A method and system for attribute mapping based on cross-domain access control

By introducing deep learning technology into cross-domain access control, a fine-grained and dynamic attribute mapping method is designed, which solves the problems of high performance consumption and poor flexibility of the existing technology in large-scale data cross-domain access scenarios, and achieves efficient and secure cross-domain access control.

CN116318931BActive Publication Date: 2025-06-06GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310207409.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-06
Publication Date
2025-06-06
Estimated Expiration
2043-03-06

AI Technical Summary

Technical Problem

The existing cross-domain access control methods have problems such as high performance consumption, high workload and poor flexibility in large-scale data cross-domain access scenarios, especially the mapping methods based on third-party trusted centers and edge computing have insufficient performance and security.

Method used

A deep learning-based attribute mapping method is designed, which uses deep learning clustering to perform attribute mapping through trusted center authentication and negotiation of cross-domain request attributes, and reduces computing resource consumption through static and dynamic storage mechanisms to achieve fine-grained, dynamic and efficient attribute mapping.

Benefits of technology

It realizes the security and efficiency of large-scale data cross-domain access, reduces the performance consumption and workload of attribute mapping, meets the dynamic attribute mapping requirements, and is suitable for large-scale data cross-domain interaction scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318931B_ABST
    Figure CN116318931B_ABST
Patent Text Reader

Abstract

The present invention proposes an attribute mapping method and system based on cross-domain access control, which belongs to the field of cross-domain access control. The system consists of a cross-domain authentication module, an attribute mapping module and a mapping storage module. The cross-domain authentication module authenticates each management domain participating in cross-domain data sharing in a trusted center, and negotiates the attribute information that must be carried by participating in the cross-domain, ensuring the legitimacy of the cross-domain parties and attributes, etc. The attribute mapping module mainly formulates the relevant mapping methods of attribute names and attribute value spaces to achieve fine-grained and dynamic attribute mapping and efficient attribute mapping. The mapping storage module reduces the consumption of attribute mapping computing resources and reduces the time cost of attribute mapping. Fine-grained dynamic cross-domain access control is achieved through a new attribute mapping method; the consumption of resources in attribute mapping is reduced, the efficiency and performance of the attribute mapping mechanism are improved, and large-scale cross-domain access is achieved; the attribute mapping method is optimized to achieve a multi-domain dynamic attribute mapping mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cross-domain access control, and in particular relates to an attribute mapping method and system based on cross-domain access control. Background Art

[0002] In recent years, my country's information technology industry has developed rapidly, realizing a new situation of the Internet of Everything. In the scenario of the Internet of Everything, through the comprehensive connection of users and data resources, we have entered a big data society of information sharing, accelerated the digital development of the manufacturing industry, realized networking and intelligent reforms, and improved the efficiency of social information services. To achieve interconnected information sharing, it is necessary to strengthen cooperation among organizations. For example, in the industrial Internet, data sharing among enterprises is required to realize the digital intelligence of the industrial chain. In smart cities, data sharing among government departments, banks, enterprises and other institutions is required to realize efficient information services. When organizations cooperate to share data, in order to ensure the confidentiality and integrity of data resources, each organization has its own management domain to establish security management specifications for communication between data owners and data users.

[0003] However, the management domains of each organization are independent of each other and have different access management mechanisms. In the real environment, there are situations where data users and data owners are no longer in the same domain. In this case, the data owner cannot authenticate the data user information or the security management of the source domain fails, that is, it is impossible to achieve secure cross-domain data interaction. Therefore, a cross-domain access control mechanism has emerged to achieve secure data interaction between data users and data owners in different management domains. The cross-domain access control security mechanism is an extension of the single-domain access control security mechanism. It solves the heterogeneity of access policies and models in different management domains and is also the main way to achieve secure cross-domain data sharing. The current cross-domain access control mechanism is mainly based on the extension of RBAC, ABAC and attribute encryption access control methods. These access control methods are very mature and have been widely used in resource access scenarios. The core of this cross-domain access control method is the mapping mechanism, which maps roles, attributes and access policies between different domains to achieve cross-domain data communication.

