Method for access control based on dynamic stealth network

By employing multi-dimensional trust assessment and elliptic curve additive group authentication, the problem of insufficient attribute protection in dynamic stealth networks is solved, thereby improving the stealth and security of devices and reducing computational complexity and communication overhead.

CN119011148BActive Publication Date: 2025-12-05BEIJING UNIV OF POSTS & TELECOMM +4
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410909380.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-08
Publication Date
2025-12-05
Estimated Expiration
2044-07-08

AI Technical Summary

Technical Problem

Existing technologies cannot fully protect the attributes submitted by resource access devices, and have high communication overhead and energy consumption, resulting in insufficient concealment and security of dynamic stealth networks.

Method used

By uploading access attribute sequences through resource access devices, setting thresholds based on trust assessment scores of multi-dimensional attributes, performing trust screening before authentication, and combining with a dynamic stealth network environment, the device attributes are hidden and fine-grained access control is achieved. Elliptic curve additive group and hash function are used for identity and attribute weight authentication.

Benefits of technology

It improves the security and stealth of dynamic stealth networks, reduces computational complexity, communication overhead and energy consumption, achieves protection of device attributes and privacy, and provides more flexible resource access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011148B_ABST
    Figure CN119011148B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of networks, and provides an access control method based on a dynamic stealth network, the dynamic stealth network comprising a resource access device, an authentication authority and a resource possession device, the method comprising the following steps: uploading, by the resource access device, an access attribute sequence of this time to the authentication authority, the access attribute sequence being used for instructing the authentication authority to calculate a trust evaluation score of the resource access device based on the access attribute sequence and broadcasting an evaluation threshold corresponding to the trust evaluation score in the dynamic stealth network; and performing authentication and access permission control in the case that the trust evaluation score reaches the evaluation threshold, the application realizes early trust screening of the device before authentication based on multi-dimensional attribute device trust evaluation, improves the security of the dynamic stealth network, and enables the resource access control to be more fine-grained and flexible through device attribute allocation of the resource access control permission, so that the method has low calculation complexity, small communication cost and low energy consumption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network technology, and in particular to an access control method based on dynamic stealth networks. Background Technology

[0002] Dynamic stealth networks are characterized by stealth and dynamism. Stealth means that devices need to be protected when they access the network so that other malicious devices cannot intercept relevant data. Dynamism means that devices may frequently access and disconnect from the network. A large number of frequent access authentications may cause network latency and put pressure on resource providers.

[0003] To address the issue of concealment, current methods protect device attributes during the resource access device authentication process. However, this concealment primarily focuses on protecting critical information such as the device ID, without comprehensively protecting all attributes submitted by the resource access device. This could allow attackers to intercept and analyze this attribute data within the network, leading to the inference and forgery of the resource access device's identity. Regarding the dynamic nature of access, existing technologies achieve dynamic access through device trust assessment. However, current trust assessments rely on relatively simple attributes and employ machine learning methods, resulting in high network overhead and energy consumption. Summary of the Invention

[0004] This invention provides an access control method based on a dynamic stealth network to solve the problems of existing technologies that cannot fully protect the attributes submitted by resource access devices, and that have high communication overhead and high energy consumption.

[0005] This invention provides an access control method based on a dynamic stealth network, comprising the following steps.

[0006] The resource access device uploads the access attribute sequence of this access to the certification authority. The access attribute sequence is used to instruct the certification authority to calculate the trust assessment score of the resource access device based on the access attribute sequence, and broadcast the assessment threshold corresponding to the trust assessment score in the dynamic stealth network.

[0007] When the trust assessment score reaches the assessment threshold, the device receives the serial number of the attribute in the device attribute sequence, the key and public key of the resource access device, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device. The access attribute sequence is a subset of the device attribute sequence.

[0008] If authentication is successful, a first signature is calculated based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the requested resource.

[0009] A resource request is sent to the resource-owning device. The resource request includes: the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the requested resource, and the trust evaluation score. The resource request is used to instruct the resource-owning device to verify the trust evaluation score based on an evaluation threshold. If the trust evaluation score is greater than the evaluation threshold, the device verifies whether the attribute weight corresponding to the attribute in the access attribute sequence meets the requirements of the reference attribute weight corresponding to the requested resource based on the first signature and the public key of the resource access device. If the requirements are met, the encrypted address link of the requested resource is sent to the resource access device.

[0010] Obtain the ciphertext of the requested resource based on the ciphertext address link and then decrypt it.

[0011] According to the present invention, an access control method based on a dynamic stealth network receives the serial number of an attribute in a device attribute sequence, the key and public key of a resource access device issued by the certification authority, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication of the resource access device, including the following steps.

[0012] Receive the device attribute sequence and its corresponding serial number set issued by the certification authority, and calculate the first hidden attribute of the attribute in the access attribute sequence based on the first random positive integer and the serial number.

[0013] The second signature is calculated based on the first random positive integer, the first hidden attribute, and the public key of the certification authority.

