Data access method based on time decay trust and attribute encryption and related equipment
Through the data access method based on time attenuation trust and attribute encryption, the user's trust is evaluated and data access rights are adjusted, and the problem of low data security in the prior art is solved, and efficient and stable data access is achieved.
Patent Information
- Application Number
- CN202510295115.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-17
AI Technical Summary
The existing data access methods have the problem of low data security.
The data access method based on time attenuation trust and attribute encryption is adopted. By obtaining the user's behavioral activity, time attenuation factor, identity identification and attribute information, the user's trust is evaluated, and the data access permission is adjusted according to the trust, and the data access path is determined through the attribute directed acyclic graph, and the secure access to the target data is finally achieved.
It improves the security of data access, dynamically adjusts user data access rights, reduces the complexity of global operations, and improves the operation stability of the data access system.
Smart Images

Figure CN120162824A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data access, and in particular, to a data access method, apparatus, computer device, computer-readable storage medium, and computer program product based on time-decaying trust and attribute encryption. Background Art
[0002] Access control is a system security technology for implementing established security policies. It manages all resource access requests, that is, makes a judgment on whether to permit each resource access request according to the requirements of the security policy, and monitors the operations of the visitors through the permission restrictions of the visitors.
[0003] Currently, the data access requests of users are responded to based on a traditional access control tree.
[0004] However, the current data access method has the problem of low data security. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide a data access method, apparatus, computer device, computer-readable storage medium, and computer program product based on time-decaying trust and attribute encryption that can improve data security.
[0006] In a first aspect, this application provides a data access method based on time-decaying trust and attribute encryption, including:
[0007] In response to a user's access request for target data stored on a blockchain, obtain the user's behavior activity, time decay factor, identity identifier, and attribute information;
[0008] Obtain the trustworthiness evaluation information of the user according to the behavior activity and the time decay factor;
[0009] Based on the user trustworthiness evaluation information and the identity identifier, obtain the user's data access permission, and when the data access permission meets the data access conditions of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request;
[0010] Perform data access on the target data through the data access path.
[0011] In one of the embodiments, obtaining the user's data access permission based on the user trustworthiness evaluation information and the identity identifier includes:
[0012] Obtain the initial data access permission corresponding to the user according to the identity identifier;
[0013] Adjust the initial data access permission based on the user trustworthiness evaluation information to obtain the user's data access permission.
[0014] In one embodiment, the initial data access permission is constructed through the following steps:
[0015] Obtain the user's behavior information and initial attribute information, and generate the initial trustworthiness of the user according to the information completeness of the user behavior information and the initial attribute information;
[0016] Generate the corresponding initial data access permission for the user based on the initial attribute information and the initial trustworthiness.
[0017] In one embodiment, data access to the target data is performed through a data access path, including:
[0018] Obtain the corresponding decryption key according to the attribute information; the decryption key corresponds to the encryption key used when encrypting the target data stored on the blockchain;
[0019] Obtain the target data through the data access path, and decrypt the target data using the decryption key.
[0020] In an exemplary embodiment, the behavior activity and time decay factor of the user are obtained through the following steps:
[0021] Obtain the number of data updates and the data update time of the user; the data update time includes the current time and the last data update time;
[0022] Construct the behavior activity of the user according to the number of data updates and the preset time interval length;
[0023] Construct the time decay factor of the user based on the current time and the last data update time.
[0024] In one embodiment, according to the behavior activity and the time decay factor, obtain the user trustworthiness evaluation information, including:
[0025] Obtain the first weight corresponding to the behavior activity and the second weight corresponding to the time decay factor;
[0026] Use the first weight and the second weight to perform weighted summation on the behavior activity and the time decay factor to obtain the user trustworthiness evaluation information of the user.