[0004] At present, some methods based on cross-domain attribute mapping have been proposed. Although these methods can achieve cross-domain access control, they are still lacking. The existing cross-domain mapping methods are mainly divided into the following three types: The first is a mapping method based on a third-party trusted center, which mainly implements the mapping mechanism through a standard library. The standard library implements a one-to-one mapping of roles and attributes between different domains. The second is a mapping mechanism based on edge computing. By using edge computing or user agents, the domain where the data owner is located calculates the access policy based on the data user attribute list. The third is a mapping mechanism based on joint attributes. Each domain for cross-domain data interaction formulates standard attributes, and the attributes of all resource requests are mapped in their respective domains based on the standard attributes.

[0005] However, the prior art has the following deficiencies:

[0006] The existing mapping mechanism based on a third-party trusted center has many limitations. One of the most important limitations is the construction of a standard mapping library. If one-to-one mapping is performed for roles or attributes of multiple domains, there will be multiple mapping libraries and multiple mapping tables. When this method handles large-scale mapping, it increases the performance consumption of the cross-domain process, increases the workload and reduces the mapping efficiency. This standard library method is only suitable for cross-domain mapping involving a few domains, and is not suitable for large-scale, dynamic cross-domain data access.

[0007] The existing edge computing-based mapping method is limited by performance. First, there is a risk of man-in-the-middle attack when sending the attribute list of the data user to the domain where the data owner is located. Secondly, the domain where the data owner is located needs to calculate the corresponding access policy based on the attribute list of all data users. This process undoubtedly increases the calculation amount of the data owner, consumes a lot of computing resources, has a great impact on the performance of the cross-domain system, and has the risk of denial of service.

[0008] There are some problems in the existing mapping mechanism based on joint attributes. In this mechanism, all parties that support cross-domain data formulate a joint attribute (standard attribute), and each domain maps its own attribute to the standard attribute, and finally performs cross-domain access according to the standard attribute. There are links such as negotiation, production, issuance, and revocation of standard attributes, which increase the computational complexity of each domain and pose security risks. The joint attributes designed in this method do not take into account the dynamic nature of the attributes, which will limit the flexibility of cross-domain access and are not suitable for dynamic access control requirements. Summary of the invention

[0009] The purpose of the present invention is to provide an attribute mapping method and system based on cross-domain access control, to realize fine-grained dynamic cross-domain access control through a new attribute mapping method; to reduce the consumption of resources in attribute mapping, to improve the efficiency and performance of the attribute mapping mechanism, to realize large-scale cross-domain access; to optimize the attribute mapping method, to realize a multi-domain dynamic attribute mapping mechanism.

[0010] In order to achieve the above object, in a first aspect of the present invention, a method for attribute mapping based on cross-domain access control is provided, the method comprising:

[0011] S201: The trusted center authenticates the legitimacy of all management domains participating in cross-domain data sharing. Each management domain carries a certificate and management domain related information to register with the trusted center. If the trusted center verifies that the management domain is legitimate, it will issue an authentication identifier.

[0012] S202: The domains participating in cross-domain data sharing negotiate with the trusted center on the cross-domain request attributes that must be carried;

[0013] S203: Formulate mapping rules and match the identifier of the request attribute, and select a mapping method according to the identified attribute level;

[0014] S204: using deep learning clustering, one-to-one mapping is performed for attribute names, and weight calculation, filling calculation and formatting re-mapping are performed for attribute values;

[0015] S205: After the trusted center generates a new cross-domain attribute certificate through attribute mapping, it sends it to the data user. The data user compares the new attribute certificate with the old attribute and generates an attribute static storage table; if the static mapping table expires or does not meet the validity period conditions, it is deleted, otherwise the static mapping takes effect; for subsequent cross-domain access, the valid static table is checked for attribute mapping; if the mapping is successful, the cross-domain access is directly performed, if the mapping fails, jump back to step S204;

[0016] S206: The trusted center dynamically stores the attribute mapping results, dynamically updates the corresponding attribute mapping table based on the authentication identifiers of each domain and the changes in the cross-domain request attributes, and sets an expiration condition for the dynamic mapping table. Subsequent cross-domain access requests to the trusted center will first query the dynamic mapping table. If the query is unsuccessful, return to step S204 for mapping.

