A data cross-domain access control method and system
By employing cross-domain central authentication and multi-permission traceable encryption mechanisms, combined with machine learning and natural language processing technologies, the problems of trust measurement, mapping efficiency, and encryption security in cross-domain access control are solved, achieving secure and efficient cross-domain data sharing, and making it suitable for cross-domain access control in the industrial internet.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU UNIVERSITY
- Filing Date
- 2023-02-13
- Publication Date
- 2026-06-02
AI Technical Summary
Existing cross-domain access control methods in the Industrial Internet suffer from problems such as unreliable trust measurement, complex delegation capability updates, low efficiency of role/attribute mapping, and insecure encryption methods, making it difficult to guarantee the security and efficiency of cross-domain data sharing.
It adopts cross-domain central authentication, rule mapping, and multi-permission traceable encryption mechanisms. It extracts attribute information through machine learning and natural language processing technologies, constructs a cross-domain access control model, uses vectors to represent attribute values of different domains, generates new cross-domain access requests, and uses sparse matrix storage technology to generate new cross-domain access control information and new cross-domain access request information. It also uses natural language processing technology to generate new cross-domain access requests, realizes the information of the cross-domain access control system, generates cross-domain access request information, and sends it to data users.
It improves the security and efficiency of cross-domain data sharing, ensures cross-domain access control of data in the large-scale dynamic environment of the industrial Internet, solves the heterogeneity problem of cross-domain access management, ensures the confidentiality and integrity of cross-domain resources, and supports fine-grained accountability access control.
Smart Images

Figure CN116318865B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of industrial internet, and in particular relates to a method and system for cross-domain data access control. Background Technology
[0002] In recent years, with the continuous development of information technology in our country, the comprehensive utilization of data resources in various industries has accelerated its transformation towards informatization and intelligentization. The deep integration of information and communication technology with the industrial economy has led to the development of the Industrial Internet. Through comprehensive connectivity of people, machines, things, and systems, the Industrial Internet covers the entire industrial chain, accelerates manufacturing development, and improves service systems, providing a pathway for the digital, networked, and intelligent development of industry and even the entire industrial sector. The Industrial Internet requires strengthened cooperation among enterprises to achieve interconnected information sharing and improve the efficiency of information services. Currently, different industries within the Industrial Internet are governed by different domains. For example, an industrial chain may include design companies, manufacturing companies, financial institutions, and logistics companies. For security management, these companies have their own management domains, implementing security constraints and managing data resources within their respective domains. These independent management domains ensure the security of communication and interaction between enterprises in the Industrial Internet industrial chain.
[0003] While individual management domains can ensure the security of data resources within a single domain, they cannot guarantee the security of cross-domain information exchange and data sharing. The inability to guarantee the security of cross-domain data sharing is one of the main reasons why comprehensive information sharing and supply chain collaboration in the Industrial Internet are difficult to achieve. Because data often belongs to different management domains, sharing data between enterprises leads to the failure of existing single-domain security constraints. Data sharing between enterprises faces challenges from cross-domain authorization, primarily due to the lack of cross-domain data access control mechanisms implementable in the Industrial Internet.
[0004] Cross-domain access control is the primary method for achieving cross-domain data sharing in the Industrial Internet. Due to the heterogeneity of security policies across different management domains, universal authorization management is difficult to achieve. By formulating effective access control policies, the access behavior of data users can be constrained, enabling control over access to sensitive resources across different domains. Cross-domain access control is an extension of single-domain access control based on current Internet needs, addressing the issues of heterogeneity, dynamism, and large scale in cross-domain management, and protecting the security of cross-domain data resources. However, the lack of suitable cross-domain access control methods hinders the real-world implementation of cross-domain data sharing.
[0005] Currently, several methods for cross-domain access control have been proposed. Although access control mechanisms suitable for industrial internet scenarios have been extensively studied, there are still shortcomings. Existing methods can be mainly divided into three types: The first type is cross-domain access control methods based on trust mechanisms. These methods typically calculate the trust level of data users and then assess the granting of access permissions. The second type is cross-domain access control methods based on delegation mechanisms. These methods mainly protect data resources by delegating access capabilities and using authorization tokens. The third type is cross-domain access control methods based on mapping mechanisms. These methods are usually combined with attribute-based access control (ABAC) and role-based access control (RBAC) models for control. ABAC is an access control model that uses the connection between attributes and permissions. RBAC mainly uses cross-domain role mapping for cross-domain authorization, making configuration and management easier and more convenient. These methods mainly protect the security of cross-domain data by mapping roles and attributes to extend the single-domain access control model.
[0006] However, existing technologies have the following shortcomings:
[0007] (1) Existing cross-domain access control methods based on trust mechanisms have many limitations. One of the most significant limitations is the trust measurement problem. It is difficult to select a representative and universal trust measurement across different domains and maintain dynamic evaluation. The reliability of trust evaluation determines the effectiveness of the access control mechanism. If the reliability of trust evaluation cannot be guaranteed, the security of cross-domain data sharing cannot be guaranteed. Due to the heterogeneity and dynamism of cross-domain data access, traditional trust evaluation has security risks, thus posing a risk of sensitive data leakage in cross-domain data access.