[0027] In a second aspect, the present application also provides a data access device based on time decay trust and attribute encryption, including:
[0028] A data acquisition module, configured to obtain the user's behavior activity level, time decay factor, identity identifier, and attribute information in response to a user's access request for target data stored on a blockchain;
[0029] A trust evaluation module, configured to obtain the user's trustworthiness evaluation information based on the behavior activity level and the time decay factor;
[0030] A permission acquisition module, configured to acquire the user's data access permission based on the user's trustworthiness evaluation information and the identity identifier, and traverse a pre-set attribute directed acyclic graph according to the attribute information when the data access permission meets the data access conditions of the target data, so as to obtain the data access path corresponding to the access request;
[0031] A data access module, configured to access the target data through the data access path.
[0032] Thirdly, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0033] In response to a user's access request for target data stored on a blockchain, obtain the user's behavior activity level, time decay factor, identity identifier, and attribute information;
[0034] Obtain the user's trustworthiness evaluation information based on the behavior activity level and the time decay factor;
[0035] Based on the user's trustworthiness evaluation information and the identity identifier, acquire the user's data access permission, and traverse a pre-set attribute directed acyclic graph according to the attribute information when the data access permission meets the data access conditions of the target data, so as to obtain the data access path corresponding to the access request;
[0036] Access the target data through the data access path.
[0037] Fourthly, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0038] In response to a user's access request for target data stored on a blockchain, obtain the user's behavior activity level, time decay factor, identity identifier, and attribute information;
[0039] Obtain the user's trustworthiness evaluation information based on the behavior activity level and the time decay factor;
[0040] Based on the user trustworthiness evaluation information and identity identifier, obtain the user's data access permission, and when the data access permission meets the data access condition of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request;
[0041] Perform data access on the target data through the data access path.
[0042] In a fifth aspect, the present application also provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0043] In response to a user's access request for target data stored on a blockchain, obtain the user's behavior activity, time decay factor, identity identifier, and attribute information;
[0044] Obtain the user's trustworthiness evaluation information according to the behavior activity and the time decay factor;
[0045] Based on the user trustworthiness evaluation information and identity identifier, obtain the user's data access permission, and when the data access permission meets the data access condition of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request;
[0046] Perform data access on the target data through the data access path.
[0047] The above data access method, device, computer device, computer-readable storage medium, and computer program product based on time decay trust and attribute encryption, in response to a user's access request for target data stored on a blockchain, obtain the user's behavior activity, time decay factor, identity identifier, and attribute information, obtain the user's trustworthiness evaluation information according to the behavior activity and the time decay factor, and adjust the user's data access permission based on the user trustworthiness evaluation information, and when the data permission meets the data access condition of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request, and finally perform data access on the target data through the data access path. By dynamically adjusting the user's corresponding data access permission according to the user's behavior activity and time decay factor, the security of data access is improved. In addition, the user's attribute information is used to determine the corresponding target data access path for data access. In this way, even if the permission on a certain path changes, the access of other path users will not be affected, significantly reducing the complexity of global operations, and thus improving the operation stability of the data access system. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the accompanying drawings required for the description of the embodiments of the present application or related technologies. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related accompanying drawings can be obtained based on these drawings.
[0049] Figure 1 It is an application environment diagram of a data access method based on time-decaying trust and attribute encryption in an embodiment;
[0050] Figure 2 It is a schematic flowchart of a data access method based on time-decaying trust and attribute encryption in an embodiment;
[0051] Figure 3 It is a schematic flowchart of a data access method based on time-decaying trust and attribute encryption in another embodiment;
[0052] Figure 4 It is a structural block diagram of a data access device based on time-decaying trust and attribute encryption in an embodiment;
[0053] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0054] In order to make the objectives, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0055] The data access method based on time-decaying trust and attribute encryption provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed on the cloud or other network servers. In response to an access request initiated by the user through the terminal 102 for target data stored on the blockchain, the server 104 obtains the user's behavior activity, time decay factor, identity identifier, and attribute information, obtains the user's trustworthiness evaluation information based on the behavior activity and the time decay factor, obtains the user's data access permission based on the user trustworthiness evaluation information and the identity identifier, and traverses a pre-set attribute directed acyclic graph according to the attribute information when the data access permission meets the data access conditions of the target data to obtain the data access path corresponding to the access request, and finally accesses the target data through the data access path. Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server 104 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0056] In an exemplary embodiment, as Figure 2 shown, a data access method based on time decay trust and attribute encryption is provided. Taking the method applied to Figure 1 the server 104 in
[0057] Step S201, in response to a user's access request for target data stored on the blockchain, obtain the user's behavior activity, time decay factor, identity identifier, and attribute information.
