Access Control System Integrating Multiple Mechanisms

By using certificates in the access control system to ensure the integrity and effectiveness of authorization attributes, and dynamically fusion of multiple access control models, the problem of insufficient flexibility and scalability in the prior art is solved, and fine-grained security protection and strong security management support is achieved in complex scenarios.

CN119814476BActive Publication Date: 2025-05-27BEIJING ANDY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510294339.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-05-27
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

When existing access control models face insufficient flexibility and scalability, they are difficult to meet the needs of open dynamic networks and cannot fully meet the security management needs in complex scenarios.

Method used

By using certificates to ensure the integrity and effectiveness of authorization attributes, and dynamically integrate multiple access control models in the access control decision-making process, supporting multiple authorization factors, and building a converged access control system with multiple mechanisms.

Benefits of technology

It realizes fine-grained security protection for information, resources and services, provides strong security management support, and can flexibly expand new control models according to different business needs and scenarios, improving the scalability of the system and compatibility of multiple authorization factors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814476B_ABST
    Figure CN119814476B_ABST
Patent Text Reader

Abstract

The present invention discloses an access control system integrating multiple mechanisms, including: a subject initiating an access request to an access control execution node; the access control execution node forwarding the access request to an access control decision node; the access control decision node querying the combination of certificate types required for the access request from a policy repository; the access control decision node initiating certificate requests to multiple decision attribute issuing nodes in parallel according to the fusion method of the certificates in the certificate type combination or sequentially initiating certificate requests to different decision attribute issuing nodes according to the certificate dependency order; the access control decision node performing parallel verification or hierarchical verification according to the fusion method of the certificates in the certificate type combination to obtain an access decision result; and the access control execution node executing the access request according to the access decision result. The present invention can flexibly expand new control models according to different business requirements and scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to an access control system integrating multiple mechanisms. Background Art

[0002] Information is the most important asset of any organization and must be kept secure. The security of information can be ensured through confidentiality, integrity, and availability. In addition, the information of an organization can be protected by different methods or technologies, such as intrusion detection, steganography, cryptography, and access control. These methods are used according to the information and the purposes and goals of the organization. Among them, access control is one of the best methods for protecting information from internal and external attacks of the organization and making decisions on granting and revoking access rights to any user. With the development of network technology and the increase of network threats, access control has become one of the core means for protecting information systems and data security.

[0003] Traditional access control is divided into four types, namely, Mandatory Access Control Model (MAC), Discretionary Access Control Model (DAC), Role-Based Access Control Model (RBAC), and Attribute-Based Access Control Model (ABAC). In some fields, new access control models such as trust-based models are also introduced. In DAC, the owner of the object decides the access right granting or revocation policy for the subject or user, with relatively high flexibility and a simple and direct authorization process. MAC works based on security labels, which can be regarded as a hierarchical structure model. It controls the access rights of users or processes to system resources. Users are assigned to different security levels, while objects are assigned security labels, and the access control rights are strictly controlled by the administrator. RBAC is based on five different entities: object, operation, permission, role, and user. It centrally manages permissions through roles, making authorization management relatively simple, reducing redundant policy configurations, and facilitating division of labor and hierarchical management. ABAC dynamically decides access rights through multi-dimensional elements such as user attributes, resource attributes, and environmental attributes. Compared with RBAC, ABAC can achieve fine-grained and dynamic control, better adapting to changing access scenarios. The trust-based access model calculates a trust value based on the trustworthiness, historical behavior, context factors, etc. of the subject and incorporates it into the access decision-making process. It can comprehensively consider the dynamic behavior of users and adapt to a highly open and dynamically changing network environment.