[0008] (2) Existing cross-domain access control methods based on delegation mechanisms are limited by performance. In environments with large-scale cross-domain data sharing, the updating and revocation of delegation capabilities in these methods increases the computational load, significantly impacting the performance of the cross-domain system and leading to increased latency in the token transmission process. Furthermore, the forensic analysis of delegation capabilities is difficult under large-scale cross-domain data access, affecting the security of data sharing. This method cannot meet the cross-domain data access control requirements of large-scale dynamic scenarios in the Industrial Internet.
[0009] (3) Existing cross-domain access control methods based on mapping mechanisms have many problems. Using mapping mechanisms to address the heterogeneity of cross-domain data access control results in low efficiency and sensitive data leakage during the cross-domain access process, failing to guarantee the security of cross-domain data. Mapping mechanisms mainly include role mapping and attribute mapping. Role mapping for cross-domain data access control suffers from data leakage due to its coarse-grained nature, inflexibility, and cross-domain role conflicts. Attribute mapping for cross-domain data access control presents two problems: First, the attribute mapping mechanism is complex, requiring a complex one-to-one mapping of all attributes between different domains. Existing attribute mapping library technology is unsuitable for large-scale cross-domain data sharing. In scenarios involving numerous cross-domain accesses between multiple domains, multiple mapping libraries and a large number of mapping tables exist. This technology increases performance consumption, workload, and reduces mapping efficiency when handling large-scale mapping needs. Second, cross-domain data access control using only traditional cryptographic encryption and decryption methods or basic attribute encryption not only leads to complex key management but also hinders traceability and fails to guarantee the confidentiality and integrity of cross-domain data. Summary of the Invention
[0010] The purpose of this invention is to provide a method and system for cross-domain data access control, which achieves a highly efficient cross-domain rule mapping mechanism and data encryption mechanism through a new cross-domain data access control model. To achieve the above objective, this invention provides a method for cross-domain data access control, the method comprising:
[0011] S1. First, all domains that need to share data across domains register their information at the cross-domain center.
[0012] S2. Based on the cross-domain certificate, check whether all domains participating in cross-domain data sharing are legitimate, and verify the legitimacy of data owners and data users based on the information provided by the domain administrator. Each authentication requires the digital signatures of the domain administrator and the cross-domain center.
[0013] S3. Based on the information provided by the registered domain, the cross-domain center extracts all attribute information of each domain, represents different attributes of different domains with vectors, binds the correlation of attribute value space, and constructs the model.
[0014] S4. The cross-domain data center extracts cross-domain access request information from the cross-domain certificate. The cross-domain request information includes the data user's identity information and the relevant attribute information of the accessed resources.
[0015] S5. The cross-domain center performs rule mapping on cross-domain requests, mapping the attributes and attribute value spaces of the domain where the data user is located and the domain where the data owner is located, generating new cross-domain access request information, and sending the new information to the data user.
[0016] S6. Data owners and data users conduct cross-domain negotiations. At this time, data users need to bring the credentials issued by the cross-domain center.
[0017] S7. The data owner designs an access control tree for the resource and performs attribute and reverse encryption based on multi-permission traceability for the resource.
[0018] S8. Data users obtain the attribute key set based on the new cross-domain request calculated by the cross-domain center, and use the attribute keys to decrypt cross-domain data resources.
[0019] Furthermore, the information mentioned in step S1 includes domain-related information, owned attribute information, key information, and the validity period of cross-domain data sharing.
[0020] Furthermore, in step S2, the legitimacy of the data owner and data user is verified based on the information provided by the domain administrator: if legitimate, the next cross-domain request is allowed to be processed, and the information of the data user and data owner is added to the cross-domain trusted list; if illegitimate, the data user is informed of the relevant problem information, and cross-domain services are refused for them.
[0021] When the cross-domain center receives information about a registered domain, it first searches the cross-domain trusted list. If the domain exists, it directly provides cross-domain services; otherwise, it performs legitimacy authentication.
[0022] Furthermore, the information for cross-domain negotiation between the data owner and the data user in step S6 includes the negotiation key algorithm; the credential is used to verify the authenticity of the identity.
[0023] Furthermore, in step S8, the resource end of the data resource is used to track whether it is a legitimate decryption process, the data resource auditing method is used to determine whether it is a malicious user, and the cross-domain path of the data resource is used to achieve tracing and source identification.
[0024] In a second aspect of the present invention, a cross-domain data access control system is provided, the system comprising a cross-domain initialization module, a rule mapping module, and a cross-domain encryption module;
[0025] The cross-domain initialization module is used to authenticate the identities of cross-domain data owners and users and to ensure the legitimacy of all parties involved in cross-domain data sharing.
[0026] The mapping module is used to map attribute names and attribute value spaces within each domain;
[0027] The cross-domain encryption module is used to encrypt data with multiple permissions and traceability.
[0028] Furthermore, the cross-domain initialization module includes an information registration unit and an authentication detection unit;
[0029] The information registration unit is used for all domains that are involved in cross-domain data sharing to register information at the cross-domain center;
[0030] The authentication and detection unit is used to detect whether all domains participating in cross-domain data sharing are legitimate, and to use cross-domain certificates to detect the legitimacy of data owners and data users. Each authentication requires a digital signature from the cross-domain node.
