Access control method and system with confidentiality and integrity guarantee

By using fully homomorphic encryption technology and smart contracts on the blockchain, combining homomorphic encryption to match attributes and policy conditions, the performance problems and privacy protection challenges faced by blockchain-based access control in the existing technology in the large-scale network environment are solved, and secure, tamper-proof and auditable access control authorization is achieved.

CN120074797APending Publication Date: 2025-05-30BEIJING UNIV OF TECH

Patent Information

Application Number
CN202510243742.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing blockchain-based access control solutions are difficult to achieve secure, tamper-proof and auditable multiple types of access control authorization in large-scale network environments, while facing performance issues and privacy protection challenges.

Method used

Fully homomorphic encryption technology is used to combine blockchain and smart contracts to achieve confidentiality and integrity protection of access control policies. By storing digital fingerprints of access control policies on the blockchain, rather than actual policies, and matching attributes and policy conditions with homomorphic encryption, ensuring the privacy and security of access control decisions.

Benefits of technology

It realizes that without exposing the specific attribute values ​​of the user, verifying that the user attributes meet the requirements of the access control policy, provides efficient on-chain verification, reduces on-chain computing, enhances privacy protection, and prevents attribute forgery attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074797A_ABST
    Figure CN120074797A_ABST
Patent Text Reader

Abstract

The invention discloses an access control method and system with confidentiality and integrity guarantee. The method comprises the following steps: S1, a main body sends an access request; s2, forwarding to an access control decision node by the access control execution node; s3, the access control decision node sends the access request to the attribute management node and the strategy management node; s4, the strategy management node verifies the integrity of the strategy; s5, the attribute management node obtains an attribute value set in an encryption state; s6, the strategy management node obtains a comparison result corresponding to each strategy condition; s7, the strategy decision contract obtains a calculation result corresponding to each access control strategy; s8, the strategy decision contract judges whether all strategies pass verification or not; s9, the access control decision node feeds back an authorization result to the access control execution node; and S10, the access control execution node executes corresponding operation. According to the method, the homomorphic encryption algorithm and the digital fingerprints stored on the chain are combined, and the balance among performance, correctness, safety and privacy protection is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of blockchain and access control, and particularly relates to an access control method and system with confidentiality and integrity guarantees. Background Art

[0002] In an access control mechanism, for protected resources, it is crucial to prevent unauthorized or malicious users from accessing the resources to avoid unnecessary security incidents. Considering that improper policy modification may lead to unauthorized access to objects. Detecting and preventing improper policy modification is of utmost importance for protecting the security of resources.

[0003] In recent years, as an open and transparent distributed ledger system, the satisfactory characteristics of blockchain have made it an infrastructure for a trusted alternative access control system. How to design a reliable, flexible, and efficient authorization access control solution using blockchain for complex network services has always been a challenge. Therefore, many scholars, based on existing access control methods, have proposed various access control methods by combining blockchain and smart contracts, including the combination of blockchain and role-based access control (RBAC) model, the combination of blockchain and attribute-based access control (ABAC) model, the combination of blockchain and capability-based access control (CapBAC), and the combination of models in other scenarios. However, they tend to regard blockchain as a trusted storage system and directly record the indexes related to access control policies on the blockchain to ensure their accuracy for providing users with effective retrieval. However, due to the characteristics that each transaction and data are publicly visible, it is still challenging to achieve verifiable query, privacy protection, and access authorization based on blockchain.

[0004] However, with the rapid development of blockchain technology, an access control framework based on Ethereum and smart contracts has been proposed. However, while providing secure, tamper-proof, and auditable access control authorization for various types in a large-scale network environment, no effective solution has been proposed to solve the performance problems of the solution based on public Ethereum. Summary of the Invention

[0005] Aiming at the deficiencies in the prior art, the present invention provides an access control method and system with confidentiality and integrity guarantees. The decentralized, tamper-proof, and traceable characteristics of blockchain provide strong robustness, while the smart contracts of Ethereum provide automatic triggering and unchangeable functions. These characteristics not only ensure the integrity of policies in the access control authorization process but also ensure that the access control authorization process is not interfered with or damaged by attackers, especially the possibility of attribute forgery.