[0004] DAC is overly dependent on the judgment of resource owners, which can easily cause security risks. MAC is not flexible enough and is difficult to cope with changing business environments. When RBAC requires fine-grained authorization, role definitions are prone to "explosion", resulting in a significant increase in management complexity. In addition, the role system requires a large amount of role maintenance when the user scale and permission requirements change frequently, and lacks direct support for real-time attributes or context information. In high-concurrency or complex scenarios, ABAC policy evaluation consumes a lot of system resources, and it is difficult to synchronize attributes in real time. The trust calculation based on the trust access model is time-consuming and can easily cause access delays in high-concurrency environments. In addition, the above access control model can only select specific types of authorization factors, making it increasingly difficult to make fast and secure access decisions for a large number of distributed subject users. It cannot fully meet the needs of open dynamic networks, and the scalability of the access control model and the compatibility analysis of multiple authorization factors are seriously insufficient. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present invention provides an access control system that integrates multiple mechanisms. It ensures the integrity and validity of authorization attributes by using certificates, dynamically integrates multiple access control models in the access control decision-making process through decision points, supports multiple authorization factors, and solves the problems of traditional models in terms of insufficient flexibility and scalability. It can flexibly expand new control models according to different business needs and scenarios.

[0006] The present invention provides an access control system integrating multiple mechanisms, the system comprising: a subject, an object, an access control execution node, an access control decision node, a decision attribute issuance node, a policy repository, a certificate repository and a certificate revocation list;

[0007] The subject initiates an access request to the access control execution node, wherein the access request includes: information of the subject, information of the object to be accessed, and an operation type;

[0008] After receiving the access request, the access control execution node forwards the access request to the access control decision node;

[0009] The access control decision node queries the policy repository for a combination of certificate types required for the access request;

[0010] The access control decision node initiates certificate requests to multiple decision attribute issuing nodes in parallel according to the fusion mode of the certificates in the certificate type combination, or initiates certificate requests to different decision attribute issuing nodes in sequence according to the certificate dependency order, and each decision attribute issuing node queries the corresponding certificate from the certificate repository according to the received certificate request and returns it to the access control decision node;

[0011] The access control decision node checks whether the certificates in the certificate type combination are invalid in the certificate revocation list. If they are not invalid, parallel verification or hierarchical verification is performed according to the fusion method of the certificates in the certificate type combination. After verification, the information of the successfully verified certificates, the information of the object, and the environmental information are matched with the access control policy rules in the policy repository to obtain an access decision result and return it to the access control execution node;

[0012] The access control execution node executes the access request according to the access decision result.

[0013] Preferably, the subject is the initiator of the access request; the object is the resource created and published to the network by the resource owner; the decision attribute issuing node is a trusted decision point for issuing certificates containing access permissions to the subject according to the access control policy. Different access control models correspond to different decision attribute issuing nodes, and each decision attribute issuing node issues different types of certificates according to the corresponding access control model; the certificate types include trust degree certificates, role certificates, and security level certificates, and the certificate includes the certificate issuer, authorized content, validity period of the certificate, signature algorithm, and signature.

[0014] Preferably, the policy repository is used to store access control policy rules; assume that the access control policy rule is expressed as R = (s, o, p, op, d), where s, o, op, and p respectively represent the subject, the object that the subject needs to access, the operation type of the subject on the object, and the permissions required for the subject to operate on the object. The access control policy rule is used to specify that the operation op performed by the subject s on a group of objects o when satisfying the permission p is granted by the decision d of the rule R. The decision d includes authorized access, denied authorization, and deferred authorization. The permission p is a logical expression composed of one or more conditions connected by logical operators, and each condition is the relationship between a specific access control model condition variable and the decision value obtained by access control for this variable.