[0031] Furthermore, the rule mapping module includes a model building unit, a learning unit, and a storage unit;
[0032] The model building unit is used to extract the attribute information of each domain based on the information provided by the registered domain, classify and label them, divide the attribute types into static attributes and dynamic attributes, and represent the attributes using vectors according to different domains and different types.
[0033] The learning unit is used to map the attributes of data users and data owners using natural language processing technology. The cross-domain center extracts the attribute information of cross-domain access requests from data users, extracts attribute features through natural language processing technology, trains attribute models using machine learning, and maps them to the attributes of data owners.
[0034] The storage module is used to store the successfully mapped attribute names and attribute value spaces in a mapping table using a storage mechanism, and to generate new cross-domain access request information using sparse matrix storage technology, and then send the new information to the data user.
[0035] Furthermore, the cross-domain encryption module includes a multi-attribute permission unit and a tracking and tracing unit;
[0036] The multi-attribute permission unit is used to implement a fine-grained and distributed access control mechanism. It employs multi-attribute permission encryption technology to generate attribute key strings based on multiple permissions. Attribute management for each organization resides on different servers, using multi-attribute permission encryption technology to generate attribute key strings based on multiple permissions. The algorithm settings, AAKeyGen, CAKeyGen, encryption, and decryption are key components of the multi-attribute permission CP-ABE. The definitions of encryption and decryption are the same as the basic CP-ABE definition, except that the attributes in the access policies and keys come from different attribute servers (AA...). k ).
[0037] Multi-attribute permission encryption scheme:
[0038] 1)
[0039] The initial algorithm is set up and run by CA. Input Then, the algorithm returns (pk) k,sk k ) as AA k It outputs a public key pair, and also outputs PK and MK, where PK is publicly released and MK is secretly maintained by the CA.
[0040] 2)
[0041] Attribute key generation algorithm, by AA s Run. After entering PK, AA k key sk k A user's global identity (GID) and the property server AA k List of managed attributes L (k) The algorithm output is the same as L. (k) The corresponding key SK L(k) If the user's GID attribute list is L={L (k)} k∈I SK L ={SK L(k)} k∈I As the attribute key, where I represents AA s The index set, whose attribute fields include user attributes.
[0042] 3)
[0043] The central key generation algorithm is run by the CA. After inputting PK, MK, and GID, the algorithm outputs SKC as the central key for the user's GID.
[0044] In distributed CP-ABE, AA s The public key pair and secret key are generated by itself, eliminating the need for a central key generation algorithm. The attribute key generated by this algorithm is the same as that of the CA-enabled multi-authority CP-ABE described above.
[0045] The tracing and attribution unit implements a fine-grained and accountability-based access control mechanism. This method tracks key misuse by data users, preventing malicious users from possessing the attribute sets of legitimate users. The cross-domain path primarily records the process of cross-domain requests. It records the request path generated after the domain administrator and cross-domain center verify the legitimacy of the request and implement access control policies on the resource side. This becomes crucial information for the domain administrator to verify cross-domain requests and trace their origins. The domain administrator can perform forensic analysis of cross-domain request behavior through the cross-domain path and tracing key. The algorithm settings, encryption, and decryption definitions in the tracing and attribution scheme are the same as the basic CP-ABE definition.
[0046] Traceability and source identification solution:
[0047] 1)
[0048] AA runs this algorithm to generate attribute keys. The algorithm takes PK, MK, ID, and L as input and returns SK. ID,L This serves as the key corresponding to ID and L.
[0049] 2)
[0050] The tracking algorithm can be run on any server. Input PK and attribute key SK. ID,L Then, the algorithm first checks SK. ID,L Is this correct? If SK ID,L Being correct means it can be used in a correct decryption process; the algorithm outputs an ID, representing SK. ID,L Link to ID. Otherwise, it outputs T, representing SK. ID,L If invalid, it does not need to be traced. If the master key is involved, the algorithm defines accountability accordingly.
[0051] 3)
[0052] This is an interactive protocol between users with identity IDs and auditors. When the system uses the tracking key SK... ∗ ID,L When a user is identified as malicious, the user enters (PK, SK). ID,L ) and auditor input (PK, SK) ∗ ID,L ), and determine whether the user is malicious.
[0053] Furthermore, the cross-domain certificate includes: data owner ID. o Data User ID uThe process involves several key elements: access operation, cross-domain path, request validity period, relevant context information, domain-related information, and the domain administrator's digital signature. The cross-domain path is the route of the cross-domain request, including information about the data owner, data user, and nodes traversed by the request, thus documenting the entire trajectory of the cross-domain request. The request validity period records the validity of the cross-domain path and is used by cross-domain management and resource providers to assess the security of cross-domain requests. Relevant context information stores the context information in the cross-domain access request or indicates whether the request can be responded to, and can be used for access control decisions by resource providers. The signature is the domain administrator's electronic signature of authentication information, representing that the access request has been received and its legitimacy has been preliminarily verified by the domain administrator. The domain administrator, as the management point of a single domain, primarily confirms the legitimacy of cross-domain requests; this function can be performed by the platform or server. As a participant in cross-domain management, the domain administrator needs to be authenticated and interact with the cross-domain center, and is also one of the trusted centers in the cross-domain process. The domain administrator can preliminarily verify the legitimacy of cross-domain requests through digital signatures and supports global access control policies for the domain. All cross-domain accesses must be logged by the domain administrator to ensure the authenticity of cross-domain data access.