[0014] The identity ID, the public key of the resource access device, the second signature, and the first hidden attribute and their corresponding serial number are packaged into a first message and sent to the authentication authority. The authentication authority verifies the legitimacy of the identity based on the first message and its key. If the verification is successful, the second hidden attribute is calculated based on the first hidden attribute, and the third signature is calculated based on the authentication authority's private key and the attributes in the access attribute sequence. The third signature, the authentication authority's public key, and the second hidden attribute are packaged into a second message and sent to the resource access device.

[0015] The attribute weights of the attributes in the access attribute sequence are calculated based on the second message and the first random positive integer. The legality of the attribute weights is verified based on the sum of the attribute weights, the third signature, and the public key of the authentication authority. If the verification is legal, the authentication of the resource access device's identity and attribute weights with the authentication authority is completed.

[0016] According to an access control method based on a dynamic stealth network provided by the present invention, the first hiding attribute and the second signature are calculated according to the following formula. i .

[0017]

[0018] Where, θ i,r Indicates resource access device d i The r-th attribute in the access attribute sequence The first hidden attribute, Indicates resource access device d i The corresponding first random positive integer, PK CA H2 represents the public key of the certification authority. The hash function is given by G1, which is an additive group on an elliptic curve of order q, where g1∈G1 and g is a generator of G1. The symbol represents a cyclic group, and || represents data concatenation.

[0019] According to the access control method based on a dynamic stealth network provided by the present invention, the authentication authority verifies the legitimacy of the identity based on the first message and the authentication authority's key in the following manner.

[0020] calculate

[0021] Verify whether the following two equations are true.

[0022]

[0023] H2(ψ1||ψ2||,...,||ψ r )=H2(θ i,1 ||||θ i,2 …||θ i,r ).

[0024] in, Indicates resource access device d i Identity ID, SK CA This represents the key of the certification authority. Indicates resource access device d i public key, ψ k H1 represents an intermediate variable. The hash function.

[0025] If both equations are true, the identity authentication is valid.

[0026] According to the access control method based on dynamic stealth network provided by the present invention, the authentication authority calculates the second stealth attribute based on the first stealth attribute, and calculates the third signature according to the authentication authority's private key and the attributes in the access attribute sequence. The calculation method is as follows.

[0027] For each attribute Choose a second random positive integer The second hidden attribute is calculated as: χi,k =ι CA,k θ i,k .

[0028] Calculate the third signature using the following formula:

[0029] Among them, SK CA This represents the key of the certification authority, which is used by different resource access devices. i and d l Any property of (i≠l) and If j = k, then ι CA,j =ι CA,k .

[0030] According to the present invention, an access control method based on a dynamic stealth network calculates the attribute weight of an attribute in an access attribute sequence based on a second message and a first random positive integer, and verifies the legality of the attribute weight based on the sum of the attribute weights, a third signature, and the public key of the authentication authority. The method includes: calculating the attribute weight of an attribute in an access attribute sequence according to the following formula.

[0031]

[0032] The sum of attribute weights is: μ i =(T i,1 +T i,2 +…+T i,r ).

[0033] In the equation e(δ) i ,g1)=e(μ i PK CA If the condition is met, determine the validity of the attribute weights and obtain the resource access device d. i Each attribute Attribute weight T i,k , where e represents the bilinear mapping G1×G1→G2, and G2 represents the multiplicative group on the q-order elliptic curve.

[0034] According to the access control method based on dynamic stealth network provided by the present invention, the reference attribute weight is set by the resource-owning device in the following manner.

[0035] Resource ownership equipment RO u Obtain the attribute set {A1, A2, ..., A...} of all devices from the certification authority. R}, Resource ownership device calculation attribute weight: {T u,1 =ι CA,1 A1g1,T u,2 =ι CA,2 A2g1,…,Tu,R =ι CA,R A R g1}.

[0036] Among them, ι CA,R Represents a random number.

[0037] Resource ownership equipment RO u Randomly select encryption parameters Calculate the encryption key k of the resources m. RO,m =H2(β) RO,m g1).

[0038] Resource ownership equipment RO u Encrypt the v-th resource m RO,v , obtain resource m RO,v ciphertext This represents the XOR operation.

[0039] For accessing resource m RO,v The required weights are t different reference attributes, and the corresponding attribute sequence numbers are (S). v,1 ,S v,2 ,…,S v,t Select t-1 random numbers. Construct the polynomial f(x).

[0040] f(x) = b v,t-1 x t-1 +b v,t-2 x t-2 +…+b v,1 x+k RO,m .

[0041] Resource ownership equipment RO u The hash value of the reference attribute weight corresponding to the attribute sequence number {H2(T)} v,1 ),H2(T v,2 ),…,H2(T v,t The input is given to the polynomial f(x), and f(x) outputs t function values ​​{f}. v,1 ,f v,2 ,…,f v,t}

[0042] The uth resource-owning device RO u Will Publicly accessible to resource access devices, where keyword v,m The plaintext key of the resource to be shared, and the ciphertext key. v,m Stored in the database of the resource-owning device. Indicates resource ownership equipment RO u Identity ID, Indicates resource ownership equipment RO u The public key, H2 represents The hash function is G1, which is an additive group on an elliptic curve of order q, and g1∈G1 is a generator of G1.

[0043] According to the present invention, an access control method based on a dynamic stealth network calculates a first signature based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the resource to be requested. The method includes: calculating the first signature σ in the following manner. i,m .