[0006] The present invention provides an access control method with confidentiality and integrity guarantees, and the method includes:

[0007] S1. The subject sends an access request to the access control execution node, and the access request includes user information, information of the data owner, and the operation type;

[0008] S2. The access control execution node forwards the access request to the access control decision node after interpreting it;

[0009] S3. The access control decision node sends the access request to the attribute management node and the policy management node;

[0010] S4. The policy management node queries the access control policy of the data owner from the policy repository according to the access request, calls the policy verification contract of the distributed storage module to verify the policy integrity, checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, it uses the access control policy; otherwise, it returns the information of policy error;

[0011] S5. The attribute management node obtains the user attribute set from the attribute authentication center according to the access request, and encrypts its attribute values using the encryption algorithm of homomorphic encryption to obtain the encrypted attribute value set;

[0012] S6. The policy management node encrypts one or more policy conditions of each access control policy using the encryption algorithm of homomorphic encryption to obtain the encrypted policy conditions, calls the homomorphic ciphertext comparison function of the fully homomorphic encryption comparison contract of the distributed storage module, and performs a matching operation on the encrypted attribute values and the corresponding policy conditions to obtain the comparison results corresponding to each policy condition of the access control policy;

[0013] S7. The policy decision contract of the distributed storage module converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison results corresponding to each policy condition of the access control policy to obtain the calculation result corresponding to each access control policy;

[0014] S8. The policy decision contract determines whether all policies pass the verification according to the calculation result corresponding to each access control policy. If so, it returns an authorization result of allowing access to the access control decision node; otherwise, it returns an authorization result of denying access;

[0015] S9. The access control decision node feeds back the received authorization result to the access control execution node;

[0016] S10. The access control execution node performs corresponding operations on the data owner according to the received authorization result and returns the execution result to the subject.

[0017] Preferably, the access request further includes: private input and request metadata. The private input includes: user attributes, access time, and resource identifier. The request metadata includes: resource identifier and access context.

[0018] Preferably, before step S1, deploying the distributed storage module includes:

[0019] The policy management node uses the SHA-256 algorithm to calculate the hash value of the access control policy of the data owner in the policy repository, generates a corresponding digital fingerprint for each access control policy, automatically stores it in the distributed storage module through a smart contract, and records the current block height for subsequent quick positioning;

[0020] Each time the access control policy is updated, a version ID is incremented to provide traceability of historical versions of the access control policy. The version ID and the hash value of the corresponding access control policy are recorded in the distributed storage module so that the hash value of the historical access control policy can be obtained through the version ID when auditing is required.

[0021] Preferably, before step S1, deploying the policy management node includes:

[0022] The policy management node manages the access control policies in the policy repository, maintains the digital fingerprints of the access control policies, and listens for events of access control policy updates broadcast in the distributed storage module to record the hash value of the latest access control policy.

[0023] Preferably, before step S1, deploying the attribute management node includes:

[0024] The attribute authentication center consists of multiple attribute qualification authentication entities, is responsible for issuing user attributes, and generates keys or vouchers related to the attributes, so that the attributes required for the access request initiated by the subject are generated by multiple entities, distributing the authorization across all attribute qualification authentication entities, reducing the risk of dishonesty of a single entity's behavior;

[0025] In a single domain, the attributes required for the access control policy of the data owner in the policy repository are uniformly defined by the domain administrator for authentication rules, and the attribute values need to be preprocessed before use, that is, for non-integer type attributes, an integer value within a finite field with characteristic p is assigned, and the integer value is different from other attributes;

[0026] The identity qualification center AA of the attribute authentication center distributes attribute vouchers to users. The attribute vouchers include: user attribute values, signatures of the attribute authentication center, and the validity period of the attribute vouchers. The attribute value type is an integer.

[0027] Preferably, step S5 includes:

[0028] S51. The attribute management node obtains the user attribute set {attr 1 , attr 2 , …, attr n} from the attribute authentication center according to the access request;

[0029] S52. Use the public key pk in the encryption algorithm of homomorphic encryption to encrypt its attribute value attr i . Enc(attr i ) = E pk (attr i ), generate the ciphertext Enc(attr i ), and obtain the set of attribute values in the encrypted state {Enc(attr 1 ), Enc(attr 2 ), …, Enc(attr n )}, where i and n are positive integers.

[0030] Preferably, step S6 includes:

[0031] S61. The policy management node uses the encryption algorithm of homomorphic encryption to encrypt one or more policy conditions of each access control policy, and obtains the policy conditions in the encrypted state;

[0032] S62. Call the homomorphic ciphertext comparison equality function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is:

[0033] EQ(Enc(attr i ), Enc(P i )) = 1 - (Enc(attr i ) - Enc(P i )) p-1 (1)

[0034]

[0035] Among them, represents the finite field, EQ represents the homomorphic ciphertext comparison equality function, represents the attribute value in the encrypted state, represents the policy condition in the encrypted state, the number of multiplications is p - 2, the depth is log(p - 1), p is a prime number, and i is a positive integer;

[0036] S63. If the comparison result of the two is not equal, call the homomorphic ciphertext comparison less than function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is:

[0037]

[0038]

[0039] where LT represents the homomorphic ciphertext comparison less than function, the number of multiplications is 3p - 5, and the multiplication depth is log(p - 1) + 1;

[0040] S64. If the comparison result is neither equal nor less than, call the homomorphic ciphertext comparison greater than function, the homomorphic ciphertext comparison less than or equal to function, and the homomorphic ciphertext comparison greater than or equal to function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is:

[0041] GT(Enc(attr i ), Enc(P i )) = LT(Enc(P i ), Enc(attr i )) (5)

[0042] LEQ = 1 - GT(Enc(attr i ), Enc(P i )) (6)

[0043] GEQ = 1 - LT(Enc(attr i ), Enc(P i )) (7)

[0044] where GT represents the homomorphic ciphertext comparison greater than function, LEQ represents the homomorphic ciphertext comparison less than or equal to function, and GEQ represents the homomorphic ciphertext comparison greater than or equal to function.

