A data access rights management method and system based on smart contracts

By analyzing data access events and current permission policies on the blockchain, making decisions and implementing temporary permission adjustments, the problem of difficulty in flexibly adjusting permission management in the existing technology is solved, and the effect of dynamic response to data access needs is achieved.

CN119598521BActive Publication Date: 2025-05-20INST OF APPLIED MATHEMATICS HEBEI ACADEMY OF SCI
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510142053.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-20
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

The existing blockchain data access permission management methods are difficult to flexibly adjust permissions and cannot dynamically respond to changes in data access requirements.

Method used

By analyzing data access events on the blockchain in the past period of time, combining the permission management strategy of the current smart contract, the temporary management strategy and duration of the decision-making permissions, and temporarily updating the smart contract in the future period of time to dynamically adjust data access permissions.

Benefits of technology

It realizes dynamic adjustment of blockchain data access rights based on data access needs, improving the applicability and responsiveness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119598521B_ABST
    Figure CN119598521B_ABST
Patent Text Reader

Abstract

The present invention provides a data access permission management method and system based on smart contracts, wherein the method includes: obtaining data access events of a blockchain in a first time period in the past; wherein the duration of the first time period is a standard duration; based on the data access events, deciding a temporary permission management strategy and a temporary permission management duration; based on the temporary permission management strategy, managing the data access permission of the blockchain accordingly in a second time period in the future; wherein the duration of the second time period is the temporary permission management duration. The data access permission management method and system based on smart contracts of the present invention dynamically and flexibly adjust the data access permission of the blockchain according to the access requirements of the data, greatly improving the applicability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of permission management, and particularly to a method and system for data access permission management based on smart contracts. Background Art

[0002] Blockchain is a decentralized distributed ledger technology that can store and transmit data among multiple nodes. A smart contract in blockchain is a self-executing contract, the terms and conditions of which are written into the contract in the form of code and can be automatically executed when specific conditions are met. The advantages of smart contracts lie in their automation, transparency, and trustlessness, which enable their wide application in various scenarios.

[0003] In blockchain, most traditional data access permission management is static, that is, the access permissions of users to data are determined by the preset rules in the smart contract.

[0004] However, in practical applications, the access requirements of data may change with factors such as time, environment, and user behavior. Therefore, how to flexibly adjust the data access permissions of blockchain has become a new challenge. Summary of the Invention

[0005] One object of the present invention is to provide a method for data access permission management based on smart contracts. By analyzing the data access events recorded in the blockchain in the past first time period and combining the existing permission management strategies in the current smart contract, the temporary permission management strategy and the duration of temporary permission management are determined. Based on the temporary permission management strategy, the smart contract is temporarily updated in the future second time period to perform corresponding first temporary management on the data access permissions of the blockchain, so as to dynamically and flexibly adjust the data access permissions of the blockchain according to the access requirements of the data, greatly improving the applicability of the system.

[0006] A method for data access permission management based on smart contracts provided by an embodiment of the present invention includes:

[0007] Determine the temporary permission management strategy and the duration of temporary permission management based on the data access events in the blockchain in the past first time period and the current permission management strategy in the smart contract of the blockchain; wherein, the duration of the first time period is the first standard duration;

[0008] Temporarily update the smart contract in the future second time period based on the temporary permission management strategy to perform corresponding first temporary management on the data access permissions of the blockchain; wherein, the duration of the second time period is the duration of temporary permission management.

[0009] Optionally, the decision-making of the temporary permission management policy and the temporary permission management duration based on the data access events of the blockchain within the past first time period and the current permission management policy in the smart contract of the blockchain includes:

[0010] Perform feature description processing on the data access event to obtain a first feature description vector;

[0011] Determine the mapping knowledge corresponding to the first feature description vector from the mapping knowledge base;

[0012] Invite data access permissions for the data access nodes of the blockchain;

[0013] Obtain the acceptance feedback information of the data access nodes that accept the data access permission invitation;

[0014] Extract the mapping relationship between the acceptance feedback information and the mapping knowledge;

[0015] Perform feature description processing on the mapping relationship to obtain a second feature description vector;

[0016] Determine the decision-making knowledge corresponding to the second feature description vector from the decision-making knowledge base;

[0017] Compare with the decision-making knowledge to make decisions on the temporary permission management policy and the temporary permission management duration.

[0018] Optionally, the data access permission management method based on the smart contract further includes:

[0019] When multiple users in the same user group jointly access the blockchain within the future third time period, generate an access association circle for each user; wherein, each user in the same user group is pre-bound, and at least one user in the same user group is related to the temporary permission management policy; the future third time period is after the future second time period and adjacent to the future second time period, and the duration of the third time period is the second standard duration;

[0020] Based on the access interaction circle, modify the temporary permission management policy;

[0021] Based on the modified temporary permission management policy, temporarily update the smart contract within the future third time period to perform corresponding second temporary management on the data access permissions of the blockchain.