[0017] Furthermore, the identifier is unique and implements integrity verification.

[0018] Furthermore, the cross-domain request attributes include a data owner domain ID, a data manager domain ID, a source domain signature, and a trusted identifier.

[0019] In a second aspect of the present invention, there is provided an attribute mapping system based on cross-domain access control, comprising:

[0020] Cross-domain authentication module: used to authenticate each management domain participating in cross-domain data sharing in the trusted center, and negotiate the attribute information that must be carried by participating in cross-domain, to ensure the legitimacy of the cross-domain parties and attributes;

[0021] Attribute mapping module: used to achieve fine-grained and dynamic attribute mapping and high-efficiency attribute mapping;

[0022] Mapping storage module: used to reduce the consumption of attribute mapping computing resources and reduce the time cost of attribute mapping.

[0023] Further, the cross-domain authentication module includes a cross-domain registration unit and an attribute authentication unit;

[0024] The attribute mapping module includes a mapping rule formulation unit and a deep learning mapping unit;

[0025] The mapping storage module includes a static storage unit and a dynamic storage unit.

[0026] Furthermore, the cross-domain registration unit is used to ensure that the attributes acquired by the attribute owner and the trusted center are credible;

[0027] The attribute authentication unit is used to normalize the cross-domain attribute information that must be carried in the request, thereby increasing the security of cross-domain access.

[0028] Furthermore, the mapping rule making unit is used to set the level of attribute mapping using the identifier, and set a mark for both the attribute name and the attribute value, and the mark distinguishes the mapping rule;

[0029] The deep learning mapping unit is used to perform attribute mapping according to the specified mapping rules, and needs to match the corresponding markers to complete two mappings.

[0030] Furthermore, the mapping rules include: 1. mapping of attribute names; 2. mapping of attribute value spaces with uniqueness; 3. mapping of attribute value spaces with dynamicity; 4. mapping of attribute value spaces with trustworthy indicators;

[0031] The attribute value space includes position, level and role;

[0032] The two mappings are specifically: the first one is a one-to-one mapping for attribute names, and the second one is a mapping for attribute value space.

[0033] Furthermore, the static storage unit is used to statically store the attribute mapping results of the trusted center to the data user management domain, and set the expiration time and expiration conditions of the static table. If the conditions are met, the management domain deletes the static mapping table. If the static mapping table is valid, the data user will first map from the static table when making a cross-domain request.

[0034] Furthermore, the dynamic storage unit is used to realize dynamic storage of the trusted center, construct a dynamic mapping storage table based on the attribute mapping results and set the invalidation conditions, and dynamically update the storage table through the attribute mapping of different cross-domain access requests. When the subsequent trusted center receives a cross-domain request, it first searches the dynamic mapping table for the mapping result, and then performs regular mapping based on the level of the mark.

[0035] The beneficial technical effects of the present invention are at least as follows:

[0036] (1) Implement large-scale attribute mapping to ensure the security of cross-domain access control:

[0037] The mapping mechanism is the core of realizing cross-domain access control of data. The access control policies of different management domains are authenticated by mapping roles or attributes, thereby solving the heterogeneity problem of management domain access control policies. The current mapping mechanism is mainly implemented by using standard libraries. This technology mainly sets mapping rules manually. The mutual mapping of attributes between multiple domains greatly increases the workload and reduces the mapping efficiency. Therefore, it is not suitable for large-scale cross-domain access. In addition, the mapping based on the standard library may have inaccurate mapping rules, resulting in loopholes in the access control mechanism. The present invention designs an attribute mapping method for cross-domain access control, which realizes accurate cross-domain attribute mapping and ensures the security of cross-domain access control. At the same time, the attribute mapping method based on deep learning designed by the present invention improves the efficiency of attribute mapping and meets the needs of large-scale data cross-domain access scenarios.