[0045] Based on the same inventive concept, the present invention also provides an access control system with confidentiality and integrity guarantee. The system includes: a subject, a data owner, an access control execution node, an access control decision node, an attribute management node, an attribute authentication center, a policy management node, a policy repository, and a distributed storage module. The distributed storage module includes a fully homomorphic encryption comparison contract, a policy verification contract, and a policy decision contract;

[0046] The subject sends an access request to the access control execution node, and the access request includes user information, information of the data owner, and an operation type;

[0047] The access control execution node forwards the access request to the access control decision node after interpreting it;

[0048] The access control decision node sends the access request to the attribute management node and the policy management node;

[0049] The policy management node queries the access control policy of the data owner from the policy repository according to the access request, calls the policy verification contract to verify the policy integrity, checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, it uses the access control policy; otherwise, it returns an information indicating a policy error.

[0050] The attribute management node obtains the user attribute set from the attribute authentication center according to the access request, and encrypts its attribute values using the encryption algorithm of homomorphic encryption to obtain the attribute value set in the encrypted state.

[0051] The policy management node encrypts one or more policy conditions of each access control policy using the encryption algorithm of homomorphic encryption to obtain the policy conditions in the encrypted state, and calls the homomorphic ciphertext comparison function of the fully homomorphic encryption comparison contract to perform a matching operation on the attribute values in the encrypted state and the corresponding policy conditions, and obtains the comparison result corresponding to each policy condition of the access control policy.

[0052] The policy decision contract converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison result corresponding to each policy condition of the access control policy, and obtains the calculation result corresponding to each access control policy.

[0053] The policy decision contract determines whether all policies pass the verification according to the calculation result corresponding to each access control policy. If so, it returns an authorization result allowing access to the access control decision node; otherwise, it returns an authorization result denying access.

[0054] The access control decision node feeds back the received authorization result to the access control execution node.

[0055] The access control execution node performs corresponding operations on the data owner according to the received authorization result, and returns the execution result to the principal.

[0056] Preferably, the access request further includes: private input and request metadata. The private input includes: user attributes, access time, resource identifier. The request metadata includes: resource identifier and access context.

[0057] Preferably, deploying the distributed storage module includes:

[0058] The policy management node uses the SHA-256 algorithm to calculate the hash value of the access control policy of the data owner in the policy repository, generates a corresponding digital fingerprint for each access control policy, automatically stores it in the distributed storage module through a smart contract, and records the current block height for subsequent quick positioning;

[0059] Each time the access control policy is updated, a version ID is incremented to provide a traceability function for historical versions of the access control policy. The distributed storage module records each version ID and the hash value of the corresponding access control policy so that the hash value of the historical access control policy can be obtained through the version ID when auditing is required.

[0060] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0061] The present invention provides a privacy protection mechanism based on fully homomorphic encryption. Especially in scenarios involving complex access control rules and high requirements for privacy protection, the transparency of the blockchain (distributed storage module) makes it such that if access control policy matching is directly performed on the chain, the privacy of the object policy and user attributes will be severely threatened. The present invention uses a homomorphic encryption comparison method to make access control authorization decisions on the blockchain while ensuring data protection, privacy, and anonymization, ensuring that the process of access control policy matching on the chain proves that the user's attributes meet the requirements of the access control policy without exposing the specific attribute values of the user. It not only provides efficient on-chain verification, reduces on-chain calculations, but also enhances privacy protection and prevents attribute forgery attacks.

[0062] For a real-time system with high requirements for access control response time, the present invention uses a method of storing information off-chain for access control policies and storing digital fingerprints on-chain, which not only provides a verification function for dynamic access control policy changes, but also reduces the on-chain interaction frequency compared with the method of storing policies on-chain, improves the response speed of access control, and enhances the throughput of the system.

[0063] The present invention combines a homomorphic encryption algorithm and on-chain storage of digital fingerprints to achieve a balance among performance, correctness, security, and privacy protection. It is applicable to scenarios with high requirements for access control security and efficient response at the same time. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a schematic flowchart of an access control method with confidentiality and integrity guarantees provided by the present invention;

[0065] Figure 2 It is a schematic flowchart of an access control method with confidentiality and integrity guarantees provided by the present invention;

[0066] Figure 3Schematic diagram of an access control system with confidentiality and integrity guarantees provided by the present invention. Detailed implementation manners

[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0068] The present invention will be further described in detail below with reference to the accompanying drawings.

