Authorization verification method, system and device, computer equipment and storage medium
By introducing authorization verification methods in data access control, querying and verifying the matching of authorization operation credentials and metadata authorization service items, the limitations of role-based access control methods in precise control are solved, and strict operation permission control and security improvement of data are achieved.
Patent Information
- Application Number
- CN202510402483.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-05-02
AI Technical Summary
Role-based access control methods have limitations in accurately controlling each operation of each metadata item and cannot meet more precise access requirements.
An authorization verification method is proposed. By querying the authorization operation credentials when receiving the target operation, verifying the target metadata operation authorization item that matches the target metadata authorization service item, and using the target metadata authorization operation verification key for authorization verification, ensuring that only legally authorized operations can be executed.
It realizes fine granular operation authorization control of data, ensures strict control of data access and operation permissions, and reduces potential security risks.
Smart Images

Figure CN119918092A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data access control, and in particular to an authorization verification method, system, device, computer equipment and storage medium. Background Art
[0002] Access control, as a basic element in the security field, is mainly used to clarify the conditions under which specific subjects are allowed to access corresponding data, applications and resources.
[0003] In the related art, the role-based access control method grants or restricts the system access rights of individuals according to their role positioning in the organizational structure. However, the role-based access control method has certain limitations when it comes to accurately controlling each operation of each metadata item. Summary of the invention
[0004] The embodiments of this specification are intended to solve at least one of the technical problems in the related art to a certain extent. To this end, the embodiments of this specification propose an authorization verification method, system, device, computer equipment and storage medium.
[0005] This specification provides an authorization verification method, which includes: When receiving a target operation to be performed on target data, querying the authorization operation credential based on the target metadata authorization service item corresponding to the target operation; In the case that it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result; When the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation.
[0006] In one implementation manner, the authorization operation credential further includes a hash identifier and an encrypted identity, and the authorization verification is performed based on the authorization operation credential and a target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result, including: Determining information to be verified based on the target metadata authorization operation verification key and the target metadata operation authorization item; Determining the identity to be verified based on the encrypted identity and the information to be verified; Determine a hash identifier to be verified based on the identity to be verified and the random parameter; The hash identifier to be verified is compared with the hash identifier to obtain an authorization verification result.
[0007] In one embodiment, comparing the hash identifier to be verified with the hash identifier to obtain an authorization verification result includes: When the hash identifier to be verified is equal to the hash identifier, obtaining the authorization verification result indicating that the authorization verification is passed; In the case that the hash identifier to be verified is not equal to the hash identifier, the authorization verification result indicating that the authorization verification fails is obtained.
[0008] In one embodiment, before performing the target operation on the target data, the method further includes: In the case of receiving a user authentication operation, receiving a metadata authorization service item that allows data operations to be performed corresponding to the user unique identifier and the metadata operable by the user and determining a random parameter; The authorization operation credential is generated based on the user unique identifier, the metadata authorization service item, the random parameter and the initialization data.
[0009] In one embodiment, the initialization data is determined by: Determine, based on the metadata and the metadata authorization service item applicable to the metadata, a privacy parameter and a characteristic value corresponding to each applicable metadata authorization service item of each metadata; Determine, based on the private parameter and the characteristic value corresponding to each applicable metadata authorization service item of each metadata, the metadata authorization operation verification key corresponding to the non-private parameter and each applicable metadata authorization service item of each metadata; The initialization data is determined based on private parameters, characteristic values corresponding to each applicable metadata authorization service item of each metadata, non-private parameters and a metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata.
[0010] In one embodiment, the authorization operation credential further includes an authorized access frequency, and when the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation, including: When the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation with the authorized access frequency as a constraint.
[0011] An implementation manner of this specification provides an authorization verification system, which includes an authorized access control center and a key generation center. The authorization verification system implements the steps of any of the above methods.
[0012] The embodiments of this specification provide an authorization verification device, the device comprising: An authorization operation credential query module is used to query the authorization operation credential based on the target metadata authorization service item corresponding to the target operation when receiving the target operation performed on the target data; A target operation authorization verification module is used to perform authorization verification based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item, and obtain an authorization verification result when it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item; The permission authorization control module is used to allow the target metadata to be operated based on the target operation when the authorization verification result indicates that the authorization verification is passed.
[0013] An embodiment of the present specification provides a computer device, which includes: a memory, and one or more processors communicatively connected to the memory; the memory stores instructions executable by the one or more processors, and the instructions are executed by the one or more processors to enable the one or more processors to implement the steps of the method described in any of the above embodiments.