[0054] The beneficial technical effects of the present invention are at least as follows:
[0055] (1) Ensure the security of cross-domain data sharing and meet the needs of large-scale dynamic industrial interconnection.
[0056] Existing cross-domain data access mechanisms pose security risks. Dynamic assessment of trust mechanisms, delegation of permissions in delegation mechanisms, and role / attribute mapping in mapping mechanisms all face certain security issues. This invention proposes a complete cross-domain data access control scheme. It utilizes machine learning to improve the efficiency of cross-domain rule mapping and employs optimized attribute encryption methods to implement a multi-permission traceable cross-domain encryption scheme, ensuring the security of cross-domain data access and meeting the large-scale, dynamic cross-domain requirements of the Industrial Internet environment.
[0057] (2) Solve the problem of heterogeneous cross-domain access management and improve the efficiency and accuracy of cross-domain rule mapping.
[0058] Cross-domain access control first needs to address the heterogeneity of access authorization rules across different domains. Existing mapping methods based on standard libraries solve this problem, but these methods are unsuitable for dynamic, large-scale mapping scenarios. This invention utilizes NLP technology to implement a cross-domain rule mapping mechanism through feature extraction and model training of cross-domain attribute information. This method is the core of cross-domain data management, solving the heterogeneity problem and the complexity of rule mapping in cross-domain data management. It also improves the efficiency of cross-domain rule mapping in large-scale cross-domain scenarios, reduces mapping latency, lowers performance overhead on cross-domain systems, and ensures accurate cross-domain mapping through fine-grained mapping of attribute names and attribute value spaces, thus achieving highly efficient cross-domain data access control.
[0059] (3) Ensuring the confidentiality and integrity of cross-domain resources facilitates access control with fine-grained accountability.
[0060] Existing traditional attribute encryption methods cannot achieve fine-grained accountability and tracing capabilities, and cannot perform security analysis of cross-domain access in cross-domain data sharing, leading to serious security problems. This invention designs a multi-permission traceable attribute encryption method for distributed environments. It utilizes a tracking key algorithm, auditing methods, and cross-domain path recording to track cross-domain access behavior and detect malicious users, and enables tracing and evidence collection, facilitating the identification and accountability of suspects after malicious behavior occurs. It also ensures the confidentiality and integrity of cross-domain access data resources. Attached Figure Description
[0061] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.
[0062] Figure 1 This is a schematic diagram of a cross-domain data access control method according to the present invention.
[0063] Figure 2 This is a framework diagram of a cross-domain data access control system according to the present invention.
[0064] Figure 3 This is a schematic diagram of a multi-permission traceable data encryption and decryption method according to an embodiment of the present invention.
[0065] Figure 4 This is a schematic diagram of a specific embodiment of a cross-domain data access control method according to an embodiment of the present invention. Detailed Implementation
[0066] Embodiments of the present invention are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0067] Specific implementation method one: as follows Figure 1 As shown, this invention provides a cross-domain data access control method that can achieve both single-domain and cross-domain access control. The single-domain access control method does not require a rule mapping process, and the specific steps for cross-domain access control are as follows:
[0068] S1. First, all domains that are to share data across domains register their information in the cross-domain center. The information includes domain-related information, attribute information, key information, and the validity period of the cross-domain data sharing.
[0069] S2. Based on the cross-domain certificate, the system checks the legitimacy of all domains participating in cross-domain data sharing and verifies the legitimacy of data owners and users based on information provided by the domain administrators. Each authentication requires digital signatures from both the domain administrator and the cross-domain center. If legitimate, the system allows processing of the next cross-domain request and adds the data user and data owner information to the cross-domain trusted list. If illegitimate, the system informs the data user of the relevant issues and refuses to provide cross-domain services. Upon receiving information about a registered domain, the cross-domain center prioritizes searching the cross-domain trusted list. If the domain exists, cross-domain services are provided directly; otherwise, legitimacy authentication is performed.
[0070] S3. Based on the information provided by the registered domain, the cross-domain center extracts all attribute information of each domain, represents different attributes of different domains with vectors, binds the correlation of attribute value space, and constructs the model.
[0071] S4. The cross-domain data center extracts cross-domain access request information from the cross-domain certificate. The cross-domain request information includes the data user's identity information and the relevant attribute information of the accessed resource.
[0072] S5. The cross-domain center performs rule mapping on cross-domain requests, mapping the attributes and attribute value spaces of the domain where the data user resides and the domain where the data owner resides. It generates new cross-domain access request information and sends this new information to the data user.
[0073] S6. The data owner and the data user conduct cross-domain negotiation (negotiate key algorithm and other information). At this time, the data user needs to carry the credentials issued by the cross-domain center (to verify the authenticity of the identity).
[0074] S7. The data owner designs an access control tree for the resource and performs attribute encryption on the resource based on multi-permission traceability.
[0075] S8. Data users derive an attribute key set from the new cross-domain request calculated by the cross-domain center, and use the attribute keys to decrypt cross-domain data resources. The resource side uses a tracking algorithm to determine whether it is a legitimate decryption process, uses an auditing method to determine whether it is a malicious user, and uses cross-domain paths to achieve source tracing.
