Zero-trust identity access control method based on block chain

By adopting a blockchain-based zero-trust identity access control method in IoT devices, the problem of insufficient computing power and storage space of IoT devices is solved, the authenticity and security of device identity is realized, access permissions are dynamically adjusted, and threat information is responded in real time, which is improved overall security of police IoT scenarios.

CN119995828AInactive Publication Date: 2025-05-13张冬冬
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510200464.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Most existing IoT devices do not have strong computing power and storage space, and cannot directly integrate security functions such as identity authentication and access control in the device chip, and it is difficult to implement secure identity authentication and efficient cross-domain access control in police IoT scenarios with massive access and low device computing power.

Method used

The blockchain-based zero-trust identity access control method is adopted to authenticate by obtaining device information, and decentralized processing is used to ensure the authenticity of device identity and tamper-proof, record and store access logs, conduct trust evaluation and access rights adjustment, and build a trust delivery mechanism to share threat information and respond in real time.

Benefits of technology

It realizes effective identity authentication and access control in IoT devices, ensures the authenticity and security of device identity, dynamically adjusts access permissions, responds to threat information in real time, and improves the overall security of police IoT scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995828A_ABST
    Figure CN119995828A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of smart police affairs, and provides a zero-trust identity access control method based on a block chain, and the method comprises the steps: carrying out the authentication of equipment information, and enabling the authentication to comprise equipment and a user; performing access control on the equipment which is authenticated to be qualified, adjusting the access authority according to the authenticated equipment and the user, performing cross-domain access control according to the access authority, recording an access record, and storing an access log; carrying out decentration processing on the equipment authentication, ensuring the authenticity and tamper-proofing of the equipment identity through the decentration processing, encrypting the access log, and obtaining an audit result of the access log; according to the method, the access log is accessed, trust evaluation is performed according to the access log, the access authority is adjusted according to the trust score, and a trust transfer mechanism is constructed, so that the problem that security functions such as identity authentication and access control cannot be directly integrated in a chip of the Internet of Things equipment due to the fact that most of the existing Internet of Things equipment does not have relatively strong computing power and enough storage space is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of smart policing technology, and in particular relates to a zero-trust identity access control method based on blockchain. Background Art

[0002] Zero-trust networks can eliminate internal and external threats to the network through continuous authentication, authorization, and trust assessment technologies. Blockchain, by integrating cryptography, consensus mechanisms, smart contracts and other technologies, has the characteristics of decentralization, anti-tampering, and traceability, and can provide reliable security protection for the Internet of Things.

[0003] The traditional security protection model based on network boundaries can no longer effectively deal with various threats in emerging network environments. How to implement secure identity authentication technology, perform efficient cross-domain access control, and build a reliable trust management mechanism in police IoT scenarios with characteristics such as massive access and low device computing power is an urgent problem that needs to be solved. Summary of the invention

[0004] The purpose of an embodiment of the present invention is to provide a zero-trust identity access control method based on blockchain, aiming to solve the problems raised in the third part of the background technology.

[0005] The embodiment of the present invention is implemented as follows: a zero-trust identity access control method based on blockchain, the method comprising:

[0006] Acquire device information, the device information including device identity, and authenticate the device information, the authentication including the device and user;

[0007] Obtain authentication results, perform access control on qualified users, adjust access rights based on authenticated devices and users, perform cross-domain access control based on access rights, record access records, and store access logs;

[0008] Decentralize device authentication to ensure the authenticity and tamper-proofness of device identity, encrypt access logs, obtain audit results of access logs, and trace security events on access logs based on audit results;

[0009] Trust assessment is performed based on access logs, access rights are adjusted based on trust scores, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through blockchain, and threat information is shared and responded to in real time through the trust transfer mechanism.

[0010] Preferably, the steps of obtaining authentication results, performing access control on qualified authentications, adjusting access rights according to authenticated devices and users, performing cross-domain access control according to access rights, recording access records, and storing access logs specifically include:

[0011] Obtaining authentication results and performing access control on those who have passed the authentication, wherein the access control is used to adjust access rights;

[0012] Adjust access rights based on authenticated devices and users, and perform cross-domain access control based on access rights;

[0013] The access records are recorded to obtain access logs, and the access logs are stored.

[0014] Preferably, the cross-domain access control is secure access between different systems and domains.