[0015] Preferably, the access control decision node is specifically used for:

[0016] S31. The access control decision node receives the access request, and the access request is expressed as (s req , o req , op req ), s req represents the information of the subject, o req represents the information of the object, and op req represents the operation type;

[0017] S32. Based on o reqObtain the access control policy rule R(o req ) for the object from the policy repository. If R(o req ) does not exist, deny access. If R(o req ) exists, execute step S33;

[0018] S33. Based on s req Obtain the access control policy rule R(s req , o req ) for s req from R(o req ). If R(s req , o req ) does not exist, deny access. If R(s req , o req ) exists, execute step S34;

[0019] S34. Based on op req Obtain the access control policy rule for the corresponding operation R(s req , o req ) from R(s req , o req , op req ). If R(s req , o req , op req ) does not exist, deny access. If R(s req , o req , op req ) exists, execute step S35;

[0020] S35. Obtain the permission p from the access control policy rule R(s req , o req , op req ), and determine the combination of certificate types required for the access request according to the specific access control model conditional variables in the permission p.

[0021] Preferably, the access control decision node is specifically configured to:

[0022] If at least two certificates in the certificate type combination are in a horizontal fusion manner, the access control decision node initiates a certificate request to multiple decision attribute issuing nodes in parallel, and each decision attribute issuing node independently processes the corresponding certificate generation logic;

[0023] If the certificate in the certificate type combination is in the vertical fusion mode, the access control decision node sequentially sends certificate requests to different decision attribute issuing nodes according to the certificate dependency order. After the certificate verification of the previous decision attribute issuing node passes, its output will be used as the certificate generation input parameter of the subsequent decision attribute issuing node;

[0024] Each decision attribute issuing node queries the corresponding certificate from the certificate repository according to the received certificate request. If it exists, it returns it to the access control decision node. If it does not exist, it uses the identity of the subject or other types of certificates as input to issue the corresponding certificate for the subject and return it to the access control decision node.

[0025] Preferably, the access control decision node is specifically used for:

[0026] The access control decision node checks whether the certificate in the certificate type combination exists in the certificate revocation list. If it does not exist, it means the certificate is not expired and certificate verification is performed. If the certificate verification fails, it means the attribute information contained in the certificate has expired, and the access control decision node will adopt different processing strategies according to the fusion mode of the certificate;

[0027] If at least two certificates in the certificate type combination are in the horizontal fusion mode, the access control decision node performs parallel verification. If a certain certificate verification fails, it will not interrupt the verification of other certificates;

[0028] If the certificate in the certificate type combination is in the vertical fusion mode, the access control decision node performs hierarchical verification. If a certain certificate verification fails, it will cause the verification process of other certificates that depend on this certificate subsequently to be interrupted;

[0029] After all certificate verifications are completed, the attribute information of the authorized content field in the successfully verified certificate, the information of the object, and the environmental information are matched with the access control policy rules in the policy repository to obtain an access decision result and return it to the access control execution node. The access decision result includes: allow access, deny access, or delay authorization access.

[0030] Preferably, the access control execution node is specifically used for:

[0031] The access control execution node performs corresponding operations according to the access decision result;

[0032] If the access decision result is allow access, the access control execution node performs corresponding operations on the object;

[0033] If the access decision result is deny access, access is blocked and the required certificate type combination and the corresponding access conditions are notified to the subject;

[0034] If the access decision result is deferred authorization access, the subject will obtain the access right after a predetermined time.

[0035] Preferably, the decision attribute issuing node is further configured to:

[0036] During the entire access process, monitor the validity of the certificates in the certificate type combination. If it is found that the subject's certificate is no longer valid, add the original certificate to the certificate revocation list and generate a new certificate to be stored in the certificate repository.

[0037] Compared with the prior art, the beneficial effects of the present invention are:

[0038] 1. By means of the certificate storage center, the repeated calculations of the decision attribute issuing nodes are reduced, and the certificate validity is ensured in combination with the monitoring center and the revocation list.

[0039] 2. By using different types of decision attribute issuing nodes as the certificate issuing center, various access control models can be flexibly integrated, providing strong support for security management in complex scenarios.

[0040] 3. Different types of authorization certificates, such as user identity attributes and trust levels, are issued by different decision attribute issuing nodes, thereby realizing fine-grained security protection for information, resources, and services.

[0041] 4. When the system needs to expand other access control models, only relevant decision attribute issuing nodes need to be added and integrated into the system without affecting the overall operation of the system.