[0058] Among them, the blockchain can be understood as a distributed ledger technology that provides decentralized storage and access control, with high transparency, immutability, and security; the behavior activity can be understood as the statistics of a user's behavior within a specific time period to evaluate their activity level; the time decay factor can be understood as being calculated based on the user's most recent activity time to reflect the decay of the user's trust over time; the identity identifier can be understood as specific information of the user in the server, used to distinguish different users; the attribute information can be understood as various types of data related to the user's identity and characteristics, such as basic identity information, contact information, account information, preference settings, behavior data, permissions and roles, social information, and identity verification information.
[0059] Optionally, the user initiates an access request for the target data stored on the blockchain to the server 104 through the terminal 102. In response to the access request, the server 104 obtains the user's data update count, data update time, identity identifier, and attribute information, constructs the behavior activity based on the data update count and the pre-set time interval length, and constructs the user's time decay factor based on the data update time. Storing the data on the blockchain ensures the transparency and security of the data, and at the same time, by collecting multi-source data, it lays a data foundation for subsequent obtaining of data access permissions and data access.
[0060] Step S202, obtain the user's trust evaluation information based on the behavior activity and the time decay factor.
[0061] Among them, the trust evaluation information can be understood as the quantitative information of the server's trust in the user, and this quantitative information can be sorted and compared.
[0062] Exemplarily, the server 104 obtains the first weight corresponding to the behavior activity and the second weight corresponding to the time decay factor, and uses the first weight and the second weight to perform a weighted sum of the behavior activity and the time decay factor to obtain the user's trust evaluation information. By combining the behavior activity and the time decay factor, a comprehensive trust evaluation information is formed, which helps the server 104 obtain more data access permissions that conform to the user's current state, thereby improving the security of data access.
[0063] Step S203, based on the user trust evaluation information and the identity identifier, obtain the user's data access permissions, and when the data access permissions meet the data access conditions of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request.
[0064] Step S204, perform data access on the target data through the data access path.
[0065] Among them, the attribute directed acyclic graph can be understood as the relationship between attributes. Each node represents an attribute, and the direction indicates the dependence between attributes.
[0066] Optionally, the server 104 obtains the user's initial data access permission based on the identity identifier, adjusts the initial data access permission according to the user trustworthiness evaluation information to obtain the user's data access permission, and when the data access permission meets the data access condition of the target data, that is, the user passes the identity authentication and the permission indicates permission to access, traverses the pre-set attribute directed acyclic graph according to the attribute information, and determines the path in the attribute directed acyclic graph where the node attribute information matches the attribute information as the data access path corresponding to the access request, and performs data access on the target data through the data access path. Through the DAG (directed acyclic graph) structure, the user can meet the access permission requirements through different paths. In this way, even if the permission of a certain path changes, the access of other path users will not be affected, greatly improving the flexibility of permission management.
[0067] In the above data access method based on time decay trust and attribute encryption, in response to the user's access request for data, in response to the user's access request for the target data stored on the blockchain, obtain the user's behavior activity, time decay factor, identity identifier, and attribute information, obtain the user trustworthiness evaluation information according to the behavior activity and the time decay factor, and adjust the user's data access permission based on the user trustworthiness evaluation information, and when the data permission meets the data access condition of the target data, traverse the pre-set attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request, and finally perform data access on the target data through the data access path. By dynamically adjusting the user's corresponding data access permission according to the user's behavior activity and time decay factor, the security of data access is improved. In addition, the user's attribute information is used to determine the corresponding target data access path for data access. In this way, even if the permission on a certain path changes, the access of other path users will not be affected, significantly reducing the complexity of global operations, and thus improving the operation stability of the data access system.