[0044]

[0045] Indicates resource access device d i The key, H1 represents The hash function, S i,t Indicates resource access device d i The sequence number of the t-th attribute in the access attribute sequence.

[0046] The resource request is:

[0047] in, Indicates resource access device d i Identity ID, Indicates resource access device d i Score i This represents the trust assessment score during the i-th visit.

[0048] Resource ownership equipment RO u Verify, as follows, whether the attribute weights corresponding to the attributes in the access attribute sequence meet the requirements of the reference attribute weights corresponding to the requested resource.

[0049] In the resource request (S) i,1 ,S i,2 ,…,S i,t ) and resource ownership equipment RO u Public serial number (S) v,1 ,S v,2 ,…,S v,r Matching is performed for (t≤r).

[0050] Resource ownership equipment RO u Calculate φ i,m =H1(S i,1 ||S i,2 ||…||S i,t ||keyword v,m g1, in equation If true, the attribute weights corresponding to the attributes in the access attribute sequence are determined to satisfy the reference attribute weights corresponding to the requested resource, where e represents the bilinear mapping G1×G1→G2 and G2 represents the multiplicative group on the q-order elliptic curve.

[0051] Obtaining and decrypting the ciphertext of the requested resource based on the ciphertext address link includes: using the publicly available attribute sequence number. and resource access device d i Corresponding attribute weight T i,j The Lagrange polynomial is used to recover f(x).

[0052]

[0053] g(x) = f(x).

[0054] Resource access device d i Decryption key for computed resource ciphertext by Decrypting the ciphertext of the resource c v,m Obtain plaintext resources

[0055] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the access control method based on a dynamic stealth network as described above.

[0056] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the access control method based on dynamic stealth networks as described above.

[0057] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the access control method based on dynamic stealth networks as described above.

[0058] The access control method based on dynamic stealth networks provided by this invention involves resource access devices uploading access attribute sequences, which include multiple attributes. Device trust assessment is performed based on multi-dimensional attributes, and thresholds are set according to trust scores to achieve pre-authentication trust screening of devices, improving the security of dynamic stealth networks. All access attributes submitted by the devices are hidden, and combined with the characteristics of the dynamic stealth network environment, attribute-based access control with device concealment is achieved. This not only enables device access in the dynamic stealth network environment but also ensures that device attributes and privacy are not leaked. By pre-setting reference attribute weights for resources, resource access permissions are bound to device attributes, and resource access control permissions are allocated based on device attributes, making resource access control more granular and flexible. Compared with access control models in traditional network environments, this method has lower computational complexity, shorter computation time, lower communication overhead, and lower energy consumption. Attached Figure Description

[0059] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0060] Figure 1 This is a schematic diagram of the architecture of a dynamic stealth network.

[0061] Figure 2 This is a flowchart illustrating the access control method based on dynamic stealth networks provided by the present invention.

[0062] Figure 3 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0063] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0064] The dynamic stealth network includes: resource access devices, authentication authorities, and resource ownership devices. The access control method based on the dynamic stealth network in this embodiment of the invention is applied to the resource access devices, such as... Figure 1 As shown, steps S210 to S250 are included.

[0065] Step S210: The resource access device uploads the access attribute sequence of this access to the certification authority. The access attribute sequence is used to instruct the certification authority to calculate the trust assessment score of the resource access device based on the access attribute sequence, and broadcast the assessment threshold corresponding to the trust assessment score in the dynamic stealth network. The access attribute sequence includes multiple dimensions of attributes, such as: network environment attributes (device access IP address, device network status, data transmission latency, and device traffic, etc.), device hardware attributes (physical hardware address), device software attributes, and device security attributes, etc.

[0066] Step S220: When the trust assessment score reaches the assessment threshold, receive the serial number of the attribute in the device attribute sequence, the key and public key of the resource access device issued by the certification authority, and interact with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication of the resource access device. The access attribute sequence is a subset of the device attribute sequence.

[0067] Step S230: If authentication is successful, calculate the first signature based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the requested resource.

[0068] Step S240: Send a resource request to the resource-owning device. The resource request includes: the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the requested resource, and the trust evaluation score. The resource request instructs the resource-owning device to verify the trust evaluation score based on an evaluation threshold. If the trust evaluation score is greater than the evaluation threshold, the device verifies whether the attribute weights corresponding to the attributes in the access attribute sequence meet the requirements of the reference attribute weights corresponding to the requested resource based on the first signature and the public key of the resource access device. If the requirements are met, the encrypted address link of the requested resource is sent to the resource access device. It should be noted that the resource-owning device will pre-set the access permissions of the resource according to the confidentiality level of the resource, binding the access permissions to the device attributes. This can be understood as specifying the access permissions of the resource through the device attributes, and setting the weight of the specific device attribute for accessing the resource as the reference attribute weight. The device calculates the encrypted key and the ciphertext of the reference attribute weight, encrypts the resource using the encryption key to obtain the encrypted resource, and finally uploads the encrypted resource and the corresponding description information to the resource storage platform for storage.

[0069] Step S250: Obtain the ciphertext of the requested resource based on the ciphertext address link and decrypt it.