[0022] Optionally, the generation of the access association circle for each user includes:

[0023] Determine a first target user from each user; wherein, the first target user has the highest frequency of accessing the blockchain within the most recent preset first time;

[0024] Obtain multiple first historical items generated by the first target user for data access to the blockchain within the third future time period;

[0025] Determine the target historical item from each of the first historical items; among them, the historical item type of the target historical item matches the standard historical item type;

[0026] Obtain the earliest generation time and the latest generation time of the target historical item;

[0027] Determine the start time of the interval; among them, if the target time of the second preset time before the earliest generation time is earlier than the start time of the third future time period, use the start time of the third future time period as the start time of the interval; otherwise, use the target time as the start time of the interval;

[0028] Determine the end time of the interval; among them, the end time of the interval is the latest generation time;

[0029] Based on the start time of the interval and the end time of the interval, determine the target time interval;

[0030] Classify and count the target historical items to obtain the category distribution;

[0031] Determine the historical item conditions corresponding to the category distribution from the historical item condition library;

[0032] Determine the second target user other than the first target user from each user; among them, multiple second historical items generated by the second target user for data access to the blockchain within the target time interval meet the historical item conditions;

[0033] Generate an access association circle based on the first target user and the second target user.

[0034] Optionally, the modifying the temporary permission management policy based on the access interaction circle includes:

[0035] Perform feature description processing on the access interaction circle and the interaction circle relationships between pairs of access interaction circles to obtain a third feature description vector;

[0036] Determine the first correction knowledge corresponding to the third feature description vector from the first correction knowledge base;

[0037] Compare with the first correction knowledge and modify the temporary permission management policy.

[0038] Optionally, the modifying the temporary permission management policy based on the access interaction circle includes:

[0039] Count the number of interaction circles of the access interaction circle;

[0040] Based on the temporary permission management policy and the personnel distribution of the user group, determine the reasonable number of interaction circles;

[0041] When the target difference that the number of interaction circles is less than the reasonable number of interaction circles exceeds the difference threshold, perform feature description processing on the target difference and the policy type of the temporary permission management policy to obtain a fourth feature description vector;

[0042] Determine the second corrected knowledge corresponding to the fourth feature description vector from the second corrected knowledge base;

[0043] Compare with the second corrected knowledge and correct the temporary permission management policy.

[0044] A data access permission management system based on smart contracts provided by an embodiment of the present invention includes:

[0045] A decision-making module, configured to make decisions on a temporary permission management policy and a temporary permission management duration based on data access events on the blockchain and the current permission management policy in the smart contract of the blockchain within a past first time period; wherein, the duration of the first time period is a first standard duration;

[0046] A first management module, configured to temporarily update the smart contract within a future second time period based on the temporary permission management policy to perform corresponding first temporary management on the data access permission of the blockchain; wherein, the duration of the second time period is the temporary permission management duration.

[0047] Optionally, the decision-making module makes decisions on a temporary permission management policy and a temporary permission management duration based on data access events on the blockchain and the current permission management policy in the smart contract of the blockchain, including:

[0048] Perform feature description processing on the data access events to obtain a first feature description vector;

[0049] Determine the mapping knowledge corresponding to the first feature description vector from the mapping knowledge base;

[0050] Send a data access permission invitation to the data access node of the blockchain;

[0051] Obtain the acceptance feedback information of the data access node that accepts the data access permission invitation;

[0052] Extract the mapping relationship between the acceptance feedback information and the mapping knowledge;

[0053] Perform feature description processing on the mapping relationship to obtain a second feature description vector;

[0054] Determine the decision-making knowledge corresponding to the second feature description vector from the decision-making knowledge base;

[0055] Compare with the decision-making knowledge and make decisions on the temporary permission management policy and the temporary permission management duration.

[0056] Optionally, the data access permission management system based on smart contracts further includes:

[0057] A generation module, configured to generate an access association circle for each user when multiple users in the same user group jointly access data on the blockchain in a third future time period; wherein, each user in the same user group is pre-bound, and at least one user in the same user group is related to the temporary permission management policy; the third future time period is after and adjacent to the second future time period, and the duration of the third time period is the second standard duration;

[0058] A correction module, configured to correct the temporary permission management policy based on the access interaction circle;

[0059] A second management module, configured to temporarily update the smart contract in the third future time period based on the corrected temporary permission management policy to perform corresponding second temporary management on the data access permission of the blockchain.

[0060] Optionally, when the generation module generates the access association circle for each user, it includes:

[0061] Determine a first target user from each user; wherein, the first target user has the highest frequency of accessing data on the blockchain in the most recent preset first time;

[0062] Obtain multiple first historical items generated by the first target user accessing data on the blockchain in the third future time period;

[0063] Determine a target historical item from each first historical item; wherein, the historical item type of the target historical item matches the standard historical item type;

[0064] Obtain the earliest generation time and the latest generation time of the target historical item;

[0065] Determine the start time of the interval; wherein, if the target time at the second time preset before the earliest generation time is earlier than the start time of the third future time period, use the start time of the third future time period as the start time of the interval; otherwise, use the target time as the start time of the interval;

[0066] Determine the end time of the interval; wherein, the end time of the interval is the latest generation time;

[0067] Based on the start time of the interval and the end time of the interval, determine the target time interval;

[0068] Classify and count the target historical items to obtain the category distribution;

[0069] Determine the historical item conditions corresponding to the category distribution from the historical item condition library;

[0070] Determine a second target user other than the first target user from each user; wherein, multiple second historical items generated by the second target user for data access to the blockchain within the target time interval meet the historical item conditions;

[0071] Generate an access association circle based on the first target user and the second target user.