[0042] 5. Adopting the method of "horizontal integration + vertical integration" to support dynamic combined authorization of multi-model rules. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a schematic structural diagram of an access control system integrating multiple mechanisms provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0045] The present invention will be further described in detail below with reference to the accompanying drawings.

[0046] AsFigure 1 As shown, an embodiment of the present invention proposes an access control system integrating multiple mechanisms, including: a subject, an object, an access control execution node, an access control decision node, a decision attribute issuance node, a policy repository, a certificate repository and a certificate revocation list;

[0047] The subject initiates an access request to the access control execution node. The access request includes: information about the subject, information about the object to be accessed, and the type of operation;

[0048] After receiving the access request, the access control execution node forwards the access request to the access control decision node;

[0049] The access control decision node queries the policy repository for the combination of certificate types required for the access request;

[0050] The access control decision node initiates certificate requests to multiple decision attribute issuing nodes in parallel according to the fusion mode of the certificates in the certificate type combination, or initiates certificate requests to different decision attribute issuing nodes in sequence according to the certificate dependency order. The decision attribute issuing node queries the corresponding certificate from the certificate repository according to the received certificate request and returns it to the access control decision node;

[0051] The access control decision node checks whether the certificates in the certificate type combination are invalid from the certificate revocation list. If they are not invalid, parallel verification or hierarchical verification is performed according to the fusion method of the certificates in the certificate type combination. After the verification is completed, the successfully verified certificate information, object information and environment information are matched with the access control policy rules in the policy repository to obtain the access decision result and return it to the access control execution node;

[0052] The access control execution node executes the access request according to the access decision result.

[0053] In the embodiment of the present invention, the subject is the initiator of the access request; the object is the resource created and published to the network by the resource owner.

[0054] In the embodiment of the present invention, the decision attribute issuance node is a trusted decision point, which is used to issue a certificate containing access rights to the subject according to the access control policy. Different access control models correspond to different decision attribute issuance nodes, and each decision attribute issuance node issues different types of certificates according to the corresponding access control model. These certificates may contain different authorization information, such as the identity, role, trust or other attributes of the subject, so as to support the dynamic combination and decision of multiple access control policies.

[0055] In the embodiments of the present invention, the certificate revocation list is used to store certificates that are invalid for various reasons (such as the certificate being revoked actively, the subject identity becoming invalid, risk or abnormal behavior detection, etc.). Specifically, when the decision attribute issuing node determines that a certain certificate no longer has legitimate access rights, it will record it in the certificate revocation list and provide the list to the access control system for inspection when accepting access requests subsequently.

[0056] In the embodiments of the present invention, the policy repository is used to store access control policy rules; assuming the access control policy rule is expressed as R = (s, o, p, op, d), where s, o, op, and p respectively represent the subject, the object that the subject needs to access, the operation type of the subject on the object, and the permissions required for the subject to perform the operation on the object. The access control policy rule is used to specify that the operation op performed by the subject s on a set of objects o when the permission p is satisfied is granted by the decision d of the rule R. The decision d includes authorized access, denied authorization, and deferred authorization. The permission p is a logical expression formed by connecting one or more conditions using logical operators. Each condition is the relationship between a specific access control model condition variable and the decision value obtained by access control for this variable. Specifically, p is composed of one or more conditions C 1 , C 2 , ……, C z connected by logical operators {∧, ∨, ¬, ⊕, ……} to form a logical expression, and each condition C i can be expressed as V i {=, ≠, >, <, ≥, ≤, ∈, ……}Z i , where V i is a specific access control model condition variable, and Z i is the decision value obtained by access control for this variable.