[0070] This embodiment of the access control method based on dynamic stealth networks involves resource access devices uploading access attribute sequences, which include multiple attributes. Device trust assessment is performed based on these multi-dimensional attributes, and thresholds are set according to trust scores to achieve pre-authentication trust screening of devices, thus improving the security of dynamic stealth networks. All access attributes submitted by the devices are hidden, and combined with the characteristics of the dynamic stealth network environment, attribute-based access control with device concealment is achieved. This not only enables device access in the dynamic stealth network environment but also ensures that device attributes and privacy are not leaked. By pre-setting reference attribute weights for resources, resource access permissions are bound to device attributes, and resource access control permissions are allocated based on device attributes. This makes resource access control more granular and flexible. Compared with access control models in traditional network environments, this method has lower computational complexity, shorter computation time, lower communication overhead, and lower energy consumption.

[0071] In some embodiments, the certification authority calculates the trust assessment score for the resource access device during this access as follows.

[0072] Let q l ,q h They are two real numbers. Let q represent the set of real numbers, q = [q l ,q h ] is used to represent a range. q ij This represents the attribute value of the j-th attribute during the i-th access of any resource access device; the attribute is the evaluation metric. This represents the minimum value of the j-th attribute during the attribute collection process of the resource access device. This represents the maximum value of the j-th attribute during the attribute collection process for the resource access device. The j-th attribute is q. ij The interval to which it belongs The process involves collecting data reflecting device attributes, classifying the data according to different attributes, establishing the relationship between attributes and device trust scores, and generating a decision matrix. The decision matrix X, representing multiple attributes reflecting device behavior, is constructed as follows.

[0073]

[0074] Where s represents the number of devices, m represents the number of times a device has been accessed so far, and n represents the number of attributes.

[0075] The standardized formula for the attributes in the decision matrix X is as follows.

[0076]

[0077] The decision matrix X is normalized to obtain the following formula.

[0078] X′ =(q ij ) ′ m×sn .

[0079] Fuzzy Hierarchical Analysis (FAHP) can solve the problem of fuzzy and difficult-to-quantify device behavior indicators. Therefore, this paper uses FAHP to establish the weight system of the hierarchical model. Based on the "0.1-0.9" ratio method, the various attributes of the access behavior are compared to obtain the membership degree (the degree of correlation between attributes) r among each attribute. j For the i-th access, establish a fuzzy judgment matrix R for device attributes. i As follows. R i =(r j ) n×n .

[0080] Membership degree r of the fuzzy judgment matrix j The relationships between different attributes were quantified based on the actual collected data, making it suitable for calculating the weights of multiple attributes. To calculate the weights of device attributes, a fuzzy judgment matrix weight formula was constructed. Let ω... ij The weight of the j-th attribute represents the weight of the resource access device during the i-th access, and its calculation formula is as follows.

[0081]

[0082] Where n represents the number of resource access device attributes, a = (n-1) / 2, r ij This represents the membership degree of the fuzzy judgment matrix corresponding to the i-th access of the resource access device. Finally, the weight set of all attributes for the i-th access of the device is calculated to obtain the attribute weight matrix ω. ij Attribute weight matrix ω ij Provide weights for trust assessment.

[0083] Score i Let represent the trust assessment score at the i-th access. The formula for calculating the resource access device trust assessment score is as follows.

[0084]

[0085] Among them, (q) ij ) ′ For X ′ The attribute value of the j-th attribute during the i-th visit, ω ij This represents the weight of the j-th attribute when the resource access device accesses the resource for the i-th time.

[0086] In this embodiment, by evaluating device trust based on multi-dimensional attributes and determining whether a device is a trusted device according to the evaluation threshold, pre-authentication trust screening of devices is achieved, thereby improving network security and avoiding subsequent invalid authentication.

[0087] In some embodiments, the device receives the serial number of an attribute in a device attribute sequence, the key and public key of the resource access device, issued by the certification authority, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device, including:

[0088] Receive the device attribute sequence and its corresponding serial number set issued by the certification authority, and calculate the first hidden attribute of the attribute in the access attribute sequence based on the first random positive integer and the serial number.

[0089] The second signature is calculated based on the first random positive integer, the first hidden attribute, and the public key of the certification authority.

[0090] The identity ID, the public key of the resource access device, the second signature, and the first hidden attribute and their corresponding serial number are packaged into a first message and sent to the authentication authority. The authentication authority verifies the legitimacy of the identity based on the first message and its key. If the verification is successful, the second hidden attribute is calculated based on the first hidden attribute, and the third signature is calculated based on the authentication authority's private key and the attributes in the access attribute sequence. The third signature, the authentication authority's public key, and the second hidden attribute are packaged into a second message and sent to the resource access device.

[0091] The attribute weights of the attributes in the access attribute sequence are calculated based on the second message and the first random positive integer. The legality of the attribute weights is verified based on the sum of the attribute weights, the third signature, and the public key of the authentication authority. If the verification is legal, the authentication of the resource access device's identity and attribute weights with the authentication authority is completed.