[0014] The embodiments of this specification provide a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the method described in any of the above embodiments are implemented.
[0015] An embodiment of the present specification provides a computer program product, wherein the computer program product includes instructions, and when the instructions are executed by a processor of a computer device, the computer device is enabled to perform the steps of the method described in any one of the above embodiments.
[0016] In the implementation manner of the above specification, first, when a target operation to be performed on target data is received, the authorization operation credential is queried based on the target metadata authorization service item corresponding to the target operation to verify whether there is a valid authorization record. Then, when it is queried that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result indicating whether the operation request is legally authorized. Finally, when the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation. Through this mechanism, it is ensured that the operation can only be executed when the target operation matches the corresponding metadata operation authorization item and the verification is passed, thereby effectively managing the fine-grained operation authorization control of the data, ensuring strict control of data access and operation permissions, and reducing potential security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A flowchart of the authorization verification method provided in the implementation mode of this specification; Figure 2 A schematic diagram of a process for obtaining an authorization verification result provided in an implementation manner of this specification; Figure 3 A schematic diagram of the process of generating an authorization operation certificate provided in the implementation mode of this specification; Figure 4 A schematic diagram of a process for determining initialization data provided in an embodiment of this specification; Figure 5 A schematic diagram of an authorization verification device provided in an embodiment of this specification; Figure 6 An internal structural diagram of a computer device provided for an embodiment of this specification. DETAILED DESCRIPTION
[0018] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.
[0019] Access control is a basic element in the field of information security. Access control refers to the method and operation mechanism of authorizing and controlling the accessors of resource objects. The accessor, also known as the subject, is usually a user, process or application, while the resource object, or object, is the object being accessed, which can include files, application services, data, etc. The core goal of access control is to ensure that only authorized accessors can access protected resources, while unauthorized accessors cannot access them.
[0020] It should be noted that authorization is the way in which a visitor can access a resource object, such as reading, writing, deleting, appending a file or receiving and sending an email service. In the field of information security, authorization refers to the permission granted by the resource owner to a specific subject (executor) to perform specific operations on a resource object. The scope and operation method of authorization are determined by the resource owner. The access control mechanism is used to monitor and restrict the behavior of visitors and make corresponding decisions when receiving access requests, such as denying access, authorizing permission, or prohibiting certain operations.
[0021] There are four main access control models, each with its own unique approach to managing access to sensitive information: 1. Custom Access Control (DAC) In the DAC model, each object in the system has an owner, who grants access rights to other users based on their own judgment and needs. DAC provides a flexible control method so that resource access rights can be adjusted according to specific circumstances.
[0022] 2. Mandatory Access Control (MAC) In the MAC model, access rights are not determined by the owner of the resource, but are controlled by a central authority based on a predetermined security policy. Users can access certain resources only after review and approval. MAC is usually used in environments with extremely high information security requirements such as government and military. The authority management is relatively strict and unified, and often relies on different security levels and classifications.
[0023] 3. Role-based access control (RBAC) RBAC grants access rights based on the user's role in the organization. Each role is associated with specific permissions, and users are granted access to resources based on their role. RBAC typically manages access to resources such as database tables, columns, and cells, and works closely with access control lists (ACLs).
[0024] 4. Attribute-based access control (ABAC) ABAC relies on various attributes of users, resources, operations, and environments to decide whether to grant access rights. Unlike RBAC, ABAC is not only based on the user's role, but also considers more dimensional attributes.
[0025] However, the above access control model still has certain limitations when it comes to precise control of metadata operations, especially when it needs to be refined to each operation level, it cannot meet more precise access requirements.
[0026] Due to the huge amount of data, if different management policies are set for each data field, the management workload will far exceed the storage data itself. Metadata management can provide a solution.
[0027] Metadata management is one of the core links in the field of big data. It not only involves the description and organization of the data itself, but also undertakes the tasks of tracking data changes, ensuring data quality and improving data availability. Metadata is the descriptive information of data. It is essentially the "data" about data, that is, an abstract description of the attributes, structure and related information of data. Metadata can be understood as the smallest unit of data. Through metadata, it is possible to understand and manage data elements (such as name, size, data type, etc.), structure (such as fields, data columns, etc.) and related information (such as location, owner, etc.).