[0072] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in the written specification and the drawings.

[0073] The technical solutions of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings

[0074] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0075] Figure 1 It is a schematic diagram of a method for managing data access permissions based on a smart contract in an embodiment of the present invention;

[0076] Figure 2 It is a schematic diagram of a system for managing data access permissions based on a smart contract in an embodiment of the present invention. Detailed Embodiments

[0077] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0078] An embodiment of the present invention provides a method for managing data access permissions based on a smart contract, as Figure 1 shown, including:

[0079] S1. Based on the data access events of the blockchain within the past first time period and the current permission management policy in the smart contract of the blockchain, determine a temporary permission management policy and a temporary permission management duration; wherein, the duration of the first time period is the first standard duration;

[0080] In S1, the data access event is an event where a user records a data plan on the blockchain, which can be any access behavior of the user to data, such as operations like querying, modifying, or trading. The data access event will be recorded on the blockchain and serve as the basis for subsequent permission management decisions. The past first time period is the time range for analyzing the data access event, and its duration is the first standard duration, such as one day. The current permission management policy is the permission control rules currently defined in the smart contract in the blockchain, such as who can access the data, when they can access the data, and the access permission level. The temporary permission management policy is a policy for adjusting data access permissions determined based on the analysis of data access events in the past first time period. For example, if the data access event reflects that a certain user frequently requests access to some sensitive data, the temporary permission management policy is to temporarily increase the access permission for this sensitive data. The temporary permission management duration is the effective time length of the temporary permission management policy.

[0081] S2. Based on the temporary permission management policy, temporarily update the smart contract within the future second time period to perform corresponding first temporary management on the data access permissions of the blockchain. The duration of the second time period is the temporary permission management duration.

[0082] In S2, the future second time period is the time period after the temporary permission management policy takes effect, and its duration is the temporary permission management duration. When temporarily updating the smart contract based on the temporary permission management policy, the permissions in the smart contract will be adjusted according to the temporary management policy, thereby realizing corresponding first temporary management of the data access permissions of the blockchain.

[0083] This application analyzes the data access events recorded in the blockchain in the past first time period, combines the existing permission management policies in the current smart contract, determines the temporary permission management policy and the temporary permission management duration, and based on the temporary permission management policy, temporarily updates the smart contract within the future second time period to perform corresponding first temporary management on the data access permissions of the blockchain, dynamically and flexibly adjusting the data access permissions of the blockchain according to the access requirements of the data, and greatly improving the applicability of the system.

[0084] In one embodiment, in S1, based on the data access events in the blockchain in the past first time period and the current permission management policy in the smart contract of the blockchain, determining the temporary permission management policy and the temporary permission management duration includes:

[0085] S11. Perform feature description processing on the data access event to obtain a first feature description vector.

[0086] In S11, when performing the above feature description process, extract the features of the data access event, such as: access frequency, access data type, user role, etc., convert the extracted features into the form of a digital vector to obtain the first feature description vector, and the first feature description vector represents the feature situation of the data access event;

[0087] S12. Determine the mapping knowledge corresponding to the first feature description vector from the mapping knowledge base;

[0088] In S12, there is mapping knowledge corresponding to different first feature description vectors in the mapping knowledge base. The mapping knowledge is the data access permission adjustment measures that need to be taken and the possible data access requirements under the feature situation of the data access event represented by the first feature description vector. For example, if the feature situation of the data access event represented by the first feature description vector is that a user frequently accesses certain private data, the mapping knowledge is to temporarily elevate the user's permission and that the user urgently needs to access relevant other private data;

[0089] S13. Invite the data access nodes of the blockchain for data access permission;

[0090] In S13, the data access nodes are users, administrators or other participants who perform data access in the blockchain; when inviting for data access permission, invite the data access nodes to give feedback on their data access permission adjustment requirements, etc. for data access on the blockchain;

[0091] S14. Obtain the acceptance feedback information of the data access nodes that accept the data access permission invitation;

[0092] In S14, the corresponding acceptance feedback information is the permission adjustment requirements, etc.;

[0093] S15. Extract the mapping relationship between the acceptance feedback information and the mapping knowledge;

[0094] In S15, the mapping relationship can be that the data access permission adjustment measures that need to be taken in the mapping knowledge match the permission adjustment requirements in the acceptance feedback information, etc.;

[0095] S16. Perform feature description processing on the mapping relationship to obtain the second feature description vector;

