Access control authorization method based on fuzzy mapping
Through the access control method based on fuzzy mapping, the user privacy protection and role explosion problems of the traditional RBAC model in complex environments are solved, and more flexible and secure permission management is achieved.
Patent Information
- Application Number
- CN202310357589.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-06
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2043-04-06
AI Technical Summary
The traditional RBAC model cannot effectively guarantee user privacy protection and flexibility in an environment with a large number of users and complex role hierarchies, leading to role explosion and complexity in permission management.
An access control authorization method based on fuzzy mapping is adopted. By initializing the user and role sets, a fuzzy concept lattice and a fuzzy aggregate concept lattice are constructed. The mapping between roles and users is formally modeled using fuzzy formal concept analysis, and the fuzzy relationship between users and roles is extracted.
It improves the flexibility of user identity protection, reduces the number of roles in the system, avoids the role explosion problem, and enhances the security of the system and the flexibility of permission management.
Smart Images

Figure CN116401653B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of computer software development, and particularly relates to the modification of a traditional RBAC model. BACKGROUND
[0002] Current research on access control mainly focuses on the combination of user identity, authorization authentication and access authorization, which poses new challenges to traditional access control. In particular, the dramatic increase in user demand has complicated the management environment of access control. In a diversified environment, the main challenges of access control are as follows: user personalized demand and security diversity, traditional access control lacks protection of user privacy; user dependence on the environment is enhanced, the dramatic increase in users, resources and services brings role explosion and complexity of permission management, which poses challenges to role-based access control.
[0003] In the present application, we mainly focus on the security of user privacy in applications. In particular, in an environment with a large number of users and complex role hierarchy, the degree of protection required by enterprises and users may be diverse, and the related conventions of the RBAC model may not guarantee security. In practical application scenarios, the decision of the manager on the mapping of users and roles is fuzzy, and this fuzzy relationship is reflected in the degree of satisfaction of the user to the context condition and the degree of trust of the user to the current environment, which makes the degree of satisfaction of the user in the system to different levels fuzzy. In this relationship, we may not be able to describe it with precise mathematical language, so we use continuous values to represent the association strength.
[0004] In summary, it is necessary in the field to improve the RBAC model, provide clearer and more general definitions, meet the security features of the minimum permission and user hierarchy, and increase the flexibility of traditional access control. SUMMARY
[0005] In order to solve the technical problems mentioned in the background art, the present application provides an access control authorization method based on fuzzy mapping.
[0006] In order to achieve the above technical purpose, the technical scheme of the present application is as follows:
[0007] The access control authorization method based on fuzzy mapping comprises the following steps:
[0008] (1) Initialization: In the initialization stage, the system needs to determine the user set US = {U1, U2,..., U n}, U is each user. The role set RS = {R1, R2,..., R n}, R is each role. The relationship strength I between different roles and individual users, here the relationship strength is a fuzzy value of 0 to 1;
[0009] (2) Extracting user-role mapping: By assigning the fuzzy relationship strength between users and clear roles, we obtain the matrix M of identified users and roles. U×R ;
[0010] (3) Constructing fuzzy concepts: setting the threshold Φ d ={Φ d1 ,Φ d2 ,...,Φ dn}, the matrix M derived in step 2 U×R Convert to fuzzy form context K(U,R,I U×R ), U is the user, R is the role, and K is the mapping relationship between the current role and the user;
[0011] (4) Constructing a fuzzy concept lattice: Analyze the fuzzy formal concepts obtained in step 3 and construct a fuzzy formal concept lattice. Obtain the user-role mapping relationship from the fuzzy formal concept lattice.
[0012] (5) Based on the obtained fuzzy concept lattice, a fuzzy aggregation concept lattice is constructed, hierarchical division is performed, and the current and internal roles are converted into a mapping between fuzzy role sets. From this, the relationship between the user and the fuzzy role set can be obtained.
[0013] Furthermore, in step (1), the initialization process is as follows:
[0014] (101) Define the user and role identifiers of the system, taking four users and four roles as an example. The four user identifiers are U1, U2, U3, and U4, and the four role identifiers are R1, R2, R3, and R4. The mapping between these users and roles is a fuzzy value from 0 to 1;
[0015] (102) The association relationship UA of individual user to role mapping is as follows. The associations of users U1, U2, U3, U4 and roles R1, R2, R3, R4 are described as UA1, UA2, UA3, UA4 respectively:
[0016] UA1={0.5,0.7,0.6,0.1},UA2={0.1,0.2,0.9,0.5}
[0017] UA3={0.6,0.5,0.7,0.6},UA4={0.2,0.2,0.7,0.9}
[0018] The numerical value is the relationship strength (I) between different roles and individual users, and the relationship strength is a fuzzy value between 0 and 1.