[0057] In the embodiments of the present invention, the access control decision node is specifically used for:

[0058] S31. The access control decision node receives an access request, and the access request is expressed as (s req , o req , op req ), where s req represents the information of the subject, o req represents the information of the object, and op req represents the operation type;

[0059] S32. Based on o req obtain the access control policy rule R(o req ) for the object from the policy repository. If R(o req ) does not exist, reject the access. If R (o req) If it exists, execute step S33;

[0060] S33. Based on s req Obtain from R(o req ) the access control policy rule R(s req , o req ). If R(s req , o req ) does not exist, deny access. If R(s req , o req ) exists, execute step S34; req ) exists, execute step S34;

[0061] S34. Based on op req Obtain from R(s req , o req ) the access control policy rule R(s req , o req , op req ). If R(s req , o req , op req ) does not exist, deny access. If R(s req , o req , op req ) exists, execute step S35;

[0062] S35. Obtain the permission p from the access control policy rule R(s req , o req , op req ), and determine the combination of certificate types required for the access request according to the specific access control model conditional variables in the permission p.

[0063] In the embodiments of the present invention, the access control decision node is specifically used for:

[0064] If at least two certificates in the certificate type combination are in a horizontal fusion mode, the access control decision node sends certificate requests to multiple decision attribute issuing nodes in parallel, and each decision attribute issuing node independently processes the corresponding certificate generation logic;

[0065] If the certificate in the certificate type combination is in a vertical fusion mode, the access control decision node sequentially sends certificate requests to different decision attribute issuing nodes according to the certificate dependency order. After the certificate verification of the previous decision attribute issuing node passes, its output will be used as the certificate generation input parameter of the subsequent decision attribute issuing node;

[0066] For each decision attribute issuance node, it queries the corresponding certificate from the certificate repository according to the received certificate request. If it exists, it returns it to the access control decision node. If it does not exist, it issues the corresponding certificate for the subject based on the subject's identity or other types of certificates as input and returns it to the access control decision node.

[0067] Specifically, the decision node determines the certificate conditions required for the subject's current access from the policy rules according to the subject's access request, and then requests the corresponding decision attribute issuance nodes to issue these certificates. For the horizontal fusion scenario, the decision node initiates certificate requests to multiple decision attribute issuance nodes in parallel, and each decision attribute issuance node independently processes the certificate generation logic of the corresponding model; for the vertical fusion scenario, the decision node initiates requests to the decision attribute issuance nodes in sequence according to the model dependency order. After the certificate verification of the previous decision attribute issuance node passes, its output will be used as the input parameter for the certificate generation of the subsequent decision attribute issuance node. After each decision attribute issuance node receives the certificate application, it queries the certificate storage center. If it exists, it returns it. If it does not exist, it issues the corresponding certificate (where the attribute information is included in the certificate authorization content field) for the subject based on the subject's identity or other types of certificates as input and returns the result.

[0068] In the embodiment of the present invention, the access control decision node is specifically used for:

[0069] The access control decision node checks whether the certificates in the certificate type combination exist in the certificate revocation list. If they do not exist, it means the certificates are not expired, and certificate verification is performed. If the certificate verification fails, it means the attribute information contained in the certificate has expired, and the access control decision node will adopt different processing strategies according to the certificate fusion method;

[0070] If at least two certificates in the certificate type combination are in the horizontal fusion method, the access control decision node performs parallel verification. If a certain certificate verification fails, it will not interrupt the verification of other certificates;

[0071] If the certificates in the certificate type combination are in the vertical fusion method, the access control decision node performs hierarchical verification. If a certain certificate verification fails, it will cause the verification process of other certificates that depend on this certificate subsequently to be interrupted;

[0072] After all certificate verifications are completed, the attribute information in the authorization content field of the successfully verified certificates, the information of the object, and the environmental information are matched with the access control policy rules in the policy repository to obtain the access decision result and return it to the access control execution node. The access decision result includes: allow access, deny access, or delay authorization access.