[0015] Preferably, the steps of performing decentralized processing on device authentication, ensuring the authenticity and tamper-proofing of device identity through decentralized processing, encrypting access logs, obtaining audit results of access logs, and tracing security events on access logs through audit results specifically include:

[0016] Decentralized processing of device authentication, which is recorded and verified through blockchain;

[0017] Decentralized processing ensures the authenticity and tamper-proof nature of device identities and encrypts access logs;

[0018] Obtain the audit results of access logs and use the audit results to trace security events in access logs.

[0019] Preferably, the audit is used to determine the transparency of the access log.

[0020] Preferably, the trust evaluation is performed according to the access log, the access rights are adjusted according to the trust score, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through the blockchain, and the steps of sharing threat information in real time and responding through the trust transfer mechanism specifically include:

[0021] Perform trust evaluation based on the access log, where the trust evaluation is used to measure the amount of access rights, obtain a trust score, and adjust the access rights based on the trust score;

[0022] Obtaining an adjustment method, wherein the adjustment method includes restricting access rights and increasing access rights;

[0023] Build a trust transfer mechanism to share threat information and respond in real time.

[0024] Preferably, the trust transfer mechanism is carried out through blockchain.

[0025] The embodiment of the present invention provides a zero-trust identity access control method based on blockchain, which obtains device information, the device information includes device identity, authenticates the device information, the authentication includes device and user, obtains authentication result, performs access control on authenticated devices, adjusts access rights according to authenticated devices and users, performs cross-domain access control according to access rights, records access records, stores access logs, performs decentralized processing on device authentication, ensures the authenticity and tamper-proof of device identity through decentralized processing, encrypts access logs, obtains audit results of access logs, traces security events on access logs through audit results, performs trust evaluation according to access logs, adjusts access rights according to trust scores, and builds a trust transfer mechanism, which is performed through blockchain, shares threat information in real time and responds through the trust transfer mechanism, and solves the problem that most existing IoT devices do not have strong computing power and sufficient storage space, and therefore it is impossible to directly integrate security functions such as identity authentication and access control into IoT device chips. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 A flowchart of a zero-trust identity access control method based on blockchain provided by an embodiment of the present invention;

[0027] Figure 2 A flowchart of the steps of performing access control on qualified authentication, performing cross-domain access control according to access rights, and recording access records provided by an embodiment of the present invention;

[0028] Figure 3 A flowchart of the steps of decentralizing device authentication, encrypting access logs, and obtaining audit results of access logs provided in an embodiment of the present invention;

[0029] Figure 4 A flowchart of the steps of performing trust evaluation based on access logs, adjusting access rights based on trust scores, and building a trust transfer mechanism provided by an embodiment of the present invention; DETAILED DESCRIPTION

[0030] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0031] It is understood that the terms "first", "second", etc. used in this application may be used herein to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, without departing from the scope of this application, a first xx script may be referred to as a second xx script, and similarly, a second xx script may be referred to as a first xx script.

[0032] like Figure 1 As shown, a zero-trust identity access control method based on blockchain is provided in an embodiment of the present invention, and the method includes:

[0033] S100, acquiring device information, the device information including the device identity, and authenticating the device information, the authentication including the device and the user.

[0034] In this step, the device information is obtained. The device information refers to various data related to each device, such as the device's unique identifier, device type, device status, operating parameters, etc. In the police Internet of Things, devices may include surveillance cameras, sensors, law enforcement recorders, communication terminals, etc.

[0035] Authenticate device information. Device authentication is the process of ensuring the legitimacy of the device identity to prevent malicious or counterfeit devices from accessing the network. In the police Internet of Things, device authentication is usually based on the device's unique identity information, certificates, keys, etc.

[0036] S200, obtaining the authentication result, performing access control on qualified authentication, adjusting access rights according to the authenticated device and user, performing cross-domain access control according to the access rights, recording access records, and storing access logs.

[0037] In this step, the authentication result is obtained. When the device and user pass the identity authentication, the system will return the authentication result. If the authentication is successful, the device or user will obtain the corresponding access rights; if the authentication fails, the access will be denied.

[0038] Adjust access rights based on authenticated devices and users. Access control is the allocation of rights based on the identity information of devices and users and their roles / rights after successful authentication. Adjust access rights based on authenticated devices and users.

[0039] Perform cross-domain access control based on access rights, record access records, and store access logs. In the police Internet of Things, the system may involve multiple security domains, and different domains may have different security requirements. Cross-domain access control ensures whether users or devices in one security domain can safely access resources in another domain. Every authentication, authorization, and access operation needs to be recorded and an access log generated for subsequent auditing, monitoring, troubleshooting, and security analysis. These records will describe the access of users and devices in detail, including authentication time, device identity, accessed resources, operation type, and other information.