[0019] Furthermore, in step (2), by merging UA1, UA2, UA3, and UA4, a user matrix with role mapping in the current model can be derived.
[0020] Furthermore, in step (3), the system defines the thresholds for each role, defining the R1 role threshold as 0.4, the R2 threshold as 0.5, the R3 threshold as 0.5, and the R4 threshold as 0.4. Fuzzy values are extracted from the above associations UA1, UA2, UA3, and UA4, and the fuzzy form context is formalized. Taking the concept number {[U2, U3, U4], [R4 / 0.5]} corresponding to concept C2 as an example, concept C2 represents users U2, U3, and U4, which are related to role R4 with a relationship strength of 0.5. C3 represents users U1, U2, and U4, which are related to role R4 with a relationship strength of 0.6. In this way, a total of 9 concepts C1-C9 can be extracted. This role allocation method can display the correlation between users and roles in different situations, which can be the correlation between a certain user and a role, or the correlation between multiple users and roles when they collaborate.
[0021] Furthermore, in step (4), based on step (3), a fuzzy concept lattice is constructed. A node represents a concept, and a concept represents the degree of association between a user and a role. The fuzzy concept lattice contains all concepts at the top and bottom levels. For example, the concept of four users at the top level is at level 1, while the concept of three users is at level 1, and the concepts of two users and one user are at levels 2 and 3, respectively.
[0022] Furthermore, in step (5), the specific construction process of the fuzzy aggregation concept lattice is as follows:
[0023] (501) Under the condition that different roles have different attribute value thresholds, when the concept has the current role, if the current role attribute value is greater than or equal to the threshold, the child node absorbs the parent node connotation and saves the child node;
[0024] (502) When multiple thresholds conflict with each other during the clustering process, it is necessary to compare the difference between each attribute value and the threshold. If the sum of the difference values is positive, the child node is allowed to absorb the parent node's content and the child node is saved. Otherwise, the absorption is abandoned. The system sets the clustering threshold R, for example, R1 = 0.5, R2 = 0.7, R3 = 0.5, R4 = 0.5.
[0025] The beneficial effects brought about by adopting the above technical solution are:
[0026] (1) This invention uses fuzzy formal concept analysis to formally model the mapping between roles and users, aggregates roles, and extracts the mapping between public roles and roles. This mapping relationship can better help us manage the trust relationship and dynamic nature of roles within the system. By introducing the concept of fuzzy roles, user identity protection is achieved, and compared with the traditional RBAC model, flexibility is increased.
[0027] (2) The present application extracts all nodes of top and lowest levels as a common role set, respectively recorded as FR1, FR2, FR3 and FR4. The permission in each fuzzy role set is the minimum permission principle of the aggregated nodes. In the fuzzy role set, the fuzzy role is composed of multiple user-roles, and it is difficult for malicious users to track the current user-role relationship, thereby improving the overall security of the system and greatly reducing the number of roles in the system, avoiding the "role explosion" problem. BRIEF DESCRIPTION OF DRAWINGS
[0028] Figure 1 is the overall flowchart in the present application;
[0029] Figure 2 is the access control structure diagram in the present application;
[0030] Figure 3 is the fuzzy concept lattice in the present application;
[0031] Figure 4 is the fuzzy aggregated concept lattice in the present application. DETAILED DESCRIPTION
[0032] It is easy to understand that, according to the technical scheme of the present application, a person skilled in the art can imagine various embodiments of the access control method based on policy review and authorization extension of the present application without changing the essential spirit of the present application. Therefore, the following specific embodiments and drawings are only exemplary descriptions of the technical scheme of the present application, and should not be regarded as the whole or as a limitation or restriction on the technical scheme of the present application.
[0033] The technical scheme of the present application will be described in detail below with reference to the drawings.