[0028] For example, metadata in a library is similar to a book catalog. Libraries manage their collections through book catalogs, which contain information such as the name, number, author, subject, introduction, and placement of the book, helping librarians to efficiently manage and quickly find books. The role of metadata in data management is similar to that of a library's book catalog, which helps data managers manage and query data. Metadata runs through the entire process of data flow on a big data platform, mainly including data source metadata, data processing metadata, data warehouse or data subject library metadata, data application layer metadata, and data interface service metadata.
[0029] According to different application fields and functions, metadata can be divided into three categories: business metadata, technical metadata, and management metadata.
[0030] Business metadata: describes the business meaning and business rules of data. Clarifying business metadata helps business personnel understand the actual application scenarios of data and improve the usability of data.
[0031] Technical metadata: describes the structure, storage method, transmission rules, etc. of data, making it easier for computers or databases to identify, store, transmit and exchange data. Technical metadata provides developers with detailed information about data structure and storage, supporting application development and system integration. At the same time, technical metadata can also help business personnel quickly find the data they need.
[0032] Management metadata: It involves the management attributes of data, including data owner, data governance responsibility, data security level, etc. By clarifying the management metadata, it can help clarify the person and department responsible for data management and provide protection for data security management.
[0033] Metadata connects data, data warehouses and data applications, and records the entire process of data from generation to consumption. Metadata can provide detailed information on data assets, helping users discover, identify, understand, organize, retrieve and effectively use data.
[0034] Attribute-Based Encryption (ABE) can be considered as an extension of Identity-Based Encryption (IBE). In an identity-based encryption system, a user's identity is represented by a unique identifier. Attribute-based encryption, on the other hand, uses a set of attributes to represent the user's identity, extending the representation of the user's identity from a single identifier to multiple attributes. In addition, attribute encryption also embeds the access control structure into the attribute set, so that the public key cryptography system has the access control capability for specific attributes and attribute sets. Among them, Attribute-Based Encryption (ABE) is an encryption model that implements encryption and decryption operations by associating ciphertext and key with the user's attribute set and access control policy. Unlike public key encryption, ABE ensures that the ciphertext can be successfully decrypted if and only if the user's attribute set satisfies a specific access control policy.
[0035] Based on the above analysis, the implementation method of this specification provides an authorization verification method. First, when a target operation is received for target data, the authorization operation credential is queried based on the target metadata authorization service item corresponding to the target operation to verify whether there is a valid authorization record. Then, when it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result, indicating whether the operation request is legally authorized. Finally, when the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation. Through this mechanism, it is ensured that the operation can only be executed when the target operation matches the corresponding metadata operation authorization item and the verification is passed, thereby effectively managing the fine-grained operation authorization control of the data, ensuring strict control of data access and operation permissions, and reducing potential security risks.
[0036] The implementation method of this specification provides an example of an authorization verification method, which selects key data attributes and category information in metadata as key metadata, and combines a set of operations on data (including basic operations such as adding, deleting, modifying, and checking, as well as data processing, data desensitization, data watermarking, data circulation, and other processing processes) to form fine-grained data operation access authorization control. Specifically, independent access authorization control can be set for each operation of each key metadata (such as adding, deleting, modifying, and checking), or centralized authorization management can be performed for the combined operations of multiple key metadata. Each key operation can be equipped with a dedicated authorization verification key to achieve refined data authorization management.
[0037] In order to ensure the security of the system, the authorization control system introduces necessary cryptographic technology, which not only realizes fine-grained authorization access control, but also ensures the security and effectiveness of the authorization management system. In addition, the results of each authorized access will be recorded and output to the audit system or blockchain evidence storage platform. This process ensures the immutability and traceability of data operations, thereby further improving the transparency and security of data operations.
[0038] This specification provides an authorization verification method. Figure 1 , the authorization verification method may include the following steps: S110. When a target operation to be performed on target data is received, the authorization operation credential is queried based on the target metadata authorization service item corresponding to the target operation.
[0039] S120. When it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result.
[0040] S130. When the authorization verification result indicates that the authorization verification is passed, operation on the target data is allowed based on the target operation.