[0040] S300, decentralized processing of device authentication, ensuring the authenticity and tamper-proofing of device identity through decentralized processing, encrypting access logs, obtaining audit results of access logs, and tracing security events of access logs through audit results.

[0041] In this step, the device authentication is decentralized. Decentralized authentication uses blockchain technology to process the device's identity authentication, ensuring the authenticity of the device's identity and preventing forgery or tampering. The identity information, authentication records and other data of each device are stored in the decentralized blockchain network. Blockchain uses encryption, consensus mechanisms and other means to ensure the immutability and authenticity of data;

[0042] Devices can be authenticated using a private and public key pair. When a device is registered, its public key is published to the blockchain, while the private key is stored only locally on the device. The device proves its identity through a signature operation, ensuring that no third party can forge the device's identity. Whenever a device attempts to access system resources, the authentication system confirms that its identity is valid by verifying the device's public key against the identity record in the blockchain.

[0043] S400, perform trust evaluation based on access logs, adjust access rights based on trust scores, and build a trust transfer mechanism, which is implemented through blockchain. Threat information is shared in real time and responses are made through the trust transfer mechanism.

[0044] In this step, trust evaluation is performed based on access logs. Trust evaluation is the process of evaluating the trust of devices / users that have just been connected to the system or have not frequently accessed the system. By analyzing the access logs of these devices or users, their trust can be evaluated by comprehensively considering factors such as their behavior patterns, activity frequency, and types of resources accessed.

[0045] Once a user or device passes the trust assessment, the system will adjust its access rights based on the trust score. The trust score is determined based on multi-dimensional data such as the device's historical behavior, authentication status, and access mode. The trust transfer mechanism achieves trust transfer between devices, users, and systems by sharing and disseminating trust information. The core idea of ​​the trust transfer mechanism is that the trust of a device or user depends not only on its own behavior, but also on the trust status of other devices or users.

[0046] like Figure 2 As shown, as a preferred embodiment of the present invention, the steps of obtaining the authentication result, performing access control on qualified authentication, adjusting the access rights according to the authenticated device and user, performing cross-domain access control according to the access rights, recording the access records, and storing the access logs specifically include:

[0047] S201, obtaining authentication results, and performing access control on those who pass the authentication, wherein the access control is used to adjust access rights.

[0048] In this step, the authentication result is obtained. The process of obtaining the authentication result first depends on the device or user passing the authentication mechanism of the identity authentication system. After authentication, the system will return the authentication result based on the authentication information. If the authentication is successful, the device or user will obtain the corresponding access rights; if the authentication fails, the access will be denied;

[0049] After successful authentication, based on the authentication results, the system will adjust access rights according to the predefined access control policy, which defines access rights based on the role of the device or user. For example, administrators can access all resources, while ordinary users can only access limited resources.

[0050] S202, adjusting access rights according to the authenticated device and user, and performing cross-domain access control according to the access rights, wherein the cross-domain access control is secure access between different systems and domains.

[0051] In this step, access rights are adjusted based on the authenticated devices and users. After the system confirms the authentication results, access rights are dynamically adjusted based on the identity information of the devices and users. Authenticated users will be assigned different access rights based on their roles (such as police officers, administrators, auditors, etc.). For example, police officers can access real-time monitoring data but cannot modify system settings, while administrators can modify system configurations.

[0052] Police IoT systems may have multiple security domains (e.g., command center, frontline equipment, regional monitoring systems, etc.), and access control between these security domains requires special attention. Cross-domain access control ensures secure access between different domains, which may have different security levels and policies.

[0053] S203, recording the access record, obtaining an access log, and storing the access log.

[0054] In this step, access records are recorded, access records are recorded and stored, which is an important part of ensuring system security and meeting compliance requirements. By recording each access operation in detail, it is not only possible to monitor the system status in real time and detect potential security threats in a timely manner, but also to provide data support for subsequent audits, troubleshooting and security incident response.

[0055] like Figure 3 As shown, as a preferred embodiment of the present invention, the steps of performing decentralized processing on device authentication, ensuring the authenticity and tamper-proof of device identity through decentralized processing, encrypting access logs, obtaining audit results of access logs, and tracing security events on access logs through audit results specifically include:

[0056] S301, decentralized processing is performed on device authentication, and the decentralized processing is recorded and verified through a blockchain.