[0034] The basic idea of the present application is to formalize the mapping form of roles and users using the method of fuzzy formal concept analysis, and to aggregate roles and extract common roles and role mappings. The overall flowchart is shown in the accompanying drawings. Figure 1 By introducing the concept of fuzzy role, the protection of user identity is realized, the flexibility of traditional access control is increased, and the number of roles in the system is greatly reduced, avoiding the "role explosion" problem. The access control flowchart is shown in the accompanying drawings. Figure 2
[0035] The access control authorization method based on fuzzy mapping includes the following steps:
[0036] Step 1: Initialization: In the initialization phase, the system needs to determine the user set US = {U1, U2,..., U n}, U is each user. The role set RS = {R1, R2,..., R n }, R is each role. The relationship strength I between different roles and individual users, where the relationship strength is a fuzzy value between 0 and 1;
[0037] Step 2: Extract user-role mapping: By assigning the fuzzy relationship strength between users and clear roles, we can obtain the matrix M of identified users and roles. U×R ;
[0038] Step 3: Construct fuzzy concepts: set threshold Φ d ={Φ d1 ,Φ d2 ,...,Φ dn}, the matrix M derived in step 2 U×R Convert to fuzzy form context K(U,R,I U×R ), U is the user, R is the role, and K is the mapping relationship between the current role and the user;
[0039] Step 4: Constructing a fuzzy concept lattice: Analyze the fuzzy formal concepts obtained in step 3 and construct a fuzzy formal concept lattice. Obtain the user-role mapping relationship from the fuzzy formal concept lattice.
[0040] Step 5: Based on the obtained fuzzy concept lattice, construct a fuzzy aggregate concept lattice, perform hierarchical division, and convert the current and internal roles into a mapping between fuzzy role sets. From this, the relationship between users and fuzzy role sets can be obtained.
[0041] In this embodiment, the above step 1 can be implemented by adopting the following preferred solution:
[0042] (101) Define the user and role identifiers of the system, taking four users and four roles as an example. The four user identifiers are U1, U2, U3, and U4, and the four role identifiers are R1, R2, R3, and R4. The mapping between these users and roles is a fuzzy value from 0 to 1;
[0043] (102) The association relationship UA of individual user to role mapping is as follows. The associations of users U1, U2, U3, U4 and roles R1, R2, R3, R4 are described as UA1, UA2, UA3, UA4 respectively:
[0044] UA1={0.5,0.7,0.6,0.1},UA2={0.1,0.2,0.9,0.5}
[0045] UA3={0.6,0.5,0.7,0.6},UA4={0.2,0.2,0.7,0.9}
[0046] The numerical value is the relationship strength (I) between different roles and individual users, and the relationship strength is a fuzzy value between 0 and 1.
[0047] In the embodiment, the following preferred scheme can be used to implement the above step 2:
[0048] By merging UA1, UA2, UA3, UA4, it can be concluded that the user matrix with role mapping in the current model.
[0049] In the embodiment, the following preferred scheme can be used to implement the above step 3:
[0050] The threshold values of the respective roles are defined by the system, and the threshold value of R1 is 0.4, the threshold value of R2 is 0.5, the threshold value of R3 is 0.5, and the threshold value of R4 is 0.4. The fuzzy values are extracted from the above-mentioned association UA1, UA2, UA3, UA4, and the fuzzy form context is formalized. Taking the concept number {[U2, U3, U4], [R4 / 0.5]} corresponding to the concept C2 as an example, the concept C2 represents users U2, U3 and U4, which are related to the role R4, and the relationship strength is 0.5. C3 represents users U1, U2 and U4, which are related to the role R4, and the relationship strength is 0.6. In this way, a total of 9 concepts C1-C9 can be extracted. This role allocation method can show the association degree between users and roles in different situations, which can be the association degree between a certain user and a role, or the association degree between multiple users and a role when cooperating.
[0051] In the embodiment, the following preferred scheme can be used to implement the above step 4:
[0052] On the basis of step (3), a fuzzy concept lattice is constructed. As shown in Figure 3 , the nodes represent concepts, and the concepts represent the association degree between users and roles. The fuzzy concept lattice contains all level concepts from the top level to the lowest level. For example, the four user concepts are in the top level, and the three user concepts are in level 1, and the two user concepts and the one user concept are in level 2 and level 3, respectively.
[0053] In the embodiment, the following preferred scheme can be used to implement the above step 5:
[0054] (501) Under the condition that different roles have different attribute value thresholds, when the current role has a concept, if the attribute value of the current role is greater than or equal to the threshold value, the child node absorbs the connotation of the parent node, and the child node is saved;
[0055] (502) When multiple threshold values conflict with each other in the clustering process, it is necessary to compare the difference values of the attribute values and the threshold values. If the total difference value is positive, the child node is allowed to absorb the connotation of the parent node, and the child node is saved, otherwise the absorption is abandoned. The system sets the clustering threshold R, for example, R1=0.5, R2=0.7, R3=0.5, and R4=0.5. The fuzzy aggregation concept lattice is shown in Figure 4 .