[0069] As Figure 1-2 shown, an access control method with confidentiality and integrity guarantees provided by an embodiment of the present invention includes:

[0070] S1. A subject sends an access request to an access control execution node, where the access request includes user information, information of a data owner, and an operation type;

[0071] S2. The access control execution node forwards the access request to an access control decision node after interpretation;

[0072] S3. The access control decision node sends the access request to an attribute management node and a policy management node;

[0073] S4. The policy management node queries the access control policy of the data owner from a policy repository according to the access request, calls a policy verification contract of a distributed storage module to verify the policy integrity, checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, the access control policy is used; otherwise, information indicating a policy error is returned;

[0074] S5. The attribute management node obtains a user attribute set from an attribute authentication center according to the access request, and encrypts its attribute values using a homomorphic encryption algorithm to obtain an encrypted attribute value set;

[0075] S6. The policy management node encrypts one or more policy conditions of each access control policy using a homomorphic encryption algorithm to obtain encrypted policy conditions, calls a homomorphic ciphertext comparison function of a fully homomorphic encryption comparison contract of a distributed storage module, and performs a matching operation on the encrypted attribute values and the corresponding policy conditions to obtain a comparison result corresponding to each policy condition of the access control policy;

[0076] S7. The policy decision contract of the distributed storage module converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison results corresponding to each policy condition of the access control policy, and obtains the calculation result corresponding to each access control policy;

[0077] S8. The policy decision contract determines whether all policies pass the verification according to the calculation result corresponding to each access control policy. If so, it returns an authorization result of allowing access to the access control decision node; otherwise, it returns an authorization result of denying access.

[0078] S9. The access control decision node feeds back the received authorization result to the access control execution node;

[0079] S10. The access control execution node performs corresponding operations on the data owner according to the received authorization result and returns the execution result to the subject.

[0080] In the embodiment of the present invention, the access request further includes: private input and request metadata. The private input includes: user attributes, access time, resource identifier, and the request metadata includes: resource identifier and access context.

[0081] In the embodiment of the present invention, before step S1, deploying the distributed storage module includes:

[0082] The policy management node uses the SHA-256 algorithm to calculate the hash value of the access control policy of the data owner in the policy repository, generates a corresponding digital fingerprint for each access control policy, automatically stores it in the distributed storage module through a smart contract, and records the current block height for subsequent rapid positioning;

[0083] Each time the access control policy is updated, a version ID is incremented to provide a traceability function for the historical versions of the access control policy. The version ID and the hash value of the corresponding access control policy are recorded in the distributed storage module so that the hash value of the historical access control policy can be obtained through the version ID when auditing is required.

[0084] In the embodiment of the present invention, before step S1, deploying the policy management node includes:

[0085] The policy management node manages the access control policies in the policy repository, maintains the digital fingerprints of the access control policies, and listens for events of access control policy updates broadcast in the distributed storage module to record the hash value of the latest access control policy.

[0086] In the embodiment of the present invention, before step S1, deploying the attribute management node includes:

[0087] The attribute authentication center consists of multiple attribute qualification authentication entities, which are responsible for issuing user attributes and generating keys or vouchers related to the attributes, so that the attributes required for the access requests initiated by the subject are generated by multiple entities, and the authorization is distributed among all attribute qualification authentication entities, reducing the risk of dishonesty of a single entity's behavior;

[0088] In a single domain, for the attributes required by the access control policy of the data owner in the policy repository, the domain administrator uniformly defines the authentication rules, and the attribute values need to be preprocessed before use, that is, for non-integer type attributes, an integer value within the finite field with characteristic p is assigned, and the integer value is different from the integer values of other attributes;

[0089] The identity qualification center AA of the attribute authentication center distributes attribute vouchers to users. The attribute vouchers include: the attribute values of the users, the signatures of the attribute authentication center, and the validity period of the attribute vouchers. The type of the attribute values is an integer.

[0090] In the embodiment of the present invention, step S5 includes:

[0091] S51. The attribute management node obtains the user attribute set {attr 1 , attr 2 , …, attr n} from the attribute authentication center according to the access request;

[0092] S52. Use the public key pk in the encryption algorithm of homomorphic encryption to encrypt its attribute value attr i , Enc(attr i ) = E pk (attr i ), generate the ciphertext Enc(attr i ), and obtain the set of encrypted state attribute values {Enc(attr 1 ), Enc(attr 2 ), …, Enc(attr n ), where i and n are positive integers.