[0073] Specifically, the decision-making node first determines whether the certificate exists in the certificate revocation list. If it does not exist, it indicates that the certificate has not expired, and the certificate is verified. If the certificate verification fails, it indicates that the attribute information contained in the certificate has expired, and the decision-making node will adopt different processing strategies according to the fusion method of the certificate. In horizontal fusion, the verification of multiple certificates is carried out independently. If the verification of a certain certificate fails, it will not interrupt the verification of other certificates, and the verification results of other certificates can still affect the access decision, thus allowing continued authorized access in some cases. In vertical fusion, there is a nested relationship between certificates. If the verification of a certain certificate fails, it will cause the process of other subsequent certificates that depend on this certificate to be interrupted. When all certificate verifications are completed, the attribute information of the authorized content field in the successfully verified certificate is matched with the object, environment, etc., and the access request is decided. This process may involve the matching of multiple policy rules, and the decisions returned by multiple matching rule subsets are merged (such as using the logic of "allow first, deny first"), and the decision-making node passes the final access decision result (allow, deny, or delayed authorization, etc.) back to the execution node.

[0074] For example, assume there are the following two rules for accessing File A, and there are three different decision-making attribute issuing nodes that issue trust level certificates, role certificates, and security level certificates respectively, where the trust level certificate requires the role certificate as input.

[0075] Rule R1: r.obj.Name=='A'

[0076] r.Permissions.Role==Teacher&&r.Permissions.Security Level==High&&r.Permissions.Time=='weekday'

[0077] read allow

[0078] This rule R1 requires that the visitor must be a teacher and have a high security level certificate, and can perform read operations on A only on weekdays.

[0079] Rule R2: r.obj.Name=='A'

[0080] r.Permissions.Trust level>80&&r.Permissions.Time=='weekday'

[0081] read allow

[0082] This rule R2 requires that the visitor's trust level is greater than 80, and can perform read operations on A only when accessing the file on weekdays.

[0083] Embodiment of fusion:

[0084] Horizontal fusion: Multiple access control models act in parallel. The system verifies the validity of different certificates and finally decides whether to allow access through rule matching. For rule R1, the decision basis for accessing File A is "role" and "security level". The system will concurrently obtain the role and security level certificates, conduct validity checks, and then the decision-making node will match the obtained certificate information with the object, environment, etc. against the access control policy for decision-making.

[0085] Vertical fusion: There is a nested relationship between different access control models. In this example, the generation of the trustworthiness certificate depends on the role certificate as input, that is, the certificate of one model depends on the certificate of another model as input, forming a hierarchical structure. For rule R2, the decision basis for accessing File A is "trustworthiness", and the issuance of the trustworthiness certificate requires the role certificate as input. In this case, the decision-making node needs to first obtain and verify the role certificate of the subject before further applying for the trustworthiness certificate and conducting validity checks, and then match the obtained trustworthiness certificate information with the object, environment, etc. against the access control policy for decision-making.

[0086] For horizontal fusion: When the subject initiates an access request, the system simultaneously obtains the role certificate and the security level certificate. If both certificates are valid, then they are matched through the rule set. Suppose the subject's role certificate at this time conforms to Role == Teacher, the security level certificate Security Level == High, and the date is a working day. Then when R1 is matched and returns allow, accessing File A is permitted. This is horizontal fusion because the role certificate and the security level certificate are verified in parallel and jointly determine whether to allow access through R1.

[0087] For vertical fusion: When the subject initiates an access request, the decision-making node will obtain the previous certificate of the trustworthiness certificate, that is, the role certificate, as input. That is, it first obtains and verifies the role certificate of the subject before using it as input to further apply for the trustworthiness certificate and conduct validity checks, and then matches the obtained certificate information with the object, environment, etc. against the rule set. Suppose the subject's trustworthiness certificate at this time is Trust level == 90, and the date is a working day. Then when R2 is matched and returns allow, accessing File A is permitted. This is vertical fusion. Here, the vertical fusion is reflected in that the application for the trustworthiness certificate depends on first verifying the role certificate, that is, the certificate of one access control model affects the certificate application of another model.

[0088] The present invention adopts the method of "horizontal fusion + vertical fusion" to support the dynamic combined authorization of multi-model rules.