[0041] Specifically, the user is bound to the authorization operation credential. When receiving the target operation to be performed on the target data, the authorization access control center determines the metadata corresponding to the target data according to the target data of the target operation to be performed, and then queries the authorization operation credential existing on the user side according to the target metadata authorization service item associated with the target operation of the metadata, so as to determine whether there is a metadata operation authorization item matching the target metadata authorization service item. If the query result indicates that there is a metadata operation authorization item matching the target authorization service item in the authorization operation credential, the metadata operation authorization item is used as the target metadata operation authorization item, indicating that the user has the corresponding authority to perform the target operation on the target data. However, there are security risks in this authority, such as it may be illegally authorized on the user side. Therefore, when the target metadata operation authorization item is queried, the legitimacy of the operation authorization needs to be further verified. Authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to determine whether the operation request is legally authorized, thereby obtaining the authorization verification result. Only when the authorization verification result indicates that the authorization verification has passed, the operation permission restrictions will be relaxed, allowing the corresponding operation behaviors to be performed on the target data according to the specific instructions and requirements of the target operation, so as to ensure that the entire operation process is carried out safely and orderly within the framework of legal authorization, effectively protect the security and integrity of system data, and prevent unauthorized and illegal operations from causing potential damage or leakage risks to data.
[0042] On the contrary, if the target metadata operation authorization item that matches the target metadata authorization service item cannot be found in the authorization operation credential, it means that the user does not have the corresponding authority to perform the target operation on the target data, and the target operation on the target data will be prohibited.
[0043] It should be noted that when the authorization verification result indicates that the authorization verification is passed, the user's operation on the target data according to the target operation will be recorded in the log, or connected to the audit system to achieve traceability and review of the operation behavior. In addition, when the target operation is performed on the target data, new metadata is generated, such as adding new database tables, etc., it will be updated in a timely manner, and the corresponding metadata authorization operation verification key will be allocated for the new metadata and metadata authorization service items that may appear, so as to ensure that the authorization management of the entire system is always in an effective and complete state.
[0044] In the above implementation, first, when a target operation is received for the target data, the authorization operation credential is queried based on the target metadata authorization service item corresponding to the target operation to verify whether there is a valid authorization record. Then, when it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result, indicating whether the operation request is legally authorized. Finally, when the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation. Through this mechanism, it is ensured that the operation can only be executed when the target operation matches the corresponding metadata operation authorization item and the verification is passed, thereby effectively managing the fine-grained operation authorization control of the data, ensuring strict control of data access and operation permissions, and reducing potential security risks.
[0045] In some embodiments, see Figure 2 The authorization operation credential also includes a hash identifier and an encrypted identity. Based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item, authorization verification is performed to obtain the authorization verification result, which may include the following steps: S210: Determine information to be verified based on the target metadata authorization operation verification key and the target metadata operation authorization item.
[0046] S220: Determine the identity to be verified based on the encrypted identity and the information to be verified.
[0047] S230: Determine the hash identifier to be verified based on the identity to be verified and the random parameter.
[0048] S240. Compare the hash identifier to be verified with the hash identifier to obtain an authorization verification result.
[0049] Specifically, the authorization access control center has a metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata. Therefore, the authorization access control center determines the metadata corresponding to the target data according to the target data of the target operation to be executed, and then searches and determines the target metadata authorization operation verification key corresponding to the target metadata authorization service item corresponding to the target operation of the metadata. Then, the authorization access control center performs a decryption operation using the target metadata authorization operation verification key and the target metadata operation authorization item according to the established mathematical relationship and encryption algorithm principle, thereby obtaining the information to be verified. Subsequently, the encrypted identity is divided by the obtained information to be verified to calculate the identity to be verified. Next, the identity to be verified and the pre-set random parameters are used as inputs, and a hash operation is performed through a hash function to generate a hash identifier to be verified. Since the hash identifier to be verified is calculated based on the information provided by the user, and the information provided by the user may be forged, the calculated hash identifier to be verified is compared with the hash identifier provided by the trusted source. According to whether the two are consistent, the final authorization verification result is obtained to determine whether the target operation has passed the authorization verification and can be executed.
[0050] For example, the target metadata authorization service item Corresponding to the target metadata authorization operation verification key Authorize operations based on target metadata to verify the key and target metadata operation authorization items Perform calculations to obtain the information to be verified = = ,in, is a random number. And the information to be verified Perform division operation to calculate the identity to be verified Next, the identity to be verified With pre-set random parameters As input, a hash operation is performed through a specific one-way hash function to generate a hash identifier to be verified. .
[0051] In the above implementation, the information to be verified is determined based on the target metadata authorization operation verification key and the target metadata operation authorization item, the identity to be verified is determined based on the encrypted identity and the information to be verified, the hash identifier to be verified is determined based on the identity to be verified and the random parameters, the hash identifier to be verified is compared with the hash identifier to obtain the authorization verification result, and the reliability of the verification is improved.