[0093] In the embodiment of the present invention, step S6 includes:

[0094] S61. The policy management node uses the encryption algorithm of homomorphic encryption to encrypt one or more policy conditions of each access control policy, and obtains the policy conditions in the encrypted state;

[0095] S62. Call the homomorphic ciphertext comparison equality function to perform a matching operation on the attribute values in the encrypted state and the corresponding policy conditions. The calculation formula is:

[0096] EQ(Enc(attr i), Enc(P i )) = 1 - (Enc(attr i ) - Enc(P i )) p-1 (1)

[0097]

[0098] Among them, represents a finite field, EQ represents a homomorphic ciphertext comparison equal function, represents the attribute value in the encrypted state, represents the policy condition in the encrypted state, the number of multiplications is p - 2, the depth is log(p - 1), p is a prime number, and i is a positive integer;

[0099] S63. If the comparison result of the two is not equal, then call the homomorphic ciphertext comparison less than function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is:

[0100]

[0101]

[0102] Among them, LT represents the homomorphic ciphertext comparison less than function, the number of multiplications is 3p - 5, and the multiplication depth is log(p - 1) + 1;

[0103] S64. If the comparison result of the two is neither equal nor less than, then call the homomorphic ciphertext comparison greater than function, the homomorphic ciphertext comparison less than or equal to function, and the homomorphic ciphertext comparison greater than or equal to function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is:

[0104] GT(Enc(attr i ), Enc(P i )) = LT(Enc(P i ), Enc(attr i )) (5)

[0105] LEQ = 1 - GT(Enc(attr i ), Enc(P i )) (6)

[0106] GEQ = 1 - LT(Enc(attr i ), Enc(P i )) (7)

[0107] Among them, GT represents the homomorphic ciphertext comparison greater than function, LEQ represents the homomorphic ciphertext comparison less than or equal to function, and GEQ represents the homomorphic ciphertext comparison greater than or equal to function.

[0108] After verifying the integrity of the policy without error, the policy management node encrypts the policy conditions using the encryption algorithm of homomorphic encryption, and then calls the homomorphic ciphertext addition function of the homomorphic encryption contract to perform a matching operation on the user's attribute ciphertext Enc(attr i ) and the corresponding encrypted form of the policy Enc(P i ).

[0109] First, consider the case where the attribute is equal to the condition required by the policy. In the case of homomorphic encryption, it is to compare whether the attribute and the policy are equal in the encrypted state. The present invention converts the ciphertext comparison into a method of evaluating a binary polynomial. As shown in formulas (1) and (2), determining whether the attribute value and the policy condition are equal in the encrypted state by homomorphic comparison is converted into calculating the binary polynomial EQ(Enc(attr i ), Enc(P i )).

[0110] Next, consider the case where the attribute is within the range required by the policy. In the case of homomorphic encryption, it is to judge "less than", "greater than", "less than or equal to" and "greater than or equal to". Homomorphic comparison to judge that the attribute value in the encrypted state is less than the policy condition is denoted as LT(Enc(attr i ), Enc(P i )) and its construction is as shown in formulas (3) and (4). For example, Enc(attr i ) = 3, Enc(P i ) = 5. Then, only when a = 3, EQ(Enc(attr i ), a) = 1, and at this time So LT(Enc(attr i ), Enc(P i )) = 1. The above example verifies the correctness of LT(Enc(attr i ), Enc(P i )).

[0111] Then, based on LT(Enc(attr i ), Enc(P i ), the binary polynomials of "greater than", "less than or equal to" and "greater than or equal to" can be easily constructed into formulas (5), (6) and (7) respectively. Through the above method, the comparison result between the attribute value and the policy condition can be obtained, and the comparison results include: "equal", "less than", "greater than", "less than or equal to" and "greater than or equal to". The comparison result of the policy condition is used as the input and decision basis for the policy decision contract.

[0112] The policy decision contract converts the Boolean logic calculation of the access control policy into an arithmetic calculation of the comparison result of attributes and policy conditions in the encrypted state. Among them, the AND gate (representing logical AND) is converted into an ADD gate (performing addition operation), and the OR gate (representing logical OR) is converted into a MULT gate (performing multiplication operation).

[0113] For example, the policy Ρ = (P 1 ∨ P 2 ) ∧ P 3 , and its authorization result is determined by the comparison results of P 1 , P 2 , P 3 in the encrypted state output by the fully homomorphic encryption comparison contract and the corresponding encrypted attributes:

[0114] Result = (Result 1 + Result 2 ) · Result 3

[0115] If all policy verifications pass, the policy decision contract returns the authorization result to the access control decision node: if the user meets the policy constraints, access is allowed; if the user does not meet the policy constraints, access is denied. The user client receives the authorization result and performs corresponding operations.