[0076] Based on the above methods, such as Figure 2 As shown, the present invention also provides a cross-domain data access control system. According to... Figure 2 As shown, the system includes: a cross-domain initialization module, a rule mapping module, and a cross-domain encryption module.
[0077] Specifically: 1) The cross-domain initialization module is responsible for authenticating the identities of data owners and users across domains, ensuring the legitimacy of data sharing among all parties. 2) The rule mapping module is responsible for mapping attribute names and attribute value spaces within each domain. This module is the foundation of cross-domain access control and the core of cross-domain access. 3) The cross-domain encryption module is responsible for multi-permission traceable data encryption. This module is a functional component of cross-domain access control and the core of data protection.
[0078] The cross-domain initialization module includes an information registration module and an authentication detection module.
[0079] 1) Information Registration Unit: The domains where data owners and data users reside register cross-domain related information (domain-related information, owned attribute information (encrypted), etc.) with the cross-domain center, registering all domains that share data across domains, thus achieving the first line of security detection for cross-domain transactions.
[0080] 2) Authentication and Detection Unit: Detects whether all domains involved in cross-domain data sharing are legitimate, and uses cross-domain certificates to detect the legitimacy of data owners and data users. Each authentication requires the digital signature of the cross-domain node to verify the authenticity of the node and operation.
[0081] A cross-domain certificate is defined as: data owner IDo, data user IDu, access operation, cross-domain path, request validity period, relevant context information, domain-related information, and the domain administrator's digital signature.
[0082] A cross-domain path is the path of a cross-domain request, including information about the data owner, data user, and nodes traversed by the access request, encompassing the entire trajectory of the cross-domain request. The request validity period records the validity of the cross-domain path, used by cross-domain management and resource ends to determine the security of cross-domain requests. Relevant context information stores contextual information within the cross-domain access request or indicates whether the request can be responded to, and can be used for access control decisions by the resource end. The signature is the domain administrator's electronic signature of authentication information, representing that the access request has been received by the domain administrator and its legitimacy has been initially verified. The domain administrator is the management point of a single domain, primarily responsible for verifying the legitimacy of cross-domain requests; this function can be performed by the platform or server. As a participant in cross-domain management, the domain administrator needs to be authenticated and interact with the cross-domain center, and is also one of the trusted centers in the cross-domain process. The domain administrator can initially verify the legitimacy of cross-domain requests through digital signatures and supports global access control policies for the domain. All cross-domain access must be recorded by the domain administrator to ensure the authenticity of cross-domain data access.
[0083] The rule mapping module includes a model building unit, a model unit, and a storage unit.
[0084] 1) Model Unit: Based on the information provided by the registered domain, extract the attribute information of each domain, classify and label them, classify the attribute type into static attributes and dynamic attributes, and use vector representation for attributes according to different domains and different types;
[0085] 2) Learning Unit: Natural Language Processing (NLP) techniques are used to map the attributes of data users and data owners. The cross-domain center extracts attribute information from cross-domain access requests by data users, extracts attribute features using NLP, trains an attribute model using machine learning, and maps it to the attributes of the data owner.
[0086] 3) Storage unit: The storage mechanism stores the attribute names and attribute value spaces that have been successfully mapped across domains in a mapping table, and uses sparse matrix storage technology (the mapping matrix is a sparse matrix). When there is a similar cross-domain request next time, the stored mapping information is used for direct mapping.
[0087] Cross-domain encryption modules such as Figure 3 The data encryption shown is responsible for multi-permission traceability, including multi-attribute permission units and traceability units.
[0088] 1) Multi-Attribute Permission Unit: Implements a fine-grained and distributed access control mechanism. Attribute management for each organization resides on different servers, employing multi-attribute permission encryption technology to generate attribute key strings based on multiple permissions. The algorithm settings, AAKeyGen, CAKeyGen, encryption, and decryption are key components of the multi-attribute permission CP-ABE. The definitions of encryption and decryption are the same as the basic CP-ABE definition, except that the attributes in the access policies and keys come from different attribute servers (AA...). k Multi-attribute access control encryption scheme:
[0089] 1.
[0090] The initial algorithm is set up and run by CA. Input Then, the algorithm returns. (pk) k ,sk k ) As AA k It outputs a public key pair, and also outputs PK and MK, where PK is publicly released and MK is secretly maintained by the CA.
[0091] 2.
[0092] Attribute key generation algorithm, by AA s Run. After entering PK, AA k key sk k A user's global identity (GID) and the property server AA k List of managed attributes L (k) The algorithm output is the same as L. (k) The corresponding key SK L(k) If the user's GID attribute list is L={L (k)} k∈I SK L ={SK L(k)} k∈I As the attribute key, where I represents AA s The index set, whose attribute fields include user attributes.
[0093] 3.
[0094] The central key generation algorithm is run by the CA. After inputting PK, MK, and GID, the algorithm outputs SKC as the central key for the user's GID.
[0095] In distributed CP-ABE, AA sThe public key pair and secret key are generated by itself, eliminating the need for a central key generation algorithm. The attribute key generated by this algorithm is the same as that of the CA-enabled multi-authority CP-ABE described above.