[0052] In some implementations, comparing the hash identifier to be verified with the hash identifier to obtain an authorization verification result may include: when the hash identifier to be verified is equal to the hash identifier, obtaining an authorization verification result indicating that the authorization verification is passed.
[0053] In some cases, during the authorization verification process, the hash identifier in the authorization operation credential is calculated based on legal and valid information and is reliable. The hash identifier to be verified is calculated based on the information provided by the user. Given that the information provided by the user may be forged, tampered with, or invalid, it is necessary to determine the legality of the information provided by the user.
[0054] Specifically, the authorization access control center compares the hash identifier to be verified with the hash identifier. When the hash identifier to be verified is equal to the hash identifier, it means that the authorization information content based on the two is the same and has not been tampered with. It can clearly prove that the target metadata operation authorization item in the authorization operation certificate is generated through a legal process, and its content complies with the established authorization specifications and is legal. Based on this, an authorization verification result indicating that the authorization verification is passed can be obtained, thereby allowing the corresponding authorized operation to be executed.
[0055] For example, if the hash identifier to be verified is Hash ID , and obtain the authorization verification result indicating that the authorization verification is successful.
[0056] In the above implementation, when the hash identifier to be verified is equal to the hash identifier, an authorization verification result indicating that the authorization verification is passed is obtained, thereby improving the security of the system.
[0057] In some implementations, comparing the hash identifier to be verified with the hash identifier to obtain an authorization verification result may include: when the hash identifier to be verified is not equal to the hash identifier, obtaining an authorization verification result indicating that the authorization verification failed.
[0058] Specifically, the authorization access control center compares the hash identifier to be verified with the hash identifier. When the hash identifier to be verified is not equal to the hash identifier, it indicates that there is a difference in the authorization information corresponding to the two, that is, the target metadata operation authorization item in the authorization operation certificate is not generated by a legal authorization process, and its content does not meet the pre-set authorization specification. Therefore, it can be determined that the target metadata operation authorization item is illegal. Based on this, an authorization verification result indicating that the authorization verification fails can be obtained, so that the corresponding authorization operation is not allowed to be executed.
[0059] For example, if the hash identifier to be verified is Hash ID , and obtain the authorization verification result indicating that the authorization verification is successful.
[0060] In the above implementation, when the hash identifier to be verified is not equal to the hash identifier, an authorization verification result indicating that the authorization verification fails is obtained, which effectively prevents the execution of illegal operations and ensures the security and stability of the system.
[0061] In some embodiments, see Figure 3 Before performing the target operation on the target data, the method may further include the following steps: S310: When a user authentication operation is received, a metadata authorization service item that allows data operations to be performed corresponding to the user's unique identifier and the metadata operable by the user is received and a random parameter is determined.
[0062] S320: Generate an authorization operation credential based on the user's unique identifier, metadata authorization service item, random parameters and initialization data.
[0063] Specifically, each user has a unique identifier for confirming the user's specific identity, and a metadata authorization service item that allows data operations to be performed corresponding to the metadata that the user can operate. This defines the scope of specific operation permissions that the user can perform on the metadata, and identifies the types of data operations that the user can perform on the metadata, such as read, modify, delete, etc. After receiving the user's authentication request, the key generation center first receives the user's unique identifier and the metadata authorization service item that allows data operations to be performed corresponding to the metadata that the user can operate as input. At the same time, the key generation center will obtain data by random sampling within a pre-set interval and use it as a random parameter to enhance the security and reliability of the subsequent encryption process. Next, the user's unique identifier and random parameters are used as input elements, and a hash function is used to perform a hash operation to generate a hash identifier. The user's unique identifier, random parameters, and initialization data are used as the input content of the encryption operation, and encryption processing is performed through the encryption algorithm to generate an encrypted identity. Based on the metadata authorization service item, the metadata operation authorization item corresponding to the metadata authorization service item is generated by using the random parameters and initialization data through the corresponding algorithm. Finally, the key generation center will integrate the generated hash identifier, encrypted identity, and metadata operation authorization items to form an authorization operation credential and send the authorization operation credential to the user. In addition, the key generation center will also send the user's unique identifier and random parameters to the authorization access control center. It should be noted that the random parameters are not fixed. Each time a user authentication operation is obtained, the random parameters will be regenerated. There can be multiple random parameters or one random parameter. The value of the random parameter is only known by the key generation center and the authorization access control center, which effectively prevents the user from using known parameter information to forge authorization operation credentials.