[0116] The present invention provides a privacy protection mechanism based on fully homomorphic encryption. Especially in scenarios involving complex access control rules and having high requirements for privacy protection, the transparency of the blockchain makes it that if the access control policy matching is directly performed on the chain, the privacy of object policies and user attributes will be severely threatened. The present invention needs to ensure data protection, privacy, and anonymization while making access control authorization decisions on the blockchain. Homomorphic encryption addresses this challenge. The basic operations of homomorphic encryption include homomorphic addition and homomorphic multiplication, while the present invention considers another homomorphic operation, namely homomorphic comparison, and uses the second-generation fully homomorphic encryption (mainly BFV) to convert integer comparison into the idea of polynomial evaluation. It ensures that the process of access control policy matching on the chain proves that the user's attributes meet the requirements of the access control policy without exposing the specific attribute values of the user. It not only provides efficient on-chain verification, reduces on-chain calculations, but also enhances privacy protection and prevents attribute forgery attacks.

[0117] Such as Figure 3As shown in the figure, an access control system with confidentiality and integrity guarantees is also provided in an embodiment of the present invention. The system includes: a subject 100, a data owner 200, an access control execution node 300, an access control decision node 400, an attribute management node 500, an attribute authentication center 600, a policy management node 700, a policy repository 800, and a distributed storage module. The distributed storage module includes a fully homomorphic encryption comparison contract 900, a policy verification contract 1000, and a policy decision contract 1100;

[0118] The subject 100 sends an access request to the access control execution node 300. The access request includes user information, information of the data owner, and an operation type;

[0119] The access control execution node 300 forwards the access request to the access control decision node 400 after interpreting it;

[0120] The access control decision node 400 sends the access request to the attribute management node 500 and the policy management node 700;

[0121] The policy management node 700 queries the access control policy of the data owner from the policy repository 800 according to the access request, calls the policy verification contract 1000 to verify the policy integrity, checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, the access control policy is used; otherwise, an information indicating a policy error is returned;

[0122] The attribute management node 500 obtains a set of user attributes from the attribute authentication center 600 according to the access request, and encrypts its attribute values using a homomorphic encryption algorithm to obtain a set of encrypted attribute values;

[0123] The policy management node 700 encrypts one or more policy conditions of each access control policy using a homomorphic encryption algorithm to obtain encrypted policy conditions, and calls the homomorphic ciphertext comparison function of the fully homomorphic encryption comparison contract 900 to perform a matching operation on the encrypted attribute values and the corresponding policy conditions to obtain a comparison result corresponding to each policy condition of the access control policy;

[0124] The policy decision contract 1100 converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison results corresponding to each policy condition of the access control policy to obtain a calculation result corresponding to each access control policy;

[0125] The policy decision contract 1100 determines whether all policies pass the verification according to the calculation result corresponding to each access control policy. If so, an authorization result allowing access is returned to the access control decision node 400; otherwise, an authorization result denying access is returned;

[0126] The access control decision-making node 400 feeds back the received authorization result to the access control enforcement node 300;

[0127] The access control enforcement node 300 performs corresponding operations on the data owner 200 according to the received authorization result and returns the execution result to the principal 100.

[0128] Figure 3 It is a framework diagram of an access control system model with confidentiality and integrity guarantees, showing the components and interactions of all access control policy authorization processes. This system mainly consists of the following entities.

[0129] (1) Data owner: It holds the data and the corresponding access control policies, and has dynamic operation permissions for the policies, such as deployment, modification, revocation, etc.

[0130] (2) Principal (user): After the user authenticates their identity and enters the access control system, they can submit an access request.

[0131] (3) Access control enforcement node: Receives the user's access request, interprets the request and sends it to the access control decision-making node, and satisfies the user's request according to the feedback from the access control decision-making node. Interpretation means performing request transformation and formatting on the original access request for subsequent processing.

[0132] (4) Access control decision-making node: The core of the access control system, which performs real-time evaluation and decision-making on access requests. After receiving an access request, it sends it to the policy management node and the attribute management node.

[0133] (5) Policy management node: Responsible for managing and retrieving the policies used in access requests and encrypting the policy conditions.

[0134] (6) Policy verification contract: Dependent on the policy management node, it provides the function of verifying the integrity of the policy, that is, whether the policy hash value is the same as the digital fingerprint on the blockchain.

[0135] (7) Attribute management node: Provides the required attribute values according to the access request through the attribute authentication center and encrypts them.

[0136] (8) Fully homomorphic encryption comparison contract: mainly includes the homomorphic ciphertext comparison equal function EQ(), the homomorphic ciphertext comparison less than function LT(), etc., and provides the comparison of attributes and policies in the encrypted state.

[0137] (9) Policy decision contract: mainly performs boolean logic calculations on access control policies, converts them into arithmetic calculations of the comparison results of attributes and policies in the encrypted state, and returns the authorization result to the access control system.

[0138] The present invention uses a method of storing information off-chain and digital fingerprints on-chain for access control policies, which not only provides a verification function for dynamic access control policy changes, but also reduces the on-chain interaction frequency compared with the method of storing policies on-chain, improves the response speed of access control, and enhances the throughput of the system.