[0092] It should be noted that: the certification authority generates public-private key pairs (SK, PK) for the participants in the network, and generates public-private key pairs for the resource owner device (RO) and each resource access device connected to the network, and distributes them to each device through a secure channel. Resource access device d i ∈U(1≤i≤n), the public and private key pairs are respectively This represents a circular group, and the public and private key pairs of the certification authority. PK CA =g1SK CA The resource owns the device's public and private key pairs. PK RO =g1SK RO .

[0093] The certification authority also stores a sequence of attributes of devices that can access a particular resource, represented as Attr. seq =A1|A2|…|A i |Aj |…|A R After each resource access device completes the attribute collection, the data is aggregated and sent to the certification authority. The certification authority then normalizes the attributes and ensures that A... i j ,(i,j,R∈N * ), N * Represents the set of natural numbers, and for the set of attributes applied to access, it is Attr. set ={A1,A2,…,A R Resource access device d i The attribute sequence is z represents the number of resource access devices, and the corresponding ordered attribute set is: r represents the resource access device d i The number of attributes in the access attribute sequence.

[0094] In some embodiments, the device attribute sequence and its corresponding sequence number set issued by the certification authority are received, that is, the attribute sequence set and corresponding sequence number {(A1,S1),(A2,S2),…,(A...S1)} sent by the certification authority to the resource access device. R ,S R )},A j (1≤j≤R) represents the attribute, and S1 represents the sequence number corresponding to attribute A1.

[0095] For each set of ordered attributes Resource access device d i Calculate the first hidden attribute and the second signature using the following formula: i By calculating the first hidden attribute on the access attribute, the access attribute is hidden.

[0096]

[0097] Where, θ i,r Indicates resource access device d i The r-th attribute in the access attribute sequence The first hidden attribute, Indicates resource access device d i The corresponding first random positive integer, PK CA H2 represents the public key of the certification authority. The hash function is G1, which is an additive group on an elliptic curve of order q, g1∈G1, which is a generator of G1, and || represents data concatenation.

[0098] After calculating the first hidden attribute and the second signature, the resource access device packages the identity ID, the resource access device's public key, the second signature, the first hidden attribute, and its corresponding serial number into a first message.​ And send it to the certification authority.

[0099] In some embodiments, the authentication authority verifies the legitimacy of the identity based on the first message and the authentication authority's key in the following manner.

[0100] calculate

[0101] Verify whether the following two equations are true.

[0102]

[0103] in, Indicates resource access device d i Identity ID, SK CA This represents the key of the certification authority. Indicates resource access device d i public key, ψ k H1 represents an intermediate variable. The hash function.

[0104] If both equations are true, the identity authentication is valid.

[0105] If the identity is verified to be legitimate, the authentication authority calculates the second hidden attribute based on the first hidden attribute, and calculates the third signature based on the authentication authority's private key and the attributes in the access attribute sequence. The calculation method is as follows.

[0106] For each attribute Choose a second random positive integer The second hidden attribute is calculated as: χ i,k =ι CA,k θ i,k This further hides access attributes, improving the network's ability to conceal attributes.

[0107] Calculate the third signature using the following formula:

[0108] Among them, SK CA This represents the key of the certification authority, which is used by different resource access devices. i and d l Any property of (i≠l) and If j = k, then ι CA,j =ι CA,k .

[0109] After calculating the third signature, the third signature, the certification authority's public key, and the second hidden attribute are packaged into a second message {PK}. CA ,δ i,(χ i,1 ,χ i,2 ,…χ i,r And send it to the resource access device d i .

[0110] In some embodiments, the attribute weights of attributes in the access attribute sequence are calculated based on the second message and the first random positive integer, and the legality of the attribute weights is verified based on the sum of the attribute weights, the third signature, and the public key of the authentication authority, including: calculating the attribute weights of attributes in the access attribute sequence according to the following formula.

[0111]

[0112] The sum of attribute weights is: μ i =(T i,1 +T i,2 +…+T i,r ).

[0113] In the equation e(δ) i ,g1)=e(μ i PK CA If the condition is met, determine the validity of the attribute weights and obtain the resource access device d. i Each attribute Attribute weight T i,k , where e represents the bilinear mapping G1×G1→G2, and G2 represents the multiplicative group on the q-order elliptic curve.

[0114] In this embodiment, establishing a legitimate set of device attributes within the certification authority avoids frequent interactions during the certification process, reduces communication overhead, meets the dynamic requirements of dynamic stealth networks, and ultimately enables secure terminal access in dynamic stealth network scenarios.

[0115] In some embodiments, the resource-owning device needs to pre-set corresponding access permissions based on the security level of the shared resource. Specifically, the access permissions are bound to device attributes, that is, the weight of the device attribute accessing the resource is set as the reference attribute permission, and the reference attribute permission serves as the access permission for the resource. In this embodiment, the reference attribute weight is set by the resource-owning device in the following manner.

[0116] Resource ownership equipment RO u Obtain the attribute set {A1, A2, ..., A...} of all devices from the certification authority. R}, Resource ownership device calculation attribute weight: {T u,1 =ι CA,1 A1g1,T u,2 =ι CA,2 A2g1,…,T u,R =ι CA,R AR g1}.

[0117] Among them, ι CA,R Represents a random number.

[0118] Resource ownership equipment RO u Randomly select encryption parameters Calculate the encryption key k of the resources m. RO,m =H2(β) RO,m g1).