[0068] In one embodiment, obtaining the user's data access permission based on the user trustworthiness evaluation information and the identity identifier includes: obtaining the initial data access permission corresponding to the user according to the identity identifier; adjusting the initial data access permission based on the user trustworthiness evaluation information to obtain the user's data access permission.
[0069] Exemplarily, the server 104 queries the initial data access rights owned by the user stored in the data storage system according to the user's identity identifier, and then adjusts the access rights based on the user trustworthiness evaluation information. The higher the trustworthiness evaluation information, the higher the corresponding data access rights. By realizing the dynamic synchronization of the trustworthiness evaluation information and the data access rights, users with higher trustworthiness can obtain wider access rights, while users with lower trustworthiness may be subject to certain access restrictions, and even in extreme cases, be restricted from accessing critical data, thereby ensuring the security of the data.
[0070] In one embodiment, the initial data access rights are constructed through the following steps: obtaining the user's behavior information and initial attribute information, and generating the initial trustworthiness of the user according to the information integrity of the user's behavior information and initial attribute information; generating the corresponding initial data access rights for the user based on the initial attribute information and the initial trustworthiness.
[0071] Among them, the initial trustworthiness can be understood as a quantitative index used to reflect the trustworthiness of a user in a specific system or environment.
[0072] Optionally, the server 104 obtains the user's behavior information and the initial attribute information when the user first logs in to the server 104, and generates the initial trustworthiness of the user according to the information integrity of the user's behavior information and initial attribute information. Then, based on the initial attribute information and the initial trustworthiness, the corresponding initial data access rights are granted to the user. Granting the corresponding initial data access rights to the user can satisfy the user's first data access request, ensure the speed and accuracy of the service response, and thereby improve the user's service experience.
[0073] In an exemplary embodiment, data access to the target data is performed through a data access path, including: obtaining the corresponding decryption key according to the attribute information; the decryption key corresponds to the encryption key used when encrypting the target data stored on the blockchain; obtaining the target data through the data access path, and decrypting the target data using the decryption key.
[0074] Among them, the target data can be understood as the ciphertext encrypted with the encryption key stored on the blockchain. The blockchain generates a system public key and a master private key, encrypts the target data using the system public key, and defines the access structure according to the attributes.
[0075] Exemplarily, the server 104 generates a decryption key corresponding to the user according to the attribute information and the pre-constructed master private key, and verifies whether the decryption key meets the access control structure defined during encryption. If it meets the requirements, the target data is obtained through the data access path and decrypted using the decryption key to obtain the inscripted data; if it does not meet the requirements, the data access request is rejected and a reminder of insufficient user permissions is returned. As the requirements change, the system can easily adjust the access control structure or the key generation algorithm to adapt to new business scenarios or security requirements. At the same time, when the user's permissions are insufficient, the system can promptly reject the data access request and return a clear reminder, improving the user experience.
[0076] In one embodiment, the user's behavior activity and time decay factor are obtained through the following steps: Obtain the number of data updates and the data update time of the user; the data update time includes the current time and the last data update time; according to the number of data updates and the length of the preset time interval, construct the user's behavior activity; based on the current time and the last data update time, construct the user's time decay factor.
[0077] Optionally, 1. Determine the frequency of user data updates:
[0078] 1) Collect data update records: The system collects each data update behavior of the user and records the specific timestamp t update 。
[0079] 2) Update frequency: The update frequency refers to the number of times the user updates data within a certain time window (such as one week or one month). Assuming the time window is T, the user's update frequency can be expressed as:
[0080]
[0081] where N update is the number of updates of the user within the time window T.
[0082] 2. Standardize the behavior activity A u :
[0083] Standardize the user behavior evidence to ensure that its value is within the range of [0, 1].
[0084] 1) Set the valid range: To make the update frequency comparable, define a reasonable update frequency range 。
[0085] 2) Standardize the update frequency: Standardize the original update frequency so that it falls within the range of [0, 1]. The standardization formula is as follows:
[0086]
[0087] This standardization process results in lower scores for users with too low update frequencies, while users who update data frequently receive higher scores.