[0038] (2) Implement an efficient attribute mapping mechanism and reduce the performance consumption of attribute mapping:

[0039] Implementing mapping calculations in each management domain consumes a lot of computing resources. When multiple domains participate in cross-domain data access, it is necessary to send the attribute list of the access domain, and the domain manager maps the new attributes of the accessed domain based on each attribute list. In the scenario of a large number of cross-domain requests, sending attribute lists and attribute mapping calculations increase the performance consumption of the attribute mapping mechanism. The present invention designs a cross-domain attribute mapping mechanism based on a third-party trusted center, which reduces the amount of calculation in each management domain, reduces the consumption of attribute mapping resources and performance, and realizes a highly efficient attribute mapping mechanism.

[0040] (3) Implement fine-grained and flexible attribute mapping to meet dynamic attribute mapping requirements:

[0041] At present, the attribute mapping method is mainly implemented by mapping the attribute names of each domain, and using the constructed standard library mapping. This method has the problem of coarse granularity and inflexible mapping. The cross-domain access attribute mapping method designed by the present invention realizes fine-grained cross-domain attribute mapping through the dual-dimensional mapping of attribute name and attribute value space. The mapping method based on attribute level designed by the present invention meets the flexible and dynamic attribute mapping requirements by formulating the mapping rules of attribute information. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The present invention is further described using the accompanying drawings, but the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative work.

[0043] Figure 1 The present invention is a flow chart of an attribute mapping method based on cross-domain access control.

[0044] Figure 2This is a schematic diagram of an attribute mapping system based on cross-domain access control according to the present invention.

[0045] Figure 3 The present invention provides a specific embodiment of an attribute mapping method based on cross-domain access control. DETAILED DESCRIPTION

[0046] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.

[0047] Embodiment 1, as Figure 1 As shown, the present invention provides an attribute mapping method based on cross-domain access control, the method comprising:

[0048] S201: The trusted center authenticates the legitimacy of all management domains participating in cross-domain data sharing. Each management domain registers with the trusted center with a certificate and management domain related information. If the trusted center verifies that the management domain is legitimate, it will issue an authentication identifier (the identifier is unique and implements integrity verification).

[0049] S202: The domains participating in cross-domain data sharing negotiate with the trusted center on the cross-domain request attributes that must be carried (data owner domain ID, data manager domain ID, source domain signature, trusted identification, and other information).

[0050] S203: Formulate mapping rules and match the identifier of the request attribute, and select a mapping method according to the identified attribute level.

[0051] S204: Using deep learning clustering, one-to-one mapping is performed for attribute names, and weight calculation, filling calculation, formatting and re-mapping are performed for attribute values.

[0052] S205: After the trusted center generates a new cross-domain attribute certificate through attribute mapping, it is sent to the data user. The data user compares the new attribute certificate with the old attribute to generate an attribute static storage table. If the static mapping table expires or does not meet the validity period conditions, it is deleted, otherwise the static mapping takes effect. For subsequent cross-domain access, first check the valid static table for attribute mapping. If the mapping is successful, cross-domain access is performed directly. If the mapping cannot be performed, jump back to step S204.

[0053] S206: The trusted center dynamically stores the attribute mapping results, dynamically updates the corresponding attribute mapping table according to the changes in the authentication identifier and attribute information of each domain, and sets an invalidation condition for the dynamic mapping table. Subsequent cross-domain access requests to the trusted center first query the dynamic mapping table. If the query is unsuccessful, return to step S204 for mapping.