[0119] Resource ownership equipment RO u Encrypt the v-th resource m RO,v , obtain resource m RO,v ciphertext This represents the XOR operation.

[0120] For accessing resource m RO,v The required weights are t different reference attributes, and the corresponding attribute sequence numbers are (S). v,1 ,S v,2 ,…,S v,t Select t-1 random numbers. Construct the polynomial f(x).

[0121] f(x) = b v,t-1 x t-1 +b v,t-2 x t-2 +…+b v,1 x+k RO,m .

[0122] Resource ownership equipment RO u The hash value of the reference attribute weight corresponding to the attribute sequence number {H2(T)} v,1 ),H2(T v,2 ),…,H2(T v,t The input is given to the polynomial f(x), and f(x) outputs t function values ​​{f}. v,1 ,f v,2 ,…,f v,t}

[0123] The above process binds resource permissions with attribute weights to form reference attribute weights, and encrypts the reference attribute weights to ensure the concealment of attribute weights.

[0124] The uth resource-owning device RO u Will Publicly accessible to resource access devices, where keyword v,m The plaintext key of the resource to be shared, and the ciphertext key. v,m Stored in the database of the resource-owning device. Indicates resource ownership equipment RO u Identity ID, Indicates resource ownership equipment RO u The public key, H2 represents The hash function is G1, which is an additive group on an elliptic curve of order q, and g1∈G1 is a generator of G1.

[0125] Through the above process of setting reference attribute permissions for resources, only attribute sets are allowed. Only the resource access device can access resource m RO,v ∈M * M * Represents a collection of resources.

[0126] In some embodiments, calculating a first signature based on the key of the resource access device, the sequence number of an attribute in the access attribute sequence, and the keyword of the requested resource includes: calculating the first signature σ in the following manner. i,m .

[0127]

[0128] Indicates resource access device d i The key, H1 represents The hash function, S i,t Indicates resource access device d i The sequence number of the t-th attribute in the access attribute sequence.

[0129] The resource request is:

[0130]

[0131] in, Indicates resource access device d i Identity ID, Indicates resource access device d i Score i This represents the trust assessment score during the i-th visit.

[0132] Resource ownership equipment RO u Upon receiving resource request M, the device trust assessment score is first verified. i ≥Score min Among them, Score min This is the lowest trust score, or evaluation threshold, that the resource to be accessed can tolerate from any device. After successful verification, the resource-owning device verifies whether the attribute weights corresponding to the attributes in the access attribute sequence meet the requirements of the reference attribute weights corresponding to the requested resource, as follows.

[0133] In the resource request (S) i,1 ,S i,2 ,…,S i,r ) and resource ownership equipment RO u Public serial number (S) v,1 ,S v,2 ,…,S v,t Matching is performed for (t≤r).

[0134] Resource ownership equipment RO u Calculate φ i,m =H1(S i,1 ||S i,2 ||…||S i,r ||keyword v,m g1, in equation If true, the attribute weights corresponding to the attributes in the access attribute sequence are determined to satisfy the reference attribute weights corresponding to the requested resource, where e represents the bilinear mapping G1×G1→G2 and G2 represents the multiplicative group on the q-order elliptic curve.

[0135] Obtaining and decrypting the ciphertext of the requested resource based on the ciphertext address link includes: using the publicly available attribute sequence number. and resource access device d i Corresponding attribute weight T i,j The Lagrange polynomial is used to recover f(x).

[0136]

[0137] g(x) = f(x).

[0138] Resource access device d i Decryption key for computed resource ciphertext by Decrypting the ciphertext of the resource c v,m Obtain plaintext resources

[0139] In this embodiment, resource access permissions are bound to device attributes, and resource access control permissions are allocated through device attributes, making resource access control more granular and flexible. Compared with access control models in traditional network environments, this model has lower computational complexity, shorter computation time, and lower communication overhead.

[0140] Figure 3 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 3As shown, the electronic device may include a processor 310, a communications interface 320, a memory 330, and a communication bus 340. The processor 310, communications interface 320, and memory 330 communicate with each other via the communication bus 340. The processor 310 can invoke logical instructions from the memory 330 to execute an access control method based on a dynamic stealth network, including the following steps.

[0141] The resource access device uploads the access attribute sequence of this access to the certification authority. The access attribute sequence is used to instruct the certification authority to calculate the trust assessment score of the resource access device based on the access attribute sequence, and broadcast the assessment threshold corresponding to the trust assessment score in the dynamic stealth network.

[0142] When the trust assessment score reaches the assessment threshold, the device receives the serial number of the attribute in the device attribute sequence, the key and public key of the resource access device, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device. The access attribute sequence is a subset of the device attribute sequence.

[0143] If authentication is successful, a first signature is calculated based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the requested resource.

[0144] A resource request is sent to the resource-owning device. The resource request includes: the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the requested resource, and the trust evaluation score. The resource request is used to instruct the resource-owning device to verify the trust evaluation score based on an evaluation threshold. If the trust evaluation score is greater than the evaluation threshold, the device verifies whether the attribute weight corresponding to the attribute in the access attribute sequence meets the requirements of the reference attribute weight corresponding to the requested resource based on the first signature and the public key of the resource access device. If the requirements are met, the encrypted address link of the requested resource is sent to the resource access device.