[0096] In S16, similarly, when performing the above feature description process, extract the features of the mapping relationship, such as: temporarily elevate the user's permission, the user needs to elevate the permission, etc., convert the extracted features into the form of a digital vector to obtain the second feature description vector, and the second feature description vector represents the feature situation of the mapping relationship;

[0097] S17. Determine the decision knowledge corresponding to the second feature description vector from the decision knowledge base;

[0098] In S17, there is decision-making knowledge corresponding to different second feature description vectors in the decision-making knowledge base. The decision-making knowledge is the measures of the temporary management strategy of decision-making authority and the temporary management duration of authority in the case of the features of the mapping relationship represented by the second feature description vector. For example, if the feature situation of the mapping relationship represented by the second feature description vector is that the user's authority needs to be temporarily elevated to meet the user's needs, then verify whether there is any malicious access behavior when the user's authority was elevated historically. If not, temporarily extract its authority as the temporary management strategy of decision-making authority, and use the time required to access other relevant private data as the temporary management duration of authority;

[0099] S18. Compare with the decision-making knowledge, the temporary management strategy of decision-making authority and the temporary management duration of authority.

[0100] In S18, finally, comparing with the decision-making knowledge, the decision on the temporary management strategy of decision-making authority and the temporary management duration of authority can be made.

[0101] The embodiment of the present invention introduces the mapping knowledge corresponding to the first feature description vector obtained by performing feature description processing on the data access event, invites the data access permission for the data access node, extracts the mapping relationship between its received feedback information and the mapping knowledge, performs feature description processing on the mapping relationship to obtain the second feature description vector, introduces the decision-making knowledge corresponding to the second feature description vector, and compares with the decision-making knowledge, the temporary management strategy of decision-making authority and the temporary management duration of authority, which greatly improves the decision-making accuracy, comprehensiveness and efficiency of the temporary management strategy of decision-making authority and the temporary management duration of authority; by temporarily adjusting the data access permission at a specific duration, the system can quickly respond to the special access needs of users without affecting the overall security. Especially when it comes to accessing private data, this flexible adjustment can ensure the balance between data access efficiency and user needs; the accurate decision on the temporary management duration of authority can effectively avoid excessive temporary adjustment of authority, reduce unnecessary resource consumption, and maximize the efficiency of blockchain data access.

[0102] In one embodiment, the method for managing data access permission based on smart contract further includes:

[0103] S3. When multiple users in the same user group jointly access the blockchain data in the future third time period, generate an access association circle for each user; wherein, each user in the same user group is pre-bound, and at least one user in the same user group is related to the temporary management strategy of authority; the future third time period is after the future second time period and adjacent to the future second time period, and the duration of the third time period is the second standard duration;

[0104] In S3, the user related to the temporary permission management policy refers to the adjustment of the user's data access permissions by the temporary permission management policy; the user group can be users with similar functions, permissions, or business requirements, and they can be pre-bound; the second standard duration can be, for example, 1 hour; within the second future time period, when at least one user in the user group accesses after adjusting their data access permissions through the temporary permission management policy, there may be a need to jointly access the blockchain data with other users in the future, such as: in a medical institution, after doctor A adjusts their data access permissions through the temporary permission management policy, they can access the medical record information of a certain patient. Then, they may want to jointly access the medical record information, treatment plans, etc. of this patient and patients with similar diseases with nurse B and pharmacist C in the future for further treatment decisions. At this time, the user can pre-bind with other users to form a user group; the access association circle is the relationship circle formed when the user group jointly accesses the blockchain data within the third future time period, which can indicate the access association situation among users in the user group, such as: access intersection, interaction behavior, and access mode, etc.

[0105] S4. Modify the temporary permission management policy based on the access interaction circle;

[0106] In S4, the access interaction circle indicates the access association situation among users in the user group. Therefore, the temporary permission management policy can be modified based on it to further adapt to and adjust the access permissions of the user group to access the blockchain data;

[0107] S5. Based on the modified temporary permission management policy, temporarily update the smart contract within the third future time period to perform corresponding second temporary management on the data access permissions of the blockchain.

[0108] In S5, similarly, based on the modified temporary permission management policy, temporarily update the smart contract within the third future time period. The permissions in the smart contract will be adjusted according to the temporary management policy, thereby realizing corresponding second temporary management on the data access permissions of the blockchain.

[0109] The embodiment of the present invention forms a constraint on the user group, accurately determines the situation that when at least one user in the user group accesses after adjusting their data access permissions through the temporary permission management policy, there may be a need to jointly access the blockchain data with other users in the future, and further adapts to and adjusts the access permissions of the user group to access the blockchain data, improving the system's ability to handle this special situation and enhancing the applicability of the system; when further adapting to and adjusting the access permissions of the user group to access the blockchain data, the temporary permission management policy is modified based on the access interaction circle, improving the accuracy, comprehensiveness, and efficiency of the modification of the temporary permission management policy.