[0054] like Figure 2 As shown, in the second aspect of the present invention, an attribute mapping system based on cross-domain access control is provided, a new attribute mapping mechanism is designed, and high-efficiency, fine-grained, and dynamic attribute mapping is realized to meet the cross-domain access control requirements in large-scale data cross-domain interaction scenarios. The method consists of three modules: a cross-domain authentication module, an attribute mapping module, and a mapping storage module. Among them, 1) the cross-domain authentication module includes cross-domain registration and attribute authentication. Each management domain participating in cross-domain data sharing is authenticated in a trusted center, and the attribute information that must be carried by participating in cross-domain is negotiated to ensure the legitimacy of cross-domain parties and attributes. 2) The attribute mapping module mainly includes the formulation of mapping rules and deep learning mapping mechanisms. The mapping rules formulate the relevant mapping methods of attribute names and attribute value spaces to achieve fine-grained and dynamic attribute mapping, and the deep learning mapping mechanism realizes efficient attribute mapping. 3) The mapping storage module includes dynamic storage and static storage methods to reduce the consumption of attribute mapping computing resources and reduce the time cost of attribute mapping.

[0055] Cross-domain authentication module:

[0056] Cross-domain registration unit: All parties across domains register the information of each management domain in the trusted center, and the trusted center verifies the legitimacy of each domain based on the authentication information. This ensures that the attributes obtained by the attribute owner and the trusted center are credible. Legitimacy authentication is the basis for the security of cross-domain attribute mapping.

[0057] Attribute authentication unit: The trusted center negotiates with all cross-domain parties on the attribute information that must be carried in the cross-domain access request (information on the management domain where the data owner and the data user are located, as well as the authentication ID of the trusted center, etc.), standardizes the cross-domain attribute information that must be carried in the request, and increases the security of cross-domain access.

[0058] Attribute Mapping Module:

[0059] Mapping rule formulation unit: Use identifiers to set the level of attribute mapping, set tags for both attribute names and attribute values, and the tags mainly distinguish the following mapping rules: a. Mapping of attribute names; b. Mapping of attribute value spaces with uniqueness (user ID and other information); c. Mapping of attribute value spaces with dynamicity (context attribute information); d. Mapping of attribute value spaces with trusted indicators (position, level, role and other information), etc.

[0060] Deep learning mapping unit: Attribute mapping is performed according to the specified mapping rules. It is necessary to match the corresponding markers to complete two mappings. The first is a one-to-one mapping for the attribute name, and the second is a mapping for the attribute value space (including weight calculation). The mapping method uses deep learning clustering technology to extract the word vector of each attribute information, and uses a deep learning network and clustering algorithm, where the total loss is the sum of the network loss and the clustering loss, to deeply cluster and map the attribute information. This method improves the efficiency and performance of a large number of attribute mappings, and is suitable for large-scale dynamic cross-domain access data scenarios.

[0061] Through the neural network, the data x i Mapped to feature z i , use z i Do clustering and at the same time for feature z i Iterative update, the corresponding network loss function is as follows:

[0062]

[0063] g w' :z i →x' i

[0064] where x i is the data, z i is x i The embedded points in the low-dimensional feature space are effective feature representations of the input samples. i Clustering, x' i is x i The reconstructed samples after the decoder are used to reset the loss. The purpose of designing the reconstructed samples is to ensure the representativeness of the embedded space features and make the embedded points more suitable for the clustering task, so as to obtain the optimal clustering result. w' For z i to x' i 's mapping.

[0065] This method designs the encoder and decoder, trains the autoencoder through reconstruction loss, completes the data representation of the data through nonlinear mapping to the latent feature space, and uses the data representation, i.e., features, as the input of the clustering module. After that, the network is fine-tuned using the clustering assignment reinforcement loss, while iteratively improving the clustering.