[0096] 2) Traceability Unit: Implements a fine-grained and accountability-based access control mechanism. This method tracks key misuse by data users, preventing malicious users from possessing the attribute sets of legitimate users. The cross-domain path primarily records the process of cross-domain requests. It records the request path generated after the domain administrator and cross-domain center verify the legitimacy of the request and implement access control policies on the resource side. This becomes crucial information for the domain administrator to verify cross-domain requests and trace their origins. The domain administrator can use the cross-domain path and tracing key to conduct forensic analysis of cross-domain request behavior. The algorithm settings, encryption, and decryption definitions in the traceability scheme are the same as the basic CP-ABE definition. Traceability Scheme:
[0097] 1.
[0098] AA runs this algorithm to generate attribute keys. The algorithm takes PK, MK, ID, and L as input and returns SK. ID,L This serves as the key corresponding to ID and L.
[0099] 2.
[0100] The tracking algorithm can be run on any server. Input PK and attribute key SK. ID,L Then, the algorithm first checks SK. ID,L Is this correct? If SK ID,L Being correct means it can be used in a correct decryption process; the algorithm outputs an ID, representing SK. ID,L Link to ID. Otherwise, it outputs T, representing SK. ID,L If invalid, it does not need to be traced. If the master key is involved, the algorithm defines accountability accordingly.
[0101] 3.
[0102] This is an interactive protocol between users with identity IDs and auditors. When the system uses the tracking key SK... ∗ ID,L When a user is identified as malicious, the user enters (PK, SK). ID,L ) and auditor input (PK, SK) ∗ ID,L ), and determine whether the user is malicious. Specific Implementation Method Two:
[0104] like Figure 4The illustration shows a specific embodiment of a cross-domain data delegation access control method. It is a dual-domain access control system where a supplier and an equipment manufacturer operate within two different management domains. The collaboration between these two companies requires the sharing of relevant data, such as the quantity and inventory of supplied goods, and the demand and production volume of the equipment manufacturer. This information is sensitive; leakage would cause serious data security problems and economic losses. This method ensures the principle of least privilege for cross-domain data access between the supplier and equipment manufacturer, achieving security for cross-domain data sharing. Furthermore, it can also ensure efficient cross-domain data access control among multiple companies in a supply chain where data sharing and collaboration among multiple organizations are required.
[0105] The specific process for cross-domain data access control between suppliers and equipment manufacturers is as follows:
[0106] 1) The domain administrators of suppliers and equipment manufacturers register cross-domain related information in the cross-domain center, including their respective domain administrator information, their respective attribute information, key information, and the validity period of cross-domain access.
[0107] 2) Verify the legitimacy of the two domains based on the cross-domain certificates provided by the supplier and manufacturer, and verify the legitimacy of the supplier user (data owner) and manufacturer user (data user) based on the information provided by their respective domain administrators. If legitimate, add the user information involved in the cross-domain process to the cross-domain trusted list and proceed with the next step of cross-domain service.
[0108] Cross-domain certificates include: Vendor ID o Manufacturer User ID u Access operations, cross-domain paths, request validity periods, relevant context information, domain-related information, and the domain administrator's digital signature.
[0109] 3) Based on the information provided by the registered domain, the cross-domain center extracts all attribute information for suppliers and manufacturers in each domain. Attribute information is represented in the format {attribute name: attribute value space}. Different attributes of suppliers and manufacturers are represented by vectors, and related attribute value spaces are bound to them. Feature extraction is performed using word vectors.
[0110] Supplier attribute information includes {Name: Full Name}, {Gender: Male / Female}, {Age: 18-100}, {Position: Employee / Manager / Senior Manager / General Manager / Chairman, etc.}, {Job Role: Security Manager / Receptionist / Technician / Accountant, etc.}, {Group: Technical Group / Project Group / Product Group, etc.}, {Level: 1 / 2 / 3 / 4}, {Email: Email Address}; Equipment manufacturer attribute information includes {Name: Full Name}, {Gender: Male / Female}, {Age: 18-80}, {Title: Employee, Manager, Director, CEO, COO, President, Vice President, etc.}, {Role: Technician / System Analyst / Security Administrator / System Administrator / Secretary / Accountant / Product Manager, etc.}, {Department: Technical Department / Security Department / Product Department, etc.}, {Security Level: P1 / P2 / P3 / P5}, {Email: Email Address};
[0111] 4) The cross-domain center extracts cross-domain access request information from the cross-domain certificate for the device manufacturer user (data user). This cross-domain request information includes: {Manufacturer User ID: Alice; Role: Product Manager; Department: Product Department; Security Level: P5, etc.}
[0112] 5) The cross-domain center performs rule mapping on cross-domain requests from manufacturer users, mapping them to the relevant attribute names and attribute value spaces of suppliers in the model. It generates new cross-domain access request information and sends this new information to the manufacturer user.
[0113] 6) Manufacturer users need to carry the credentials issued by the cross-domain center to conduct cross-domain negotiations with supplier users (negotiating key issuance and other information).
[0114] 7) The supplier user designs the access control tree shown in the figure for the resources and performs multi-authority traceable attribute encryption on the resources. In a distributed environment, there are different attribute servers, therefore multiple Access Controllers (AAs) are possible. k This access control tree indicates that only product managers with a security level of P5 can access a certain resource.