[0057] In this step, the device authentication is decentralized. The core idea of ​​decentralized device authentication is to store the device's identity information on the blockchain. The device identity verification and authorization process is completed through blockchain smart contracts and consensus mechanisms. Unlike traditional centralized identity authentication, blockchain does not rely on a single authentication center, but rather maintains and verifies the device's identity information through multiple nodes in a distributed network.

[0058] By decentralizing the device authentication process and using blockchain technology to record and verify, the security and reliability of device authentication can be greatly improved. The immutability, decentralization, and transparency of blockchain provide a strong guarantee for device authentication in the police Internet of Things, effectively preventing security threats such as identity forgery and information tampering. At the same time, the blockchain-based device authentication mechanism also provides a reliable data foundation for subsequent security incident tracing and auditing.

[0059] S302, encrypt the access log to ensure the authenticity and tamper-proof of the device identity through decentralized processing.

[0060] In this step, decentralized processing is used to ensure the authenticity and tamper-proofness of device identities, and access logs are encrypted, which is an important means to ensure security in sensitive environments such as the police Internet of Things. Decentralized processing, with the help of the technical characteristics of blockchain, can effectively prevent the forgery, tampering and centralized attacks of device identities; at the same time, access logs are encrypted to ensure the confidentiality and integrity of access data;

[0061] The biggest advantage of decentralization is tamper resistance. Since device authentication information and access logs are stored on the blockchain, once written, they cannot be modified or deleted. The blockchain uses a consensus mechanism to ensure data consistency and reliability. Therefore, once the device identity is authenticated and recorded, any malicious behavior or tampering attempts will be discovered and rejected by the network nodes.

[0062] S303, obtaining audit results of the access logs, wherein the audit is used to determine the transparency of the access logs, and security events are traced back to the access logs through the audit results.

[0063] In this step, the audit results of the access log are obtained. The audit of the access log is to analyze and check the information in the access log through a series of security policies and technologies to ensure the integrity, authenticity and transparency of the log content;

[0064] Transparency means ensuring that audit results cannot be tampered with and can be publicly verified. Through blockchain technology, the transparency of audit results can be guaranteed. Every audit result will be recorded on the blockchain, forming an open and transparent audit chain. Anyone can query and verify these audit results to ensure the fairness and integrity of the audit process.

[0065] like Figure 4 As shown, as a preferred embodiment of the present invention, the trust evaluation is performed according to the access log, the access rights are adjusted according to the trust score, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through the blockchain, and the steps of sharing threat information in real time and responding through the trust transfer mechanism specifically include:

[0066] S401, performing a trust evaluation based on the access log, wherein the trust evaluation is used to measure the amount of access rights, obtain a trust score, and adjust the access rights based on the trust score.

[0067] In this step, trust assessment is performed based on access logs. Trust assessment refers to the evaluation of devices or users newly added to the system, analyzing their behavior patterns and whether they meet the security requirements of the system. The core of this process is to evaluate the trust of devices or users based on the analysis of access logs, and dynamically adjust their access rights based on the trust score;

[0068] The trust score is a numerical value calculated based on the results of access log analysis, which indicates the degree of trust in a device or user. Adjusting access permissions based on the trust score means that the system can determine in real time what resources a device or user can access or what operations they can perform based on their trust.

[0069] S402, obtaining an adjustment method, where the adjustment method includes limiting access rights and increasing access rights.

[0070] In this step, the adjustment method is obtained. If the trust score of the device or user is low, or the behavior is abnormal, the system will reduce the potential security risk by limiting its access rights. Access rights can be restricted based on the specific trust evaluation results;

[0071] If the trust score of a device or user is high and its access behavior has been consistent with the system security requirements over a period of time, the system can increase access rights based on the evaluation results. The trust score is not fixed and will be adjusted dynamically as the device or user behavior changes.

[0072] S403, building a trust transfer mechanism, which is implemented through blockchain, and sharing threat information in real time and responding through the trust transfer mechanism.

[0073] In this step, a trust transfer mechanism is constructed. The trust transfer mechanism is based on a trust scoring model. It evaluates the trust of each device or user and establishes a trust chain based on the evaluation results. The purpose of the trust transfer mechanism is to allow the trust of devices or users to be dynamically shared and updated in the system, thereby forming a trust-based access control and security response mechanism;

[0074] Devices or users share trust information with other devices or users through blockchain. Blockchain stores the trust status of devices or users in a distributed ledger, and other devices or users can evaluate their trust based on the information in the blockchain. This trust transfer mechanism can be one-way (devices trust other devices) or two-way (two-way trust between devices).