[0066] Mapping storage module:

[0067] Static storage unit: statically stores the attribute mapping results of the trusted center to the data user management domain, and sets the expiration time and expiration conditions of the static table. If the conditions are met, the management domain deletes the static mapping table. If the static mapping table is valid, the data user will first map from the static table when making a cross-domain request. This design of storing the mapping table on the data user side can save the time of attribute mapping, thereby improving the efficiency of cross-domain access.

[0068] Dynamic storage unit: The trusted center implements dynamic storage, builds a dynamic mapping storage table based on the attribute mapping results, and sets the invalidation condition. The storage table is dynamically updated through the attribute mapping of different cross-domain access requests. When the trusted center receives a cross-domain request, it first searches for the mapping result from the dynamic mapping table, and then performs regular mapping based on the level of the tag. This design reduces the computing resource consumption of the trusted center and improves the efficiency of attribute mapping.

[0069] Embodiment 2:

[0070] like Figure 3 It is a specific implementation example of the attribute mapping method for cross-domain access control. It is a multi-domain access control system. The supplier enterprise, the manufacturer enterprise, and the logistics enterprise are in three different management domains. The three enterprises need to share some data for effective collaboration. For example, information such as the inventory of goods of the supplier enterprise and the output of the equipment manufacturer are all sensitive data, involving corporate secrets and corporate funds. If leaked, it will cause significant losses to the enterprise. Solving the data security problem requires a cross-domain access control security mechanism, but attribute mapping is the basis and is also crucial in cross-domain access control. The method in this article ensures the security of cross-domain access control by implementing secure attribute mapping. This method realizes the cross-domain access control requirements in a large-scale dynamic environment by implementing a fine-grained, dynamic, and efficient attribute mapping mechanism, and realizes efficient and secure cross-enterprise data interaction. The specific process of cross-domain attribute mapping for supplier enterprises, manufacturer enterprises, and logistics enterprises is as follows:

[0071] 1) Each enterprise participating in cross-domain access sends the management domain information (certificate information) to the trusted center, which verifies the legitimacy of the management domain of the supplier enterprise, manufacturer enterprise, and logistics enterprise. If it is legal, a management domain authentication mark is generated. If it is illegal, it cannot participate in cross-domain access.

[0072] 2) The domain managers of supplier enterprises, manufacturer enterprises, and logistics enterprises negotiate with the trusted center on necessary attribute information (domain ID, time, data owner ID, data user ID, etc.) and attribute levels.

[0073] 3) Each domain manager formulates attribute mapping rules and divides the attribute name and attribute value space of each domain into level identifiers according to the negotiated attribute level. The attribute list of each cross-domain request can be divided into four columns (attribute name level, attribute name, attribute value level, attribute value space).

[0074] For example, the cross-domain request attributes of the data user of the supplier enterprise are: {[name:xx]; [age:xx]; [uid:xxx]; [roal:xxx]; [level:xxx]; [evn:xxx]; [gid:xxx]; [time:x xx]...}. The attribute strategy of the data owner of the manufacturer enterprise is {[name:xxx]; [age:xx]; [user ID:xxx]; [position:xx]; [level:xxx]; [context:]; [time:];}. According to the attribute level classification, the class name, age, time, name, and age information are level a. This type of mapping attribute name formats the attribute value space without mapping the attribute value space; roal, level, position, and level are level d. The attribute value space of this type of trusted indicator needs to be mapped in combination with weight calculation.

[0075] 4) The trusted center maps the attributes of the cross-domain request according to the hierarchical identifier and uses the deep clustering algorithm to perform fine-grained mapping of the attribute name and attribute value space.

[0076] For example: the supplier's attribute list [level: 1-5], the manufacturer's attribute list [level: 1-9],

[0077] Attribute list of logistics enterprises [level: 1-3]; this type of attribute first calculates the weight before clustering. This type of attribute first identifies the attribute level and then maps it. The final result maps the supplier's level 3 to the manufacturer's level 5 and to the logistics enterprise's level 2.