Claims
1. The access control authorization method based on fuzzy mapping includes the following steps: (1) Initialization: In the initialization phase, the system needs to determine the user set US = {U1, U2, ..., U n }, role set RS={R1,R2,...,R n }, and the relationship strength I between different roles and individual users, where the relationship strength is a fuzzy value between 0 and 1; (2) Extracting user-role mapping: By assigning the fuzzy relationship strength between users and clear roles, we obtain the matrix M of identified users and roles. U×R ; (3) Constructing fuzzy concepts: setting the threshold Φ d ={Φ d1 ,Φ d2 ,...,Φ dn }, the system defines the threshold of each role, and defines the R1 role threshold as 0.4, the R2 threshold as 0.5, the R3 threshold as 0.5, and the R4 threshold as 0.
4. Concept C2 indicates that users U2, U3, and U4 are related to role R4, and the relationship strength is 0.5; concept C3 indicates that users U1, U2, and U4 are related to role R4, and the relationship strength is 0.6; in this way, a total of 9 concepts C1-C9 can be extracted. This role allocation method can show the correlation between users and roles in different situations, which can be the correlation between a certain user and a role, or the correlation between multiple users and roles when they cooperate; the matrix M derived in step 2 is converted to U×R Convert to fuzzy form context K(U,R,I U×R ), U is the user, R is the role, I is the relationship strength, and K is the mapping relationship between the current role and the user; (4) Constructing a fuzzy concept lattice: Analyze the fuzzy formal concepts obtained in step 3 and construct a fuzzy formal concept lattice, where nodes represent concepts and concepts represent the degree of association between users and roles. The fuzzy concept lattice contains all concepts at the top and bottom levels. The top level contains concepts of four users, three users’ concepts at level 1, and two users and one user’s concepts at levels 2 and 3, respectively. The user-role mapping relationship is obtained from the fuzzy formal concept lattice. (5) Based on the obtained fuzzy concept lattice, a fuzzy aggregation concept lattice is constructed and hierarchically divided. The current and internal roles are converted into a mapping between fuzzy role sets, from which the relationship between the user and the fuzzy role set can be obtained; under the condition that different roles have different attribute value thresholds, when the concept contains the current role, the decision on whether to save the child node is based on the comparison result between the role attribute value and the corresponding threshold; When multiple thresholds conflict with each other during the clustering process, whether to save the child node is determined based on the comparison result of the difference between each attribute value and the corresponding threshold.
2. The access control authorization method based on fuzzy mapping according to claim 1 is characterized in that: The specific process of step (1) is as follows: (101) Define the user ID and role ID of the system. The four user IDs are U1, U2, U3, and U4, and the four role IDs are R1, R2, R3, and R4. The mapping between these users and roles is a fuzzy value from 0 to 1. (102) The association relationship between individual users and roles is UA. The association between users U1, U2, U3, U4 and roles R1, R2, R3, R4 is described as UA1, UA2, UA3, UA4 respectively: UA1={0.5,0.7,0.6,0.1},UA2={0.1,0.2,0.9,0.5} UA3={0.6,0.5,0.7,0.6},UA4={0.2,0.2,0.7,0.9} Each element value in the association UA1, UA2, UA3, and UA4 is the relationship strength (I) between different roles and individual users, and the relationship strength is a fuzzy value between 0 and 1.
3. The access control authorization method based on fuzzy mapping according to claim 1 is characterized in that: In step (2), by merging UA1, UA2, UA3, and UA4, the user matrix with role mapping in the current model can be derived.
4. The access control authorization method based on fuzzy mapping according to claim 1 is characterized in that: The specific construction process of the fuzzy aggregation concept lattice in step (5) is as follows: (401) Under the condition that different roles have different attribute value thresholds, when the concept has the current role, if the current role attribute value is greater than or equal to the threshold, the child node absorbs the parent node connotation and saves the child node; (402) When multiple thresholds conflict with each other during the clustering process, it is necessary to compare the difference between each attribute value and the threshold. If the sum of the difference values is positive, the child node is allowed to absorb the parent node's content and save the child node. Otherwise, the absorption is abandoned. The system sets the clustering threshold R, R1 = 0.5, R2 = 0.7, R3 = 0.5, R4 = 0.5.
Citation Information
Patent Citations
Combined reasoning techniques for role reachability analysis in identity systems
CN116391186A