[0064] For example, taking the dynamic provision of authorization operation credentials as an example, assuming that the user's unique identifier is , where the user's unique identifier can be a string or a number, etc. The user's access permission policy can only complete one data operation on one data item. The metadata authorization service item is operation. Extract random parameters from the domain , and random parameters The authorization operation credentials are calculated using the following formula:
[0065] in, is a hash identifier, To encrypt identity, For metadata operation authorization items, Authorize the metadata service. , To initialize the data, is a one-way function, For the connector.
[0066] Assume that the user is uniquely identified as , the user's access rights policy has several items for various operation sets of different metadata items, and the metadata authorization service items are the set {1, 3, 7}. Extract random parameters from the domain , and random parameters The authorization operation credentials are calculated using the following formula:
[0067] It should be noted that dynamically providing users with authorization credentials for data operations based on their access rights policy is a flexible and secure method that is suitable for scenarios where fine-grained access control is required based on user attributes, operating environment, and resource attributes. Authorization credentials for data operations can also be provided statically. The static method is suitable for scenarios where user identities and data operations are relatively fixed and remain unchanged for a long time.
[0068] In the above implementation, when a user authentication operation is received, a metadata authorization service item that allows data operations to be performed corresponding to the user's unique identifier and the metadata that the user can operate is received and a random parameter is determined. Based on the user's unique identifier, the metadata authorization service item, the random parameter and the initialization data, an authorization operation credential is generated to improve security.
[0069] In some embodiments, see Figure 4 , the initialization data can be determined by: S410: Based on the metadata and the metadata authorization service items applicable to the metadata, determine the private parameters and the characteristic values corresponding to each applicable metadata authorization service item of each metadata.
[0070] S420: Determine the metadata authorization operation verification key corresponding to the non-private parameter and each applicable metadata authorization service item of each metadata based on the characteristic value corresponding to the private parameter and each applicable metadata authorization service item of each metadata.
[0071] S430. Determine initialization data based on private parameters, characteristic values corresponding to each applicable metadata authorization service item of each metadata, non-private parameters, and metadata authorization operation verification keys corresponding to each applicable metadata authorization service item of each metadata.
[0072] Among them, metadata authorization service items can be various data operation items used to digitally represent metadata. Data operation items can include not only add, delete, modify, and query operations, but also data processing, data desensitization, data watermarking, data circulation, etc.
[0073] Specifically, data attribute information and category information are used as metadata, and the data operation items that each metadata is allowed to execute are clarified. Then, the data operation items applicable to the metadata are represented in a digital way, and each applicable metadata authorization service item of each metadata is obtained. The key generation center maps the metadata and the metadata authorization service items applicable to the metadata, and determines the characteristic value corresponding to each applicable metadata authorization service item of each metadata, so as to form a fine-grained data operation access control, which can accurately control different operation permissions for different metadata. The key generation center will obtain data in a random sampling manner within a pre-set interval range and use it as a private parameter. Based on the determined private parameters, combined with the characteristic value corresponding to each applicable metadata authorization service item of each metadata, the independent metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata is further determined to ensure the uniqueness and independence of each metadata authorization operation verification key, so as to ensure the security and accuracy of data operations. In addition, it is also necessary to determine the non-private parameters based on the private parameters and the characteristic value corresponding to each applicable metadata authorization service item of each metadata.
[0074] The private parameters, the characteristic values corresponding to each applicable metadata authorization service item of each metadata, the non-private parameters and the metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata are integrated and determined as initialization data for subsequent data operation authorization and verification processes. It should be noted that the private parameters remain fixed after being determined.
[0075] In some implementations, the metadata authorization operation verification key can be sent to an authorization access control center or distributed to multiple authorization management units, each of which is responsible for different types of metadata, to achieve refined access authorization management for data operations on each metadata, or to achieve flexible access authorization management for a single data operation or multiple combined operations.
[0076] For example, first, select metadata (assuming Items), count all data operation item sets (assuming Since some metadata are not applicable to all data operations in practice, theoretically only The matrix combination of these types corresponds to the relationship between these metadata and data operations. The matrix can be randomized or directly input into the key generation center to be mapped into metadata authorization service items.