[0088] 3. Calculate the time decay factor D u :
[0089] The trustworthiness of user behavior should decay gradually over time to prevent users from maintaining a high level of trust after a long period of inactivity. The time decay factor D u is calculated as follows:
[0090]
[0091] where is the decay rate, t current is the current time, and t last is the time when the user last updated the data. This formula ensures that over time, the user's trustworthiness gradually decreases unless the user updates the data regularly.
[0092] By adopting a time decay function, the user's trustworthiness gradually decreases over time to prevent long-term inactive users from maintaining a high level of trust. At the same time, the frequency of the user's data updates is introduced as an important parameter to measure activity, ensuring that users who frequently contribute data can maintain a relatively high trust score.
[0093] In one embodiment, based on the behavior activity and the time decay factor, the user's trustworthiness evaluation information is obtained, including: obtaining the first weight corresponding to the behavior activity and obtaining the second weight corresponding to the time decay factor; using the first weight and the second weight, performing a weighted sum on the behavior activity and the time decay factor to obtain the user's trustworthiness evaluation information.
[0094] Exemplarily, calculate the user's trustworthiness T u (i.e., the aforementioned user trustworthiness evaluation information):
[0095] Define the weight vector: Considering that different systems may have different attentions to behavior activity and time decay, a weight vector is introduced to perform weighted processing on each factor. Assume the weight of behavior activity is w f , and the weight of the time decay factor is w t , then the calculation formula for trustworthiness is:
[0096]
[0097] where w f (i.e., the aforementioned first weight) and w t (i.e., the aforementioned second weight) represent the weights of behavior activity and the time decay factor, and the sum of the two should be equal to 1:
[0098]
[0099] This formula combines behavioral activity with a time decay factor to form a comprehensive trust score. It helps users screen the shared information to obtain a better user experience. By assigning different weights to the behavioral activity and the time decay factor, the system can flexibly adjust the calculation method of trust according to the requirements of specific application scenarios. This flexibility makes the trust evaluation more accurate, can reflect different focuses of the system on user behavior, and thus improves the accuracy of obtaining user trust evaluation information.
[0100] In an exemplary embodiment, as Figure 3 shown, a specific implementation of a data access method based on time decay trust and attribute encryption is provided, including steps S301 to S308. Among them:
[0101] Step S301, in response to a user's access request for target data stored on the blockchain, obtain the user's data update count, data update time, identity identifier, and attribute information.
[0102] Step S302a, according to the identity identifier, obtain the initial data access permission corresponding to the user; the initial data access permission is generated according to the user's behavior information and initial attribute information.
[0103] Step S302b, according to the data update count and the preset time interval length, construct the user's behavioral activity.
[0104] Step S303b, based on the current time and the last data update time, construct the user's time decay factor.
[0105] Step S304b, use the first weight corresponding to the behavioral activity and the second weight corresponding to the time decay factor to perform weighted summation on the behavioral activity and the time decay factor to obtain the user's trust evaluation information.
[0106] Step S305, based on the user trust evaluation information, adjust the initial data access permission to obtain the user's data access permission.
[0107] Step S306, traverse the preset attribute directed acyclic graph according to the attribute information to obtain the data access path corresponding to the access request.
[0108] Step S307, obtain the corresponding decryption key according to the attribute information; the decryption key corresponds to the encryption key used when encrypting the target data stored on the blockchain.
[0109] Step S308: Obtain the target data through the data access path and decrypt the target data using the decryption key.