[0139] The present invention combines a homomorphic encryption algorithm and on-chain storage of digital fingerprints to achieve a balance among performance, correctness, security, and privacy protection, and is applicable to scenarios with high requirements for access control security and the need for efficient response.

[0140] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An access control method with confidentiality and integrity assurance, characterized in that: The method comprises: S1. The subject sends an access request to the access control execution node, where the access request includes user information, data owner information, and operation type; S2, the access control execution node interprets the access request and forwards it to the access control decision node; S3, the access control decision node sends the access request to the attribute management node and the policy management node; S4. The policy management node queries the access control policy of the data owner from the policy repository according to the access request, calls the policy verification contract of the distributed storage module to verify the integrity of the policy, and checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, the access control policy is used, otherwise, the policy error information is returned; S5. The attribute management node obtains a user attribute set from an attribute authentication center according to the access request, and encrypts the attribute values ​​using a homomorphic encryption algorithm to obtain an attribute value set in an encrypted state; S6. The policy management node uses a homomorphic encryption algorithm to encrypt one or more policy conditions of each access control policy to obtain the policy conditions in an encrypted state, calls the homomorphic ciphertext comparison function of the fully homomorphic encryption comparison contract of the distributed storage module, performs a matching operation on the attribute value in the encrypted state and the corresponding policy condition, and obtains a comparison result corresponding to each policy condition of the access control policy; S7, the policy decision contract of the distributed storage module converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison result corresponding to each policy condition of the access control policy, and obtains the calculation result corresponding to each access control policy; S8. The policy decision contract determines whether all policies are verified based on the calculation results corresponding to each access control policy. If so, it returns an authorization result of allowing access to the access control decision node; otherwise, it returns an authorization result of denying access; S9, the access control decision node feeds back the received authorization result to the access control execution node; S10. The access control execution node performs corresponding operations on the data owner according to the received authorization result, and returns the execution result to the subject.

2. The method according to claim 1, characterized in that The access request further includes private input and request metadata, wherein the private input includes user attributes, access time, and resource identification, and the request metadata includes a resource identifier and an access context.

3. The method according to claim 1, characterized in that Before step S1, deploying the distributed storage module includes: The policy management node uses the SHA-256 algorithm to calculate the hash value of the access control policy of the data owner in the policy repository, generates a corresponding digital fingerprint for each access control policy, automatically stores it in the distributed storage module through a smart contract, and records the current block height for subsequent rapid positioning; Each time the access control policy is updated, a version ID is incremented to provide a traceability function for the historical versions of the access control policy. Each version ID and the hash value of the corresponding access control policy are recorded in the distributed storage module so that the hash value of the historical access control policy can be obtained through the version ID when an audit is required.

4. The method according to claim 1, characterized in that Before step S1, deploying the policy management node includes: The policy management node manages the access control policies in the policy repository, maintains the digital fingerprints of the access control policies, and monitors the access control policy update events broadcast in the distributed storage module to record the latest hash value of the access control policy.

5. The method according to claim 1, characterized in that Before step S1, deploying the attribute management node includes: The attribute authentication center is composed of multiple attribute qualification authentication entities, which are responsible for issuing user attributes and generating keys or credentials related to the attributes, so that the attributes required for the access request initiated by the subject are generated by multiple entities, and the authorization is distributed among all attribute qualification authentication entities, reducing the risk of dishonesty of a single entity; In a single domain, the attributes required by the access control policy of the data owner in the policy repository are uniformly defined by the domain administrator. The attribute values ​​need to be preprocessed before use, that is, for non-integer type attributes, a finite domain with characteristic p is assigned. The integer value in , and is different from the integer values ​​of other attributes; The identity qualification center AA of the attribute authentication center distributes attribute certificates to users. The attribute certificates include: the attribute value of the user, the signature of the attribute authentication center and the validity period of the attribute certificate. The attribute value type is an integer.

6. The method according to claim 1, characterized in that Step S5 includes: S51, the attribute management node obtains the user attribute set {attr1, attr2, ..., attr n }; S52, use the public key pk in the encryption algorithm of homomorphic encryption to its attribute value attr i Encryption, Enc(attr i )=E pk (attr i ), generate ciphertext Enc(attr i ), and obtain the attribute value set in the encrypted state {Enc(attr1), Enc(attr2),…, Enc(attr n )}, where i and n are positive integers.