[0115] 8) The manufacturer user calculates an attribute key based on the new cross-domain request calculated by the cross-domain center (the manufacturer user's attribute information satisfies the access control tree designed by the supplier), and uses the attribute key to decrypt cross-domain data resources. The supplier uses a tracing algorithm to determine whether it is a legitimate decryption process, uses an auditing method to determine whether it is a malicious user, and uses the cross-domain path provided by the cross-domain center to achieve source tracing (in this example, the cross-domain path is manufacturer user -> cross-domain center -> supplier user).
[0116] In summary, this invention utilizes machine learning techniques and attribute-based encryption access control to design a rule mapping mechanism and a cross-domain encryption mechanism, achieving cross-domain data access control suitable for large-scale dynamic industrial internet environments. This invention proposes a cross-domain registration and authentication scheme to authenticate the legitimacy of cross-domain requests, a rule mapping scheme using NLP technology for cross-domain rule mapping to provide a security foundation for cross-domain data access, and a cross-domain encryption scheme optimizing CP-ABE to achieve multi-permission traceable cross-domain data encryption and decryption. The key technical points of this invention are as follows:
[0117] Design of a cross-domain data access control system. This invention designs a cross-domain data access control system that utilizes machine learning technology and optimized attribute encryption technology to ensure the security of cross-domain data access in large-scale dynamic environments.
[0118] Cross-domain authentication mechanism. This invention designs a cross-domain authentication mechanism to ensure the legitimacy of cross-domain transactions. This mechanism uses a cross-domain center to verify the legitimacy of participants in cross-domain data sharing, constructs cross-domain attribute information, generates cross-domain paths, and provides security protection for cross-domain data sharing.
[0119] Cross-domain rule mapping mechanism. The cross-domain rule mapping mechanism proposed in this invention utilizes NLP technology to extract attribute information features and train an attribute model, achieving high-efficiency cross-domain attribute information mapping, solving the heterogeneity problem of cross-domain data management, reducing the performance impact of cross-domain mapping, and improving the reliability of cross-domain mapping.
[0120] A multi-authority traceable cross-domain encryption scheme. This invention proposes a multi-authority traceable cross-domain encryption scheme that ensures the confidentiality and integrity of data access across domains. This scheme optimizes the traditional CP-ABE scheme, proposes a tracking key algorithm and a cross-domain auditing method, and utilizes cross-domain paths to achieve multi-attribute authorization for distributed environments, while simultaneously enabling traceability of cross-domain data access.
[0121] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
Claims
1. A method for cross-domain data access control, characterized in that, The method includes: S1. First, all domains that need to share data across domains register their information at the cross-domain center. S2. Based on the cross-domain certificate, check whether all domains participating in cross-domain data sharing are legitimate, and verify the legitimacy of data owners and data users based on the information provided by the domain administrator. Each authentication requires the digital signatures of the domain administrator and the cross-domain center. S3. The cross-domain center extracts all attribute information of each domain based on the information provided by the registered domain, and uses vectors to represent different attributes of different domains, binds the correlation of attribute value space, and constructs the model; specifically: based on the information provided by the registered domain, it extracts the attribute information of each domain, classifies and labels them, classifies attribute types into static attributes and dynamic attributes, and uses vectors to represent attributes according to different domains and different types. S4. The cross-domain data center extracts cross-domain access request information from the cross-domain certificate. The cross-domain request information includes the data user's identity information and the relevant attribute information of the accessed resources. S5. The cross-domain center performs rule mapping on cross-domain requests, mapping the attributes and attribute value spaces of the domain where the data user is located and the domain where the data owner is located, generating new cross-domain access request information, and sending the new cross-domain access request information to the data user. S6. Data owners and data users conduct cross-domain negotiations. At this time, data users need to bring the credentials issued by the cross-domain center. S7. The data owner designs an access control tree for the resource and performs attribute encryption based on multi-permission traceability; specifically: 1) The initial setup algorithm is run by CA; input Then, the algorithm returns (pk) k ,sk k ) as AA k It outputs a public key pair, and also outputs PK and MK, where PK is publicly released and MK is secretly maintained by the CA; 2) Attribute key generation algorithm, by AA s Run; after entering PK, AA k key sk k A user's global identity (GID) and the property server AA k List of managed attributes L (k) The algorithm output is the same as L. (k) The corresponding key SK L(k) If the user's GID attribute list is L={L (k) } k∈I SK L ={SK L(k) } k∈I As the attribute key, where I represents AA s The index set, whose attribute fields include user attributes; 3) The central key generation algorithm, which will be run by the CA, outputs SKC as the central key for the user's GID after inputting PK, MK, and GID. S8. The data user obtains an attribute key set based on the new cross-domain request calculated by the cross-domain center, and uses the attribute keys to decrypt the cross-domain data resource; the resource end of the data resource uses a tracking algorithm to determine whether it is a legitimate decryption process, the data resource auditing method is used to determine whether it is a malicious user, and the cross-domain path of the data resource is used to achieve source tracing; Source tracing scheme: 1) AA runs this algorithm to generate attribute keys; the algorithm takes PK, MK, ID, and L as input and returns SK. ID,L As the key corresponding to ID and L; 2) The tracking algorithm can be run by any server; input PK and attribute key SK. ID,L Then, the algorithm first checks SK. ID,L Is this correct? If SK ID,L Being correct means it can be used in a correct decryption process; the algorithm outputs an ID, representing SK. ID,L Link to ID; otherwise, it outputs T, representing SK. ID,L If invalid, it does not need to be traced; if the master key is involved, the algorithm defines accountability accordingly. 3) This is an interactive protocol between users with identity IDs and auditors; when the system uses the tracking key SK... ∗ ID,L When a user is identified as malicious, the user enters (PK, SK). ID,L ) and auditor input (PK, SK) ∗ ID,L ), and determine whether the user is malicious.