[0110] In a specific application environment, the specific implementation of the above process is as follows:
[0111] 1. Trust evaluation model based on activity and time decay:
[0112] This model focuses on the behavior of users updating data, specifically the number of times a user updates data within a given time period. By introducing the update frequency as a key parameter and combining it with the time decay factor, the trust score can be dynamically adjusted. The key variables of the model include the user's update frequency, the time decay factor, and the weight of the user's update behavior. The core structure of this model consists of the following parts:
[0113] User behavior activity A u : Evaluate the activity level by counting the user's behavior within a specific time. Time decay factor D u : Calculate based on the time of the user's last activity to reflect the decay of the user's trust over time. Trust level T u : The final evaluation result, reflecting the overall trust status of the user. The specific calculation steps are as follows:
[0114] Step1: Determine the frequency of the user updating data:
[0115] 1) Collect data update records: The system collects each data update behavior of the user and records the specific timestamp t update .
[0116] 2) Update frequency: The update frequency refers to the number of times a user updates data within a certain time window (such as a week or a month). Assuming the time window is T, the user's update frequency can be expressed as:
[0117]
[0118] where N update is the number of updates by the user within the time window T.
[0119] Sep2: Standardize the behavior activity A u :
[0120] Standardize the user behavior evidence to ensure its value is within the range of [0, 1].
[0121] 1) Set the valid range: To make the update frequencies comparable, define a reasonable range of update frequencies .
[0122] 2) Standardized update frequency: Standardize the original update frequency so that it falls within the range of [0, 1]. The standardization formula is as follows:
[0123]
[0124] This standardization process gives lower scores to users with too low update frequencies, while users who update data frequently receive higher scores.
[0125] Step3: Calculate the time decay factor D u :
[0126] The trust in user behavior should gradually decay over time to prevent users from maintaining a high level of trust after being inactive for a long time. The time decay factor D u is calculated as follows:
[0127]
[0128] where is the decay rate, t current is the current time, and t last is the time when the user last updated the data. This formula ensures that the trust in the user gradually decreases over time, unless the user updates the data regularly.
[0129] Step4: Calculate the user's trust level T u :
[0130] Define the weight vector: Considering that different systems may have different levels of attention to behavioral activity and time decay, introduce a weight vector to weight each factor. Assume the weight of behavioral activity is w f , and the weight of the time decay factor is w t , then the formula for calculating the trust level is:
[0131]
[0132] where w f and w t represent the weights of behavioral activity and the time decay factor, and the sum of the two should be equal to 1:
[0133]
[0134] This formula combines behavioral activity with the time decay factor to form a comprehensive trust score. It helps users screen the shared information to obtain a better user experience.
[0135] 2. Data security access control technology based on smart contracts and attribute encryption:
[0136] The data security access control technology based on smart contracts and attribute encryption is closely combined with the trust evaluation model to jointly construct a dynamic, flexible and secure data access control mechanism. In this solution, the trust evaluation model dynamically adjusts the user's trust level by calculating the user's activity and time decay factor, and hands over the evaluation results to the smart contract for management to adjust the user's access rights in real time. Users with a higher trust level can obtain more access rights, while users with a lower trust level may be restricted in their rights or even have their access rights revoked. To further improve the flexibility of the system, this technology consists of the basic process of attribute encryption and the multi-path attribute encryption access control technology. The two work together to make the permission management both secure and efficient. The basic process of attribute encryption defines the encryption and decryption methods to ensure that the data can only be accessed by users who meet specific attributes, providing basic security protection for access control. However, traditional attribute encryption has problems such as complex permission adjustment and large impact on global changes. Therefore, this solution introduces the multi-path attribute encryption access control technology. Through the DAG (Directed Acyclic Graph) structure, users can meet the access permission requirements through different paths. In this way, even if the permissions of a certain path change, the access of users on other paths will not be affected, greatly improving the flexibility of permission management. At the same time, the smart contract combines the trust evaluation system to enable the permission allocation to be automatically adjusted according to the changes in user behavior, ensuring that the system has higher adaptability and operability while ensuring security.