[0078] 5) After the trusted center completes the mapping, it sends a new attribute certificate to the supplier's domain manager. The data user (supplier) uses the mapped attribute information to access the data owner (manufacturing industry). The data owner restricts the user's access to data resources based on the access control policy of its own management domain. The supplier's management domain generates a static storage table based on the old and new attributes. When the supplier's data user subsequently accesses the data owner across domains, the attribute mapping is first performed on the static table. If no result is found, the cross-domain request is sent to the trusted center for mapping (step 4).

[0079] 6) The trusted center stores the mapping results dynamically, and dynamically updates the storage table based on each mapping result. When the trusted center receives a cross-domain request within the validity period of the dynamic storage table, it first searches for the attribute mapping in the dynamic table. If the mapping result cannot be found, it jumps back to step 4. If the validity period of the dynamic table has expired, the cache can be cleared. In summary, the blockchain-based data controlled access method and system designed by the present invention realizes the trusted access control logic based on the blockchain, reliable and efficient data encryption and decryption, and a trusted private key distribution scheme, and realizes the trusted controlled access to data through the off-chain storage and on-chain identity authentication mechanism. The data visitor sends an access request, and the trusted verification of the visitor's identity information is realized through the access control logic based on the smart contract designed on the blockchain; after the visitor's identity information is successfully verified, the preset conditions of the smart contract will be triggered, and the encrypted private key and file location information will be sent to the visitor; the visitor then uses the pre-received shared private key to decrypt the user's private key, and then uses the private key to decrypt the file address to retrieve the file, and finally uses the user's private key to decrypt the retrieved file.

[0080] In summary, the present invention designs a fine-grained, dynamic and efficient attribute mapping method based on the idea of ​​trusted center attribute mapping, and utilizes the technology of deep learning attribute mapping to realize an access control security mechanism suitable for large-scale data cross-domain interaction. The present invention designs a cross-domain authentication method to ensure the security of the attribute mapping mechanism. The trusted center authenticates the legitimacy of each management domain, generates an authentication identifier for the legal domain, and performs attribute negotiation and authentication to ensure that the attributes obtained by the attribute owner and the trusted center are credible, thereby ensuring the security of the attribute mapping mechanism. A deep clustering attribute mapping mechanism is designed, and the deep subspace clustering algorithm can make full use of the powerful feature extraction ability of the neural network, use more discriminative features to find more accurate subspaces, complete accurate attribute clustering, and realize efficient attribute mapping. At the same time, this attribute mapping method can cope with flexibly changing attribute information and can realize dynamic attribute mapping. A mapping method based on attribute level is designed to hierarchically divide the attribute name and attribute value space to realize fine-grained attribute mapping. Static and dynamic storage methods for attribute mapping are designed. The static mapping storage table is stored in the data user domain, and the dynamic mapping storage table is stored in the trusted center. An effective caching mechanism is used to improve the efficiency of attribute mapping. There is no need to manage domain calculations to reduce the consumption of mapping computing resources.

[0081] Although embodiments of the present invention have been shown and described, those skilled in the art will appreciate that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