[0145] Obtain the ciphertext of the requested resource based on the ciphertext address link and then decrypt it.

[0146] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0147] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the access control method based on the dynamic stealth network provided by the above methods, including the following steps.

[0148] The resource access device uploads the access attribute sequence of this access to the certification authority. The access attribute sequence is used to instruct the certification authority to calculate the trust assessment score of the resource access device based on the access attribute sequence, and broadcast the assessment threshold corresponding to the trust assessment score in the dynamic stealth network.

[0149] When the trust assessment score reaches the assessment threshold, the device receives the serial number of the attribute in the device attribute sequence, the key and public key of the resource access device, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device. The access attribute sequence is a subset of the device attribute sequence.

[0150] If authentication is successful, a first signature is calculated based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the requested resource.

[0151] A resource request is sent to the resource-owning device. The resource request includes: the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the requested resource, and the trust evaluation score. The resource request is used to instruct the resource-owning device to verify the trust evaluation score based on an evaluation threshold. If the trust evaluation score is greater than the evaluation threshold, the device verifies whether the attribute weight corresponding to the attribute in the access attribute sequence meets the requirements of the reference attribute weight corresponding to the requested resource based on the first signature and the public key of the resource access device. If the requirements are met, the encrypted address link of the requested resource is sent to the resource access device.

[0152] Obtain the ciphertext of the requested resource based on the ciphertext address link and then decrypt it.

[0153] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is implemented to perform the access control method based on the dynamic stealth network provided by the above methods, including the following steps.

[0154] The resource access device uploads the access attribute sequence of this access to the certification authority. The access attribute sequence is used to instruct the certification authority to calculate the trust assessment score of the resource access device based on the access attribute sequence, and broadcast the assessment threshold corresponding to the trust assessment score in the dynamic stealth network.

[0155] When the trust assessment score reaches the assessment threshold, the device receives the serial number of the attribute in the device attribute sequence, the key and public key of the resource access device, and interacts with the certification authority based on the identity ID and the serial number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device. The access attribute sequence is a subset of the device attribute sequence.

[0156] If authentication is successful, a first signature is calculated based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence, and the keyword of the requested resource.

[0157] A resource request is sent to the resource-owning device. The resource request includes: the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the requested resource, and the trust evaluation score. The resource request is used to instruct the resource-owning device to verify the trust evaluation score based on an evaluation threshold. If the trust evaluation score is greater than the evaluation threshold, the device verifies whether the attribute weight corresponding to the attribute in the access attribute sequence meets the requirements of the reference attribute weight corresponding to the requested resource based on the first signature and the public key of the resource access device. If the requirements are met, the encrypted address link of the requested resource is sent to the resource access device.

[0158] Obtain the ciphertext of the requested resource based on the ciphertext address link and then decrypt it.

[0159] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0160] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for access control based on dynamic cloaking network, characterized in that, The method comprises the following steps: The resource access device uploads the access attribute sequence of this access to the authentication agency, wherein the access attribute sequence is used to instruct the authentication agency to calculate the trust evaluation score of the resource access device based on the access attribute sequence, and broadcast the evaluation threshold corresponding to the trust evaluation score in the dynamic stealth network; In the case that the trust evaluation score reaches the evaluation threshold, the sequence number of the attribute in the device attribute sequence, the key and the public key of the resource access device issued by the authentication agency are received, and the authentication agency is interacted based on the identity ID and the sequence number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device, wherein the access attribute sequence is a subset of the device attribute sequence; In the case of successful authentication, the first signature is calculated based on the key of the resource access device, the sequence number of the attribute in the access attribute sequence and the keyword of the to-be-requested resource; The resource request is sent to the resource possession device, wherein the resource request comprises the identity ID, the public key of the resource access device, the sequence number of the attribute in the access attribute sequence, the first signature, the keyword of the to-be-requested resource and the trust evaluation score, and the resource request is used to instruct the resource possession device to verify the trust evaluation score based on the evaluation threshold, in the case that the trust evaluation score is greater than the evaluation threshold, verify whether the attribute weight corresponding to the attribute in the access attribute sequence meets the requirement of the reference attribute weight of the to-be-requested resource based on the first signature and the public key of the resource access device, and in the case of meeting the requirement, send the ciphertext address link of the to-be-requested resource to the resource access device; The ciphertext of the to-be-requested resource is obtained based on the ciphertext address link and decrypted; The sequence number of the attribute in the device attribute sequence, the key and the public key of the resource access device issued by the authentication agency are received, and the authentication agency is interacted based on the identity ID and the sequence number of the attribute in the access attribute sequence to perform identity and attribute weight authentication on the resource access device, comprising: The device attribute sequence and the corresponding sequence number set thereof issued by the authentication agency are received, and the first hidden attribute of the attribute in the access attribute sequence is calculated based on the sequence number according to the first random positive integer; The second signature is calculated based on the first random positive integer, the first hidden attribute and the public key of the authentication agency; The identity ID, the public key of the resource access device, the second signature and the first hidden attribute and the corresponding sequence number thereof are packaged into the first message and sent to the authentication agency, so that the authentication agency verifies the legality of the identity based on the first message and the key of the authentication agency, in the case of verification, the second hidden attribute is calculated based on the first hidden attribute, and the third signature is calculated based on the private key of the authentication agency and the attribute in the access attribute sequence, and the third signature, the public key of the authentication agency and the second hidden attribute are packaged into the second message and sent to the resource access device; The attribute weight of the attribute in the access attribute sequence is calculated based on the second message and the first random positive integer, and the legality of the attribute weight is verified based on the sum of the attribute weights, the third signature and the public key of the authentication agency, and in the case of verification, the identity and attribute weight authentication of the resource access device in the authentication agency is completed.