[0110] In one embodiment, in S3, generating an access association circle for each user includes:

[0111] S301. Determine a first target user from each user; wherein, the first target user has the highest frequency of accessing the blockchain data within a recently preset first time period;

[0112] In S301, the recently preset first time period can be the most recent 10 minutes; the fact that the first target user has the highest frequency of accessing the blockchain data within the recently preset first time period indicates that its data access situation has a greater impact on future data access management;

[0113] S302. Obtain a plurality of first historical items generated by the first target user accessing the blockchain data within a third time period in the future;

[0114] In S302, correspondingly, the first historical item can be the access operation, timestamp, and specific data accessed by the first target user, etc.;

[0115] S303. Determine a target historical item from each of the first historical items; wherein, the historical item type of the target historical item matches the standard historical item type;

[0116] In S303, the standard historical item type is the historical item type that can indicate the possible access association situation between the first target user and other users during the joint access process, such as: blockchain transactions, accessing data accessed by other users, etc.;

[0117] S304. Obtain the earliest generation time and the latest generation time of the target historical item;

[0118] In S304, the earliest generation time and the latest generation time refer to the time when the first target user first generates the target historical item and the time when the first target user last generates the target historical item;

[0119] S305. Determine the starting time of the interval; wherein, if the target time of the second time preset before the earliest generation time is earlier than the starting time of the third time period in the future, use the starting time of the third time period in the future as the starting time of the interval; otherwise, use the target time as the starting time of the interval;

[0120] In S305, the preset second time can be 2 minutes; there may be an access association situation between the first target user and other users during the joint access process before the earliest generation time, but it needs to be restricted within the third time period in the future. Therefore, if the target time of the second time preset before the earliest generation time is earlier than the starting time of the third time period in the future, use the starting time of the third time period in the future as the starting time of the interval, otherwise, use the target time as the starting time of the interval;

[0121] S306. Determine the end time of the interval; where the end time of the interval is the latest generation time;

[0122] In S306, after the latest generation time, it is highly unlikely that the first target user will have an access association with other users during the joint access process. Therefore, the latest generation time is used as the end time of the interval;

[0123] S307. Based on the start time of the interval and the end time of the interval, determine the target time interval;

[0124] In S307, during the period between the start time of the interval and the end time of the interval, the first target user may have an access association with other users during the joint access process. Therefore, the target time interval is determined based on these two;

[0125] S308. Classify and count the target historical items to obtain the category distribution;

[0126] In S308, the category distribution refers to the categories involved in the target historical items and the corresponding number of historical items;

[0127] S309. Determine the historical item conditions corresponding to the category distribution from the historical item condition library;

[0128] In S309, the historical item conditions are used to screen other users who have access association situations with other users; the same type of target historical items indicate that the first target user may have the same access association situation with other users during the joint access process. Therefore, the more target historical items of a certain same type, the greater the possibility that the first target user indicated by the same type of target historical items may have the same access association situation with other users during the joint access process. Therefore, the historical item conditions can be determined based on it. For example: in the category distribution, the category is blockchain transactions, the corresponding number of historical items is 5, and the corresponding number of historical items is relatively large, representing a relatively high possibility of the occurrence of the access association situation, then the screening is looser, and the corresponding historical item condition is that the historical item indicates that the user generates any behavior related to blockchain transactions, and the user meeting this historical item condition means that they also want to participate in blockchain transactions or understand blockchain transactions or pay attention to blockchain transactions, etc.;

[0129] S310. Determine the second target users other than the first target user from each user; where the multiple second historical items generated by the second target users' data access to the blockchain within the target time interval meet the historical item conditions;

[0130] In S310, the second historical item may be the access operation, timestamp, and specific accessed data of the second target user, etc.; if multiple second historical items generated by the second target user during the target time interval for data access to the blockchain meet the historical item conditions, it indicates the access association situation generated during the joint access process with the first target user.

[0131] S311. Generate an access association circle based on the first target user and the second target user.

[0132] In S311, finally, generate an access association circle based on the first target user and the second target user, that is, the access association circle indicates the access association situation between the first target user and the second target user.

[0133] In the embodiment of the present invention, the first target user with the highest data access frequency to the blockchain within the recently preset first time is determined, and multiple first historical items of it are obtained. The target historical items whose historical item types match the standard historical item type are selected from them, and the start time and end time of the interval are determined based on the target historical items, thereby determining the target time interval, enabling the system to accurately identify the second target user with an access association situation generated during the joint access process with the first target user within a specific time interval, providing efficient support for the correction of the temporary permission management policy, avoiding analyzing irrelevant data in irrelevant time periods, and improving the generation efficiency of the access association circle.

[0134] In one embodiment, in S3, based on the access interaction circle, the correction of the temporary permission management policy includes:

[0135] Perform feature description processing on the access interaction circle and the interaction circle relationships between the access interaction circles in pairs to obtain a third feature description vector;

[0136] Determine the first correction knowledge corresponding to the third feature description vector from the first correction knowledge base;

[0137] Compare with the first correction knowledge and correct the temporary permission management policy.