[0077] After randomization The matrix maps to In the domain, we get Integer in the field As eigenvalues, and satisfy ,in Each applicable metadata authorization service item corresponding to each metadata. Randomly pick an integer from the domain , which is used as a private parameter.
[0078] Secondly, let is a prime number The bilinear group of for Generators of . In addition, let Represents a bilinear map.
[0079] Then, according to the above settings and elements, we can calculate , ,……, , As a non-private parameter.
[0080] The metadata authorization operation verification keys corresponding to each applicable metadata authorization service item of each metadata are: , ,……, .
[0081] In the above implementation, based on the metadata and the metadata authorization service items applicable to the metadata, the private parameters and the characteristic values corresponding to each applicable metadata authorization service item of each metadata are determined; based on the private parameters and the characteristic values corresponding to each applicable metadata authorization service item of each metadata, the non-private parameters and the metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata are determined; based on the private parameters, the characteristic values corresponding to each applicable metadata authorization service item of each metadata, the non-private parameters and the metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata, the initialization data is determined to implement refined data operation authorization management, thereby effectively implementing fine-grained operation authorization management of data assets.
[0082] In some embodiments, the authorization operation credential also includes an authorized access frequency. When the authorization verification result indicates that the authorization verification is passed, operations on the target data are allowed based on the target operation, which may include: when the authorization verification result indicates that the authorization verification is passed, operations on the target data are allowed based on the target operation with the authorized access frequency as a constraint.
[0083] Specifically, the authorization operation certificate also includes the authorized access frequency. The main function of the authorized access frequency is to limit the number of target operations performed by the user on the target data to achieve refined permission management and control. When the authorization verification result indicates that the authorization verification is passed, the authorized access frequency will implement a corresponding constraint control mechanism on the user's operation behavior based on the pre-set specific rules and parameters. Every time the user operates the target data based on the target operation, it will be detected in real time whether the number of operations currently used has reached the threshold set by the authorized access frequency. As long as the cumulative number of operations has not yet met the limit of the authorized access frequency, the user can perform the corresponding operation normally. However, when the number of times the user performs the target operation on the target data reaches the limit value specified by the authorized access frequency, the user will be automatically prohibited from continuing to operate on the target data based on the target operation. If the user still needs to perform the corresponding target operation on the target data in the future, the authorization operation verification process needs to be re-initiated.
[0084] For example, when generating an authorization operation credential with a user's unique ID, you need to Randomly draw integers from the field If the authorized access frequency is 1, the authorized access frequency ( , , ), by setting , to restrict the number of operations allowed on the target data based on the target operation. This model is consistent with the concept of zero trust, that is, each operation requires a separate authorization verification to ensure the legality and security of each operation. It is similar to a high-security level mechanism of one-time key, which can effectively prevent unauthorized multiple accesses or operations and ensure the security and stability of data and systems.
[0085] In addition, the validity of the authorization operation credentials can be controlled by maintaining the usage cycle, that is, building ( , , ), by setting The specific value of determines the validity period of the authorization credential. During this period, the user can operate the target data based on the target operation. Once the validity period exceeds The set time range requires re-authorization operation verification to ensure refined management and control of user operation permissions in the time dimension, further enhancing the security and reliability of the system.
[0086] When the authorized access frequency is 1, the authorized operation credential can be expressed as:
[0087] in, is a one-way function, is a random parameter, , that is, in the authorization certificate The specific value of .
[0088] In the above implementation, when the authorization verification result indicates that the authorization verification is passed, the authorized access frequency is used as a constraint to allow operations on target data based on the target operation, and the setting of the authorized access frequency is used to improve security.
[0089] The implementation manner of this specification provides an authorization verification system, which includes an authorized access control center and a key generation center. The authorization verification system implements the steps of any of the above methods.
[0090] This specification provides an authorization verification device 500. Figure 5 The authorization verification device 500 includes: an authorization operation credential query module 510, a target operation authorization verification module 520, and an authority authorization control module 530.
[0091] The authorization operation credential query module 510 is used to query the authorization operation credential based on the target metadata authorization service item corresponding to the target operation when receiving the target operation performed on the target data; The target operation authorization verification module 520 is used to perform authorization verification based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item, and obtain an authorization verification result when it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item; The permission authorization control module 530 is used to allow the target data to be operated based on the target operation when the authorization verification result indicates that the authorization verification is passed.
[0092] For a detailed description of the authorization verification device, please refer to the description of the authorization verification method above, which will not be repeated here.
