. A blockchain permission management device, employing the blockchain permission management method as described in claim 1, characterized in that, The device includes: The acquisition module is used to acquire target user information and target resource information of the blockchain; the target user information includes target user personal data and target user belonging data, and the target resource information includes target resource data and target resource belonging data. The module is used to establish access permissions for the target user to access the target resource data based on the target user's personal data and through an access control program, and to establish access restriction conditions for the target user to access the target resource data based on the data to which the target user belongs and the data to which the target resource belongs. The upload module is used to upload the access permissions and access restrictions of each target user to the target resource data to the blockchain, and to store the access permissions and access restrictions in the blockchain to complete the access control of the blockchain.

6. A blockchain user access device, applying the blockchain permission management method as described in claim 1, characterized in that, The device includes: The permission acquisition module is used to acquire the access permissions of users on the blockchain, as well as the access restrictions for those users. The determination module is used to determine the data to which the user can access resources based on the user's access restrictions. The transmission module is used to, when the user's access permissions meet the preset access conditions, query the resource data corresponding to the resource data in the resource database through the resource data, and transmit the resource data to the user's display terminal.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 3.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 3.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Database accessing authority control method and equipment based on block chain

    CN107480555A