7. The method according to claim 1, characterized in that Step S6 includes: S61, the policy management node encrypts one or more policy conditions of each access control policy using a homomorphic encryption algorithm to obtain the policy conditions in an encrypted state; S62, calling the homomorphic ciphertext comparison equality function, performing a matching operation on the attribute value in the encrypted state and the corresponding policy condition, and the calculation formula is: EQ(Enc(attr i ),Enc(P i ))=1- (Enc(attr i )-Enc(P i )) p-1 (1) in, represents a finite field, EQ represents a homomorphic ciphertext equality comparison function, represents the attribute value in the encrypted state, represents the policy condition under the encryption state, the number of multiplications is p-2, the depth is log(p-1), p is a prime number, and i is a positive integer; S63. If the comparison result of the two is not equal, the homomorphic ciphertext comparison less than function is called to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition. The calculation formula is: Among them, LT means that the homomorphic ciphertext is less than the function, the number of multiplications is 3p-5, and the multiplication depth is log(p-1)+1; S64. If the comparison results of the two are neither equal nor less than, calling the homomorphic ciphertext comparison greater than function, the homomorphic ciphertext comparison less than or equal to function, and the homomorphic ciphertext comparison greater than or equal to function to perform a matching operation on the attribute value in the encrypted state and the corresponding policy condition, the calculation formula is: GT(Enc(attr i ),Enc(P i ))=LT(Enc(P i ),Enc(attr i )) (5) LEQ=1-GT(Enc(attr i ),Enc(P i )) (6) GEQ=1-LT(Enc(attr i ),Enc(P i )) (7) Among them, GT represents the homomorphic ciphertext comparison greater than function, LEQ represents the homomorphic ciphertext comparison less than or equal to function, and GEQ represents the homomorphic ciphertext comparison greater than or equal to function.

8. An access control system with confidentiality and integrity assurance, used to implement the method according to any one of claims 1 to 7, characterized in that: The system includes: a subject, a data owner, an access control execution node, an access control decision node, an attribute management node, an attribute authentication center, a policy management node, a policy repository, and a distributed storage module, wherein the distributed storage module includes a fully homomorphic encryption comparison contract, a policy verification contract, and a policy decision contract; The subject sends an access request to the access control execution node, wherein the access request includes user information, data owner information and operation type; The access control execution node interprets the access request and forwards it to the access control decision node; The access control decision node sends the access request to the attribute management node and the policy management node; The policy management node queries the access control policy of the data owner from the policy repository according to the access request, calls the policy verification contract to verify the integrity of the policy, and checks whether the hash value of each access control policy is consistent with the digital fingerprint corresponding to the access control policy in the distributed storage module. If so, the access control policy is used, otherwise, the policy error information is returned; The attribute management node obtains a user attribute set from the attribute authentication center according to the access request, and encrypts the attribute values ​​thereof using a homomorphic encryption algorithm to obtain an attribute value set in an encrypted state; The policy management node encrypts one or more policy conditions of each access control policy using a homomorphic encryption algorithm to obtain the policy conditions in an encrypted state, calls the homomorphic ciphertext comparison function of the fully homomorphic encryption comparison contract, performs a matching operation on the attribute value in the encrypted state and the corresponding policy condition, and obtains a comparison result corresponding to each policy condition of the access control policy; The policy decision contract converts the Boolean logic calculation of one or more policy conditions of each access control policy into an arithmetic calculation of the comparison result corresponding to each policy condition of the access control policy, and obtains the calculation result corresponding to each access control policy; The policy decision contract determines whether all policies are verified based on the calculation results corresponding to each access control policy. If so, it returns the authorization result of allowing access to the access control decision node; otherwise, it returns the authorization result of denying access; The access control decision node feeds back the received authorization result to the access control execution node; The access control execution node performs corresponding operations on the data owner according to the received authorization result, and returns the execution result to the subject.

9. The system according to claim 8, characterized in that The access request further includes private input and request metadata, wherein the private input includes user attributes, access time, and resource identification, and the request metadata includes a resource identifier and an access context.

10. The system according to claim 8, characterized in that Deploying the distributed storage module includes: The policy management node uses the SHA-256 algorithm to calculate the hash value of the access control policy of the data owner in the policy repository, generates a corresponding digital fingerprint for each access control policy, automatically stores it in the distributed storage module through a smart contract, and records the current block height for subsequent rapid positioning; Each time the access control policy is updated, a version ID is incremented to provide a traceability function for the historical versions of the access control policy. Each version ID and the hash value of the corresponding access control policy are recorded in the distributed storage module so that the hash value of the historical access control policy can be obtained through the version ID when an audit is required.

Citation Information

Patent Citations

  • Access control method and system based on block chain technology

    CN108123936A

  • Block chain-based access control method capable of hiding policies and attributes

    CN113836222A

  • Zero-trust security gateway implementation method and device based on block chain structure

    CN115987696A

  • Access control method based on block chain and attribute-based encryption

    CN116112244A

  • Block chain cross-chain access control method and device, electronic equipment and storage medium

    CN117220909A

Cited By

  • Block chain-based information security intelligent management system and method

    CN120639515A

  • Blockchain-based information security intelligent management system and method

    CN120639515B