[0089] In the embodiments of the present invention, the access control execution node is specifically configured to:

[0090] The access control execution node performs corresponding operations according to the access decision result;

[0091] If the access decision result is to allow access, the access control execution node performs corresponding operations on the object;

[0092] If the access decision result is to deny access, access is blocked and the required certificate type combination and the corresponding access conditions are notified to the subject;

[0093] If the access decision result is to delay authorized access, the subject will obtain access rights after a predetermined time.

[0094] In the embodiments of the present invention, the decision attribute issuing node is further configured to:

[0095] During the entire access process, the decision attribute issuing node monitors the validity of the certificates in the certificate type combination. If it is found that the subject's certificate is no longer valid, the original certificate is added to the certificate revocation list, and the latest certificate is generated and stored in the certificate repository.

[0096] During the entire access process, the validity of the certificates is monitored by the decision attribute issuing node. Once it is found that the subject's certificate is no longer valid (such as changes in identity information, trust level, abnormal behavior, etc.), the decision attribute issuing node adds the original certificate to the revocation list and generates the latest certificate and stores it in the certificate library. Each time an access request is made, the access control system checks whether the certificate is in the revocation list to ensure that only valid certificates can be used for authorization decisions.

[0097] Compared with the prior art, the advantages of the present invention are:

[0098] By using different types of decision attribute issuing nodes as the certificate issuing center, various access control models can be flexibly integrated, providing strong support for security management in complex scenarios. Different decision attribute issuing nodes can issue different types of authorization certificates, such as user identity attributes, trust levels, etc., so as to achieve fine-grained security protection for information, resources, and services. When the system needs to expand other access control models, only relevant decision attribute issuing nodes need to be added and integrated into the system without affecting the overall operation of the system.

[0099] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An access control system integrating multiple mechanisms, the system comprising: Subject, object, access control execution node, access control decision node, decision attribute issuance node, policy repository, certificate repository and certificate revocation list; The subject initiates an access request to the access control execution node, wherein the access request includes: information of the subject, information of the object to be accessed, and an operation type; After receiving the access request, the access control execution node forwards the access request to the access control decision node; The access control decision node queries the policy repository for a combination of certificate types required for the access request; The access control decision node initiates certificate requests to multiple decision attribute issuing nodes in parallel according to the fusion mode of the certificates in the certificate type combination, or initiates certificate requests to different decision attribute issuing nodes in sequence according to the certificate dependency order, and each decision attribute issuing node queries the corresponding certificate from the certificate repository according to the received certificate request and returns it to the access control decision node; The access control decision node checks whether the certificates in the certificate type combination are invalid from the certificate revocation list. If not, parallel verification or hierarchical verification is performed according to the fusion mode of the certificates in the certificate type combination. After the verification is completed, the successfully verified certificate information, the object information and the environment information are matched with the access control policy rules in the policy repository to obtain the access decision result and return it to the access control execution node; The access control execution node executes the access request according to the access decision result.

2. The system according to claim 1, characterized in that The subject is the initiator of the access request; the object is the resource created and published to the network by the resource owner; the decision attribute issuance node is a trusted decision point, which is used to issue a certificate containing access rights to the subject according to the access control policy. Different access control models correspond to different decision attribute issuance nodes. Each decision attribute issuance node issues different types of certificates according to the corresponding access control model; the certificate types include trust certificates, role certificates and security level certificates, and the certificate includes the certificate issuer, authorization content, validity period of the certificate, signature algorithm and signature.

3. The system according to claim 1, characterized in that The policy repository is used to store access control policy rules; assuming that the access control policy rules are expressed as R = (s, o, p, op, d), where s, o, op, and p represent the subject, the object that the subject needs to access, the type of operation performed by the subject on the object, and the permission required for the subject to operate on the object, respectively. The access control policy rules are used to specify that the operation op performed by the subject s on a set of objects o when the permission p is satisfied is granted by the decision d of the rule R, and the decision d includes authorized access, denied authorization, and delayed authorization. The permission p is a logical expression composed of one or more conditions connected by logical operators, and each condition is the relationship between a condition variable of a specific access control model and a decision value obtained by access control for the variable.