[0138] The interaction circle relationship refers to the association relationship between pairwise access interaction circles, such as the existence of the same users, etc. When performing the above feature description processing, extract the features of the access interaction circles and the interaction circle relationships between pairwise access interaction circles, such as the number of access interaction circles, the maximum number of users in the access interaction circles, the same users in two access interaction circles, etc. Convert the extracted features into the form of digital vectors to obtain the third feature description vector, and the third feature description vector represents the feature situation of the access interaction circles and the interaction circle relationships between pairwise access interaction circles. The feature situation of the access interaction circles and the interaction circle relationships between pairwise access interaction circles represented by the third feature description vector can indicate how to correct the temporary permission management policy, that is, there is corresponding first correction knowledge. For example, if the feature situation of the access interaction circles and the interaction circle relationships between pairwise access interaction circles represented by the third feature description vector is that a certain user exists in all access interaction circles at the same time, it means that the generation of access association is the most active, and the temporary permission management policy can be corrected to improve its data access permission, enhance its data access ability, and it will continue to actively generate access association situations, thereby enhancing the joint access experience of the user group and improving the work efficiency of the user group. Then the corresponding first correction knowledge is to improve the data access permission of this user. Finally, compare with the first correction knowledge and correct the temporary permission management policy.

[0139] Through the intelligent and dynamic correction of the permission management policy in the embodiments of the present invention, data access and user collaboration become more efficient and personalized, avoiding the limitations brought by static permission settings, fully exploring the potential value of user interaction, and further improving the work efficiency of the entire team and the flexibility of the system.

[0140] In one embodiment, in S3, based on the access interaction circles, correcting the temporary permission management policy includes:

[0141] Count the number of interaction circles of the access interaction circles;

[0142] Based on the temporary permission management policy and the personnel distribution of the user group, determine the reasonable number of interaction circles;

[0143] When the target difference that the number of interaction circles is less than the reasonable number of interaction circles exceeds the difference threshold, perform feature description processing on the target difference and the policy type of the temporary permission management policy to obtain the fourth feature description vector;

[0144] Determine the second correction knowledge corresponding to the fourth feature description vector from the second correction knowledge base;

[0145] Compare with the second correction knowledge and correct the temporary permission management policy.

[0146] The number of interaction circles should be the number of access interaction circles that should be formed when each user in the user group fully generates access associations; the personnel distribution of the user group is the number of users related to the temporary permission management policy in the user group and the total number of users in the user group; the calculation formula for the number of interaction circles should be: , where is the number of interaction circles that should be,[[]] is the floor function,[[]] is the preset calculation coefficient corresponding to the permission type level of the permissions involved in the temporary permission management policy,[[]] is the total number of users in the user group,[[]] is the number of users in the user group related to the temporary permission management policy; in this formula, the higher the permission type level, the greater the possibility of access associations among users in the user group under the temporary permission management of the temporary permission management policy, and the greater the corresponding preset calculation coefficient; the calculation formula for the number of interaction circles that should be fully considers factors such as the permission type level and the number of users in the user group, ensuring the accuracy of the calculation of the number of interaction circles that should be; secondly, the number of interaction circles that should be can also be preset in advance by technical personnel according to the actual needs based on the temporary permission management policy and the personnel distribution of the user group; the difference threshold can be, for example: 3; when the target difference between the number of interaction circles and the number of interaction circles that should be exceeds the difference threshold, it indicates that the access associations among users in the user group are not sufficient; when performing the above feature description processing, the target difference and the policy type are converted into the form of digital vectors to obtain the fourth feature description vector, and the fourth feature description vector represents this insufficient situation; the insufficient situation represented by the fourth feature description vector can indicate how to correct the temporary permission management policy, that is, there is corresponding second correction knowledge, such as: if the insufficient situation represented by the fourth feature description vector is that the number of interaction circles is much less than the number of interaction circles that should be, and the policy type is to promote the permission of a certain user, then the permissions of other users in the user group except this user need to be promoted to enhance their enthusiasm for generating access associations, and the corresponding second correction knowledge is to promote the permissions of other users in the user group except this user; finally, the temporary permission management policy is corrected according to the second correction knowledge.[[]]

[0147] By counting the number of interaction circles and comparing it with the number of interaction circles that should be in the embodiments of the present invention, the temporary permission management policy can be dynamically adjusted to ensure that the policy can effectively promote necessary access associations in the user group, making the permission allocation more reasonable and refined, and greatly improving the applicability of the system.[[]]

[0148] The embodiments of the present invention provide a data access permission management system based on a smart contract, as Figure 2 shown, including:

[0149] A decision-making module 1, configured to determine a temporary permission management policy and a temporary permission management duration based on data access events of a blockchain within a past first time period and a current permission management policy in the smart contract of the blockchain; wherein, the duration of the first time period is a first standard duration.

[0150] A first management module 2, configured to temporarily update the smart contract within a future second time period based on the temporary permission management policy, so as to perform corresponding first temporary management on the data access permissions of the blockchain; wherein, the duration of the second time period is the temporary permission management duration.