[0093] In some embodiments, a computer device is provided, which may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an authorization verification method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse, etc.
[0094] Those skilled in the art will understand that Figure 6 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution disclosed in this specification, and does not constitute a limitation on the computer device to which the solution disclosed in this specification is applied. Specifically, the computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0095] In some embodiments, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the method steps in the above embodiments when executing the computer program.
[0096] An embodiment of the present specification provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the method in any of the above embodiments are implemented.
[0097] One embodiment of the present specification provides a computer program product, which includes instructions. When the instructions are executed by a processor of a computer device, the computer device can perform the steps of the method of any of the above embodiments.
[0098] It should be noted that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, device or equipment (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or equipment and execute instructions), or in combination with these instruction execution systems, devices or equipment. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or equipment, or in combination with these instruction execution systems, devices or equipment. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and editable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or otherwise processing in a suitable manner if necessary, and then stored in a computer memory.
Claims
1. An authorization verification method, characterized in that: The method comprises: When receiving a target operation to be performed on target data, querying the authorization operation credential based on the target metadata authorization service item corresponding to the target operation; In the case that it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item, authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result; When the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation.
2. The method according to claim 1, characterized in that The authorization operation credential also includes a hash identifier and an encrypted identity. The authorization verification is performed based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item to obtain an authorization verification result, including: Determining information to be verified based on the target metadata authorization operation verification key and the target metadata operation authorization item; Determining the identity to be verified based on the encrypted identity and the information to be verified; Determine a hash identifier to be verified based on the identity to be verified and the random parameter; The hash identifier to be verified is compared with the hash identifier to obtain an authorization verification result.
3. According to the method of claim 2, the step of comparing the hash identifier to be verified with the hash identifier to obtain an authorization verification result comprises: When the hash identifier to be verified is equal to the hash identifier, obtaining the authorization verification result indicating that the authorization verification is passed; In the case that the hash identifier to be verified is not equal to the hash identifier, the authorization verification result indicating that the authorization verification fails is obtained.
4. The method according to claim 1, characterized in that: Before performing the target operation on the target data, the method further includes: In the case of receiving a user authentication operation, receiving a metadata authorization service item that allows data operations to be performed corresponding to the user unique identifier and the metadata operable by the user and determining a random parameter; The authorization operation credential is generated based on the user unique identifier, the metadata authorization service item, the random parameter and the initialization data.
5. The method according to claim 4, characterized in that The initialization data is determined in the following manner: Determine, based on the metadata and the metadata authorization service item applicable to the metadata, a privacy parameter and a characteristic value corresponding to each applicable metadata authorization service item of each metadata; Determine, based on the private parameter and the characteristic value corresponding to each applicable metadata authorization service item of each metadata, the metadata authorization operation verification key corresponding to the non-private parameter and each applicable metadata authorization service item of each metadata; The initialization data is determined based on private parameters, characteristic values corresponding to each applicable metadata authorization service item of each metadata, non-private parameters and a metadata authorization operation verification key corresponding to each applicable metadata authorization service item of each metadata.
6. The method according to claim 1, characterized in that The authorization operation credential also includes an authorized access frequency, and when the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation, including: When the authorization verification result indicates that the authorization verification is passed, the target data is allowed to be operated based on the target operation with the authorized access frequency as a constraint.
7. An authorization verification system, characterized in that: The authorization verification system comprises an authorization access control center and a key generation center, and the authorization verification system implements the steps of the method described in any one of claims 1 to 6.
8. An authorization verification device, characterized in that: The device comprises: An authorization operation credential query module is used to query the authorization operation credential based on the target metadata authorization service item corresponding to the target operation when receiving the target operation performed on the target data; A target operation authorization verification module is used to perform authorization verification based on the authorization operation credential and the target metadata authorization operation verification key corresponding to the target metadata authorization service item, and obtain an authorization verification result when it is found that the authorization operation credential has a target metadata operation authorization item that matches the target metadata authorization service item; The permission authorization control module is used to allow the target data to be operated based on the target operation when the authorization verification result indicates that the authorization verification is passed.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method and device for accessing data
CN103268455A
Asymmetrically encrypted decentralized user authentication and authorization method
CN111245830A
Authorization management method and device based on DID voucher data circulation, electronic equipment and storage medium
CN116305231A
Authority control method and business processing method
CN117375856A
Data management and control processing method and system
CN117972785A