4. The system according to claim 3, characterized in that The access control decision node is specifically used for: S31, the access control decision node receives the access request, the access request is expressed as (s req , o req , op req ), s req Indicates the information of the subject, o req Information indicating the object, op req Indicates the operation type; S32, based on o req Obtain access control policy rules R for the object from the policy repository. req ), if R (o req ) does not exist, access is denied. req ) exists, execute step S33; S33, based on s req From R(o req ) to obtain the req The access control policy rule R (s req , o req ), if R (s req , o req ) does not exist, access is denied. If R (s req , o req ) exists, execute step S34; S34, based on op req From R (s req , o req ) to obtain the access control policy rule R (s req , o req , op req ), such as R (s req , o req , op req ) does not exist, access is denied, such as R (s req , o req , op req ) exists, execute step S35; S35, from the access control policy rule R (s req , o req , op req ), and determine the certificate type combination required for the access request according to the specific access control model condition variable in the permission p.

5. The system according to claim 1, characterized in that The access control decision node is specifically used for: If at least two certificates in the certificate type combination are in a horizontal integration mode, the access control decision node initiates certificate requests to multiple decision attribute issuance nodes in parallel, and each decision attribute issuance node independently processes the corresponding certificate generation logic; If the certificates in the certificate type combination are vertically integrated, the access control decision node will initiate certificate requests to different decision attribute issuance nodes in sequence according to the certificate dependency order. After the certificate of the preceding decision attribute issuance node is verified, its output will be used as the input parameter for certificate generation of the subsequent decision attribute issuance node; Each decision attribute issuing node queries the corresponding certificate from the certificate repository according to the received certificate request, and returns it to the access control decision node if it exists. If not, it issues the corresponding certificate to the subject based on the identity of the subject or other types of certificates as input and returns it to the access control decision node.

6. The system according to claim 1, characterized in that The access control decision node is specifically used for: The access control decision node checks whether the certificate in the certificate type combination exists in the certificate revocation list. If not, it means that the certificate is not invalid, and the certificate verification is performed. If the certificate verification fails, it means that the attribute information contained in the certificate is invalid. The access control decision node will adopt different processing strategies according to the fusion mode of the certificate; If at least two certificates in the certificate type combination are in a horizontal integration mode, the access control decision node performs parallel verification, and if the verification of one certificate fails, the verification of other certificates will not be interrupted; If the certificates in the certificate type combination are vertically integrated, the access control decision node performs hierarchical verification. If the verification of a certificate fails, the verification process of other certificates that rely on the certificate will be interrupted; After all certificates are verified, the attribute information of the authorization content field in the successfully verified certificate, the information of the object and the environment information are matched with the access control policy rules in the policy repository, and the access decision result is returned to the access control execution node. The access decision result includes: allowing access, denying access or delaying authorized access.

7. The system according to claim 1, characterized in that The access control execution node is specifically used for: The access control execution node performs corresponding operations according to the access decision result; If the access decision result is to allow access, the access control execution node performs a corresponding operation on the object; If the access decision result is access denial, blocking access and notifying the subject of the required certificate type combination and corresponding access conditions; If the access decision result is delayed authorization of access, the subject will obtain access rights after a predetermined time.

8. The system according to claim 1, characterized in that The decision attribute issuing node is also used for: During the entire access process, the validity of the certificates in the certificate type combination is monitored. If it is found that the certificate of the subject is no longer valid, the original certificate is added to the certificate revocation list, and the latest certificate is generated and stored in the certificate repository.

Citation Information

Patent Citations

  • Access control model based on certificate in network structure, and access method

    CN108390874A

  • A distributed access control model and access method

    CN109039734A