[0151] The decision-making module determines a temporary permission management policy and a temporary permission management duration based on data access events of a blockchain within a past first time period and a current permission management policy in the smart contract of the blockchain, including:

[0152] Performing feature description processing on the data access events to obtain a first feature description vector;

[0153] Determining mapping knowledge corresponding to the first feature description vector from a mapping knowledge base;

[0154] Issuing an invitation for data access permissions to data access nodes of the blockchain;

[0155] Obtaining acceptance feedback information of data access nodes that accept the invitation for data access permissions;

[0156] Extracting the mapping relationship between the acceptance feedback information and the mapping knowledge;

[0157] Performing feature description processing on the mapping relationship to obtain a second feature description vector;

[0158] Determining decision-making knowledge corresponding to the second feature description vector from a decision-making knowledge base;

[0159] Comparing with the decision-making knowledge, determining the temporary permission management policy and the temporary permission management duration.

[0160] The data access permission management system based on a smart contract further includes:

[0161] A generation module, configured to generate an access association circle for each user when multiple users in the same user group jointly access the blockchain within a future third time period; wherein, each user in the same user group is pre-bound, and at least one user in the same user group is related to the temporary permission management policy; the future third time period is after and adjacent to the future second time period, and the duration of the third time period is a second standard duration.

[0162] A correction module, configured to correct the temporary permission management policy based on the access interaction circle.

[0163] A second management module, configured to temporarily update a smart contract within a third time period in the future based on the corrected temporary permission management policy, so as to perform corresponding second temporary management on the data access permission of the blockchain.

[0164] The generating module generates an access association circle for each user, including:

[0165] Determine a first target user from each user; wherein, the first target user has the highest frequency of accessing the blockchain data within a preset first time recently;

[0166] Obtain a plurality of first historical items generated by the first target user accessing the blockchain data within a third time period in the future;

[0167] Determine a target historical item from each first historical item; wherein, the historical item type of the target historical item matches the standard historical item type;

[0168] Obtain the earliest generation time and the latest generation time of the target historical item;

[0169] Determine the start time of the interval; wherein, if the target time at a preset second time before the earliest generation time is earlier than the start time of the third time period in the future, use the start time of the third time period in the future as the start time of the interval; otherwise, use the target time as the start time of the interval;

[0170] Determine the end time of the interval; wherein, the end time of the interval is the latest generation time;

[0171] Based on the start time of the interval and the end time of the interval, determine the target time interval;

[0172] Classify and count the target historical items to obtain a category distribution;

[0173] Determine the historical item conditions corresponding to the category distribution from the historical item condition library;

[0174] Determine a second target user other than the first target user from each user; wherein, a plurality of second historical items generated by the second target user accessing the blockchain data within the target time interval meet the historical item conditions;

[0175] Generate an access association circle based on the first target user and the second target user.

[0176] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A data access rights management method based on smart contracts, characterized in that: include: Based on the data access events of the blockchain in the past first time period and the current authority management strategy in the smart contract of the blockchain, the temporary authority management strategy and the temporary authority management duration are determined; wherein the duration of the first time period is the first standard duration; Based on the temporary permission management strategy, temporarily update the smart contract in the second time period in the future to perform corresponding first temporary management of the data access rights of the blockchain; wherein the duration of the second time period is the temporary permission management duration; The data access events of the blockchain in the past first time period and the current authority management strategy in the smart contract of the blockchain, the temporary management strategy of the decision-making authority and the temporary management duration of the authority include: Performing feature description processing on the data access event to obtain a first feature description vector; Determine mapping knowledge corresponding to the first feature description vector from a mapping knowledge base; Invite data access rights to the blockchain's data access nodes; Obtaining acceptance feedback information of the data access node that accepts the data access permission invitation; Extract the mapping relationship between the received feedback information and the mapping knowledge; Performing feature description processing on the mapping relationship to obtain a second feature description vector; Determining decision knowledge corresponding to the second feature description vector from a decision knowledge base; Compare decision-making knowledge, temporary management strategy of decision-making authority and duration of temporary management of authority.

2. The data access rights management method based on smart contracts according to claim 1, characterized in that: Also includes: When multiple users in the same user group jointly access data on the blockchain in the third time period in the future, an access association circle of each user is generated; wherein the users in the same user group are bound in advance, and at least one user in the same user group is related to the temporary permission management policy; the third time period in the future is after the second time period in the future and is adjacent to the second time period in the future, and the duration of the third time period is the second standard duration; Based on the access interaction circle, the temporary management strategy of permissions is modified; Based on the revised temporary permission management strategy, the smart contract is temporarily updated in the third time period in the future to perform a corresponding second temporary management of the data access rights of the blockchain.