2. The cross-domain data access control method according to claim 1, characterized in that, The information mentioned in step S1 includes domain-related information, attribute information, key information, and the validity period of cross-domain data sharing.
3. The data cross-domain access control method according to claim 1, characterized in that, In step S2, the legitimacy of the data owner and data user is verified based on the information provided by the domain administrator. If they are legitimate, the next cross-domain request is allowed to be processed, and the information of the data user and data owner is added to the cross-domain trusted list. If it is illegal, inform the data user of the relevant issues and refuse to provide cross-domain services to them; When the cross-domain center receives information about a registered domain, it first searches the cross-domain trusted list. If the domain exists, it directly provides cross-domain services; otherwise, it performs legitimacy authentication.
4. The cross-domain data access control method according to claim 1, characterized in that, The information for cross-domain negotiation between the data owner and the data user in step S6 includes the negotiation key algorithm; the credential is used to verify the authenticity of the identity.
5. A cross-domain data access control system, characterized in that, The system includes a cross-domain initialization module, a rule mapping module, and a cross-domain encryption module; The cross-domain initialization module is used to authenticate the identities of cross-domain data owners and users and to ensure the legitimacy of all parties involved in cross-domain data sharing. It includes an information registration unit and an authentication and testing unit; Information Registration Unit: The domains where data owners and data users reside register cross-domain related information with the cross-domain center, and register all domains that share data across domains; The system verifies the legitimacy of all domains involved in cross-domain data sharing and uses cross-domain certificates to verify the legitimacy of data owners and users. Each authentication requires a digital signature from the cross-domain node. The mapping module is used to map attribute names and attribute value spaces within each domain; it includes model units, learning units, and storage units. Model Unit: Based on the information provided by the registered domain, extract the attribute information of each domain, classify and label them, classify the attribute types into static attributes and dynamic attributes, and use vector representation for attributes according to different domains and types; Learning Unit: The cross-domain center extracts attribute information of cross-domain access requests from data users, extracts attribute features through natural language processing, trains attribute models using machine learning, and maps them to the attributes of data owners; Storage unit: The storage mechanism stores the attribute names and attribute value spaces that have been successfully mapped across domains in a mapping table, and uses sparse matrix storage technology to directly map the same cross-domain request the next time. The cross-domain encryption module is used to encrypt data with multiple permissions and traceability; it includes a multi-attribute permission unit and a traceability unit. Multi-attribute permission unit: Implements a fine-grained and distributed access control mechanism; utilizes multi-attribute permission encryption technology to generate attribute key strings based on multiple permissions. 1) The initial setup algorithm is run by CA; input Then, the algorithm returns. (pk) k ,sk k ) As AA K It outputs a public key pair, and also outputs PK and MK, where PK is publicly released and MK is secretly maintained by the CA; 2) Attribute key generation algorithm, by AA s Run; after entering PK, AA k key sk k A user's global identity (GID) and the property server AA k List of managed attributes L (k) The algorithm output is the same as L. (k) The corresponding key SK L(k) If the user's GID attribute list is L={L (k) } k∈I SK L ={SK L(k) } k∈I As the attribute key, where I represents AA s The index set, whose attribute fields include user attributes; 3) The central key generation algorithm, which will be run by the CA, outputs SKC as the central key for the user's GID after inputting PK, MK, and GID. Tracing and attribution unit: Implements fine-grained and accountability-based access control mechanisms; Traceability and source identification solution: 1) AA runs this algorithm to generate attribute keys; the algorithm takes PK, MK, ID, and L as input and returns SK. ID,L As the key corresponding to ID and L; 2) The tracking algorithm can be run by any server; input PK and attribute key SK. ID,L Then, the algorithm first checks SK. ID,L Is this correct? If SK ID,L Being correct means it can be used in a correct decryption process; the algorithm outputs an ID, representing SK. ID,L Link to ID; otherwise, it outputs T, representing SK. ID,L If invalid, it does not need to be traced; if the master key is involved, the algorithm defines accountability accordingly. 3) This is an interactive protocol between users with identity IDs and auditors; when the system uses the tracking key SK... ∗ ID,L When a user is identified as malicious, the user enters (PK, SK). ID,L ) and auditor input (PK, SK) ∗ ID,L ), and determine whether the user is malicious.
6. A cross-domain data access control system according to claim 5, characterized in that, The cross-domain certificate includes: Data Owner ID o Data User ID u Access operations, cross-domain paths, request validity periods, relevant context information, domain-related information, and the domain administrator's digital signature.