Claims

1. A method for attribute mapping based on cross-domain access control, It is characterized in that The method comprises: S201: The trusted center authenticates the legitimacy of all management domains participating in cross-domain data sharing. Each management domain carries a certificate and management domain related information to register with the trusted center. If the trusted center verifies that the management domain is legitimate, it will issue an authentication identifier. S202: The domains participating in cross-domain data sharing negotiate with the trusted center on the cross-domain request attributes that must be carried; S203: Formulate mapping rules and match the identifiers of the requested attributes, select a mapping method according to the attribute level of the identifier, and set tags for both the attribute name and the attribute value using the attribute level of the identifier, wherein the tags distinguish the mapping rules; S204: Utilize deep learning clustering to perform one-to-one mapping for attribute names, perform weight calculation, fill calculation and formatting re-mapping for attribute values, perform attribute mapping according to specified mapping rules, and need to match corresponding identifiers to complete two mappings. The mapping rules include: (1) mapping of attribute names; (2) mapping of attribute value spaces with uniqueness; (3) mapping of attribute value spaces with dynamicity; (5) mapping of attribute value spaces with trustworthy indicators; the attribute value spaces include positions, grades and roles; the two mappings are specifically: the first is a one-to-one mapping for attribute names, and the second is a mapping for attribute value spaces; S205: After the trusted center generates a new cross-domain attribute certificate through attribute mapping, it sends it to the data user. The data user compares the new attribute certificate with the old attribute to generate an attribute static storage table; if the static storage table expires or does not meet the validity period conditions, it is deleted, otherwise the static mapping takes effect; for subsequent cross-domain access, the valid static storage table is checked for attribute mapping; if the mapping is successful, the cross-domain access is performed directly, and if the mapping fails, it jumps back to step S204; S206: The trusted center dynamically stores the attribute mapping results, dynamically updates the corresponding dynamic mapping table according to the authentication identifiers of each domain and the changes in the cross-domain request attributes, and sets an expiration condition for the dynamic mapping table. Subsequent cross-domain access requests to the trusted center will first query the dynamic mapping table. If the query is unsuccessful, return to step S204 for mapping.

2. According to claim 1, a method for attribute mapping based on cross-domain access control, It is characterized in that The identifier is unique and integrity-verified.

3. According to claim 1, a method for attribute mapping based on cross-domain access control, It is characterized in that The cross-domain request attributes include a data owner domain ID, a data manager domain ID, a source domain signature, and a trusted identifier.

4. An attribute mapping system based on cross-domain access control, used to implement the method of claim 1, It is characterized in that include: Cross-domain authentication module: used to authenticate each management domain participating in cross-domain data sharing in the trusted center, and negotiate the attribute information that must be carried by participating in cross-domain, to ensure the legitimacy of the cross-domain parties and attributes; Attribute mapping module: used to achieve fine-grained and dynamic attribute mapping and high-efficiency attribute mapping; Mapping storage module: used to reduce the consumption of attribute mapping computing resources and reduce the time cost of attribute mapping.

5. According to claim 4, an attribute mapping system based on cross-domain access control, It is characterized in that The cross-domain authentication module includes a cross-domain registration unit and an attribute authentication unit; The attribute mapping module includes a mapping rule formulation unit and a deep learning mapping unit; The mapping storage module includes a static storage unit and a dynamic storage unit.

6. According to claim 5, an attribute mapping system based on cross-domain access control, It is characterized in that The cross-domain registration unit is used to ensure that the attributes acquired by the attribute owner and the trusted center are credible; The attribute authentication unit is used to normalize the cross-domain attribute information that must be carried in the request, thereby increasing the security of cross-domain access.

7. The attribute mapping system based on cross-domain access control according to claim 5, It is characterized in that The static storage unit is used to statically store the attribute mapping results of the trusted center to the data user management domain, and set the expiration time and expiration conditions of the static storage table. If the conditions are met, the management domain deletes the static storage table. If the static storage table is valid, the data user will first map from the static storage table when making a cross-domain request.

8. According to claim 5, an attribute mapping system based on cross-domain access control, It is characterized in that The dynamic storage unit is used to realize dynamic storage of the trusted center, build a dynamic mapping table based on the attribute mapping results and set the invalidation conditions, dynamically update the storage table through the attribute mapping of different cross-domain access requests, and subsequently, when the trusted center receives a cross-domain request, it first searches the dynamic mapping table for the mapping result, and then performs regular mapping based on the level of the mark.

Citation Information

Patent Citations

  • Cross-domain access control method and system, storage medium, computer equipment and terminal

    CN112532591A

  • Data cross-domain security sharing system and method

    CN113132103A