3. The data access rights management method based on smart contracts as claimed in claim 2, characterized in that: The generating of the access association circle of each user includes: Determine a first target user from among the users; wherein the first target user has the highest frequency of accessing data on the blockchain within a recently preset first time period; Acquire multiple first historical items generated by the first target user accessing data on the blockchain within a third time period in the future; Determine a target history item from each first history item; wherein the history item type of the target history item matches the standard history item type; Get the earliest and latest generation time of the target history item; Determine the interval start time; if the target time of the second time preset before the earliest generation time is earlier than the start time of the third time period in the future, the start time of the third time period in the future is used as the interval start time; otherwise, the target time is used as the interval start time; Determine the interval end time; wherein the interval end time is the latest generated time; Determine the target time interval based on the interval start time and the interval end time; Classify and count the target historical items to obtain category distribution; Determine the historical item conditions corresponding to the category distribution from the historical item condition library; Determine a second target user other than the first target user from among the users; wherein a plurality of second historical items generated by the second target user accessing data on the blockchain within the target time interval meet the historical item condition; A visit association circle is generated based on the first target user and the second target user.

4. The data access rights management method based on smart contracts as claimed in claim 2, characterized in that: The modification of the temporary permission management strategy based on the access interaction circle includes: Performing feature description processing on the visit interaction circles and the interaction circle relationships between the visit interaction circles to obtain a third feature description vector; Determine the first revised knowledge corresponding to the third feature description vector from the first revised knowledge base; According to the first revision knowledge, revise the temporary management strategy of permissions.

5. The data access rights management method based on smart contracts as claimed in claim 2, characterized in that: The modification of the temporary permission management strategy based on the access interaction circle includes: Count the number of interaction circles that visit the interaction circle; Determine the appropriate number of interaction circles based on the temporary permission management strategy and the distribution of user groups; When the target difference value of the number of interaction circles less than the expected number of interaction circles exceeds the difference threshold, the target difference value and the policy type of the temporary authority management policy are subjected to feature description processing to obtain a fourth feature description vector; Determining second revised knowledge corresponding to the fourth feature description vector from the second revised knowledge base; According to the second revision knowledge, revise the temporary management strategy of permissions.

6. A data access rights management system based on smart contracts, characterized in that: include: A decision-making module, used to decide on a temporary authority management strategy and a temporary authority management duration based on data access events of the blockchain in the past first time period and the current authority management strategy in the smart contract of the blockchain; wherein the duration of the first time period is a first standard duration; A first management module is used to temporarily update the smart contract within a second time period in the future based on the temporary permission management strategy, so as to perform a corresponding first temporary management on the data access rights of the blockchain; wherein the duration of the second time period is the temporary permission management duration; The decision module decides the temporary management strategy of the authority and the temporary management duration of the authority based on the data access events of the blockchain in the past first time period and the current authority management strategy in the smart contract of the blockchain, including: Performing feature description processing on the data access event to obtain a first feature description vector; Determine mapping knowledge corresponding to the first feature description vector from a mapping knowledge base; Invite data access rights to the blockchain's data access nodes; Obtaining acceptance feedback information of the data access node that accepts the data access permission invitation; Extract the mapping relationship between the received feedback information and the mapping knowledge; Performing feature description processing on the mapping relationship to obtain a second feature description vector; Determining decision knowledge corresponding to the second feature description vector from a decision knowledge base; Compare decision-making knowledge, temporary management strategy of decision-making authority and duration of temporary management of authority.

7. The data access rights management system based on smart contracts as claimed in claim 6, characterized in that: Also includes: A generation module, used for generating an access association circle for each user when multiple users in the same user group jointly access data on the blockchain in a third time period in the future; wherein the users in the same user group are bound in advance, and at least one user in the same user group is related to the temporary permission management policy; the third time period in the future is after the second time period in the future and is adjacent to the second time period in the future, and the duration of the third time period is the second standard duration; A correction module, used to correct the temporary management policy of permissions based on the access interaction circle; The second management module is used to temporarily update the smart contract within a third time period in the future based on the revised temporary permission management strategy to perform corresponding second temporary management of the data access rights of the blockchain.

8. The data access rights management system based on smart contracts as claimed in claim 7, characterized in that: The generating module generates the access association circle of each user, including: Determine a first target user from among the users; wherein the first target user has the highest frequency of accessing data on the blockchain within a recently preset first time period; Acquire multiple first historical items generated by the first target user accessing data on the blockchain within a third time period in the future; Determine a target history item from each first history item; wherein the history item type of the target history item matches the standard history item type; Get the earliest and latest generation time of the target history item; Determine the interval start time; if the target time of the second time preset before the earliest generation time is earlier than the start time of the third time period in the future, the start time of the third time period in the future is used as the interval start time; otherwise, the target time is used as the interval start time; Determine the interval end time; wherein the interval end time is the latest generated time; Determine the target time interval based on the interval start time and the interval end time; Classify and count the target historical items to obtain category distribution; Determine the historical item conditions corresponding to the category distribution from the historical item condition library; Determine a second target user other than the first target user from among the users; wherein a plurality of second historical items generated by the second target user accessing data on the blockchain within the target time interval meet the historical item condition; A visit association circle is generated based on the first target user and the second target user.

Citation Information

Patent Citations

  • Smart contract cross-domain access method based on master-slave chain architecture

    CN119363424A