[0075] In one embodiment, a computer device is provided, the computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are implemented:

[0076] Acquire device information, the device information including device identity, and authenticate the device information, the authentication including the device and user;

[0077] Obtain authentication results, perform access control on qualified users, adjust access rights based on authenticated devices and users, perform cross-domain access control based on access rights, record access records, and store access logs;

[0078] Decentralize device authentication to ensure the authenticity and tamper-proofness of device identity, encrypt access logs, obtain audit results of access logs, and trace security events on access logs based on audit results;

[0079] Trust assessment is performed based on access logs, access rights are adjusted based on trust scores, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through blockchain, and threat information is shared and responded to in real time through the trust transfer mechanism.

[0080] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the processor performs the following steps:

[0081] Acquire device information, the device information including device identity, and authenticate the device information, the authentication including the device and user;

[0082] Obtain authentication results, perform access control on qualified users, adjust access rights based on authenticated devices and users, perform cross-domain access control based on access rights, record access records, and store access logs;

[0083] Decentralize device authentication to ensure the authenticity and tamper-proofness of device identity, encrypt access logs, obtain audit results of access logs, and trace security events on access logs based on audit results;

[0084] Trust assessment is performed based on access logs, access rights are adjusted based on trust scores, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through blockchain, and threat information is shared and responded to in real time through the trust transfer mechanism.

[0085] It should be understood that, although each step in the flow chart of each embodiment of the present invention is shown in sequence according to the indication of the arrow, these steps are not necessarily performed in sequence according to the order indicated by the arrow. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.

[0086] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0087] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0088] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.

[0089] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A zero-trust identity access control method based on blockchain, characterized in that: The method comprises: Acquire device information, the device information including device identity, and authenticate the device information, the authentication including the device and user; Obtain authentication results, perform access control on qualified users, adjust access rights based on authenticated devices and users, perform cross-domain access control based on access rights, record access records, and store access logs; Decentralize device authentication to ensure the authenticity and tamper-proofness of device identity, encrypt access logs, obtain audit results of access logs, and trace security events on access logs based on audit results; Trust assessment is performed based on access logs, access rights are adjusted based on trust scores, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through blockchain, and threat information is shared and responded to in real time through the trust transfer mechanism.

2. According to claim 1, a zero-trust identity access control method based on blockchain is characterized in that: The steps of obtaining authentication results, performing access control on qualified authentications, adjusting access rights according to authenticated devices and users, performing cross-domain access control according to access rights, recording access records, and storing access logs specifically include: Obtaining authentication results and performing access control on those who have passed the authentication, wherein the access control is used to adjust access rights; Adjust access rights based on authenticated devices and users, and perform cross-domain access control based on access rights; The access records are recorded to obtain access logs, and the access logs are stored.

3. According to claim 2, a zero-trust identity access control method based on blockchain is characterized in that: The cross-domain access control is for secure access between different systems and domains.

4. According to claim 2, a zero-trust identity access control method based on blockchain is characterized in that: The steps of performing decentralized processing on device authentication, ensuring the authenticity and tamper-proofing of device identity through decentralized processing, encrypting access logs, obtaining audit results of access logs, and tracing security events on access logs through audit results specifically include: Decentralized processing of device authentication, which is recorded and verified through blockchain; Decentralized processing ensures the authenticity and tamper-proof nature of device identities and encrypts access logs; Obtain the audit results of access logs and use the audit results to trace security events in access logs.

5. According to claim 4, a zero-trust identity access control method based on blockchain is characterized in that: The audit is used to determine the transparency of the access log.

6. According to claim 4, a zero-trust identity access control method based on blockchain is characterized in that: The trust evaluation is performed according to the access log, the access rights are adjusted according to the trust score, and a trust transfer mechanism is constructed. The trust transfer mechanism is performed through the blockchain, and the steps of sharing threat information in real time and responding through the trust transfer mechanism specifically include: Perform trust evaluation based on the access log, where the trust evaluation is used to measure the amount of access rights, obtain a trust score, and adjust the access rights based on the trust score; Obtaining an adjustment method, wherein the adjustment method includes restricting access rights and increasing access rights; Build a trust transfer mechanism to share threat information and respond in real time.

7. A zero-trust identity access control method based on blockchain according to claim 6, characterized in that: The trust transfer mechanism is carried out through blockchain.