2. The dynamic cloaking network based access control method of claim 1, wherein, The first hidden attribute and the second signature are calculated according to the following equations : ; ; wherein, represents a first hidden attribute of a first attribute in a sequence of access attributes of a resource access device , r represents a first attribute in a sequence of access attributes of a resource access device , represents a first random positive integer corresponding to the resource access device , represents a public key of an authentication authority, represents a hash function of , is an additive group on an elliptic curve of order , is a generator of , represents a cyclic group, and || represents data concatenation.

3. The dynamic cloaking network based access control method of claim 2, wherein, The authentication authority verifies the legality of the identity based on the first message and the key of the authentication authority in the following manner: Computing ; Verify whether the following two equations are correct: ; ; wherein denotes an identity ID of the resource access device , denotes a key of the certification authority, denotes a public key of the resource access device , is an intermediate variable, denotes a hash function. If both equations are correct, the identity authentication is legal.

4. The dynamic cloaking network based access control method of claim 2, wherein, The authentication authority calculates the second hidden attribute based on the first hidden attribute, and calculates the third signature according to the private key of the authentication authority and the attribute in the attribute sequence, in the following manner: For each attribute select a second random positive integer , , compute the second hidden attribute as: ; The third signature is calculated according to the following formula: ; wherein, represents a key of an authentication authority, for different resource access devices and any attribute of and , if then .

5. The dynamic cloaking network based access control method of claim 4, wherein, Based on the second message and the first random positive integer, the attribute weight of the attribute in the attribute sequence is calculated, and the legality of the attribute weight is verified based on the sum of the attribute weight, the third signature and the public key of the authentication authority, including: the attribute weight of the attribute in the attribute sequence is calculated according to the following formula: ; The sum of the attribute weights is: ; In case of equality the legality of the attribute weight is determined, and the resource access device is obtained attribute weight of each attribute of , wherein denotes a bilinear mapping denotes multiplication group on elliptic curve of order 6. The dynamic cloaking network based access control method according to any one of claims 2 to 5, characterized in that, The reference attribute weight is set by the resource possession device in the following manner: Resource owning device RO u Obtain the set of attributes for all devices from the certification authority The resource owning device computes the attribute weights: ; wherein represents a random number; Resource owning device RO u Randomly selecting encryption parameters , computing the owned resources m Encryption key ; Resource owning device RO u Encrypting the v first resource , obtaining the ciphertext of the resource , denotes an exclusive OR operation;​ For accessing a resource Required t Different reference attribute weights, the sequence number of the corresponding attribute is Select Random number Construct polynomial : ; Resource owning device RO u hash value of the reference attribute weight corresponding to the attribute serial number input to the polynomial , output t function values ; A first u resource-owning device RO u A second resource-access device A database An identity ID of the resource-owning device RO u A public key of the resource-owning device RO u A hash function of the resource-owning device An elliptic curve of order An additive group on the elliptic curve A generator of the elliptic curve​​​​​ 7. The dynamic cloaking network-based access control method of claim 6, wherein, The first signature is calculated based on a key of a resource access device, a serial number of an attribute in an attribute sequence, and a keyword of a resource to be requested, including: calculating the first signature in the following manner : ; a key of the resource access device , a hash function of , a sequence number of an th attribute in an attribute sequence of the resource access device t th attribute in an attribute sequence of the resource access device The resource request is: wherein, denotes an identity ID of the resource access device denotes a public key of the resource access device denotes a trust evaluation score at the nth access, denotes a trust evaluation score at the i nth access, Resource owning device RO u The attribute weight corresponding to the attribute in the access attribute sequence is verified as follows: matching the resource request to a resource request template with the resource owning device RO u disclosed serial number performing a match, wherein ; Resource owning device RO u Computing , in case that the equation holds, determining that the attribute weight corresponding to the attribute in the attribute sequence satisfies the reference attribute weight corresponding to the resource to be requested, wherein denotes a bilinear mapping, denotes a multiplication group on an elliptic curve of order Based on the ciphertext address link, the ciphertext of the resource to be requested is obtained and decrypted, including: Utilizing a published attribute serial number and resource access device corresponding attribute weight , employing lagrange polynomial recovery wherein ; ; ; Resource access device Decryption key for a computational resource ciphertext to Decrypting a resource ciphertext Obtaining a resource plaintext .

8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to realize the access control method based on the dynamic stealth network as claimed in any one of claims 1 to 7. 9.A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the access control method based on the dynamic stealth network as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Zero-trust dynamic access control method based on GBDS user credibility evaluation

    CN115549973A

  • Service providing device

    JP2012063994A