[0137] There are three roles for the technical solution designed in this paper, namely USER (user), BC (block chain), and SC (Smart Contract). There are three roles:
[0138] USER: The user can be the user or owner of the data file. The owner can modify, update, and access the file, while the user can only read the file. BC: The blockchain platform (BC) replaces the CDC (cloud storage provider) in the traditional solution. The blockchain platform provides decentralized storage and access control. The encryption of the file, key generation, and access control policy are executed through the smart contract. The blockchain has high transparency, immutability, and security, and can ensure the management of user file sharing and access requests. SC: The smart contract (SC) undertakes the responsibilities of the TPA (third-party audit institution) and is used to manage access control, permission update, authentication, and key update. All user access behaviors and permission changes will be recorded and verified through the smart contract to ensure the accuracy and effectiveness of access control.
[0139] (1) Basic process of attribute encryption:
[0140] This solution aims to achieve decentralized, automated access control and data encryption / decryption management through blockchain and smart contracts, ensuring data security and flexible management of permissions. The specific steps are as follows:
[0141] Step1: Setup (Initialization):
[0142] The blockchain platform generates the system public key PK and the master private key MK. At the same time, the smart contract is uploaded to the blockchain. After successful deployment, the USER can interact with the blockchain through the smart contract.
[0143] Step2: (Encryption):
[0144] The USER encrypts the file M using the blockchain system public key PK and defines the access structure A according to the attributes. The encrypted ciphertext CT is stored in the blockchain, and the relevant access permission information of the ciphertext is stored and updated through the smart contract. The encryption process is completed by the blockchain nodes, and the index of the ciphertext storage and the permission verification are managed by the smart contract, ensuring that the user can only read the ciphertext when specific attribute conditions are met.
[0145] Step3: (Private Key Generation):
[0146] The system generates the user private key SK according to the master private key MK and the user's attribute set S. This private key is bound to the user's blockchain address, and the smart contract manages the user's access permissions. The private key generation can be completed at any node of the blockchain, but its permission information and distribution process are recorded by the smart contract to ensure the secure distribution of the key. The smart contract is responsible for generating, distributing, and managing the user's private key SK and ensuring the update or redistribution of the private key when the permissions change.
[0147] Step4: (Decryption):
[0148] When the user wants to access the file M, the blockchain verifies whether the user's private key SK meets the access control structure A defined during encryption. If the condition is met, the user can read the ciphertext CT through the smart contract and decrypt it to obtain the plaintext M. The decryption operation is completed by the smart contract, and the user's private key SK is matched with the access control structure A stored on the blockchain. If the match is successful, the decryption request is approved by the blockchain, and the user can read the plaintext.
[0149] (2) Multi-Path Attribute Encryption Access Control Technology:
[0150] In the traditional access control tree model, access control often relies on a single path or rule structure. As a result, when users need different permissions, they must redefine or modify the global permission rules. The access control structure in this technical design solution is based on a distributed attribute graph (DAG), and permission management is carried out through smart contracts. Nodes in the DAG represent attributes, and different paths represent different access conditions or permission combinations. Through the DAG structure, users can verify permissions from multiple paths, and the smart contract is responsible for automatically judging whether the user meets the access conditions according to the preset rules.
[0151] Step1: Initialization phase:
[0152] 1) Definition of attribute set:
[0153] Each data file corresponds to an attribute set U, U = {U1, U2, U3, …, Un}. The private key set PA generated by the file owner is a non-empty subset of U, PA = {P1, P2, P3, …, Pm}, where m ≤ n. When a user accesses a data file, its private key set PA will be matched with the paths in the DAG to determine whether it has access permissions. The smart contract will be responsible for automatically verifying these attribute combinations to ensure that the accessor meets the requirements on the DAG path.
[0154] 2) Definition of the key attribute KA of the file:
[0155] The key attribute KA of the file serves as the core node in the DAG. The smart contract determines which users have the file modification permission based on the KA node. Due to the flexibility of the DAG structure, different users can obtain the permission of the KA node through different paths, which simplifies permission management. The smart contract is responsible for monitoring the modification permission requests of the KA node to ensure that only eligible users are allowed to modify the file, while the access paths of other users are not affected. This avoids the permission conflict problem caused by modifying permissions in the traditional access control tree.
[0156] 3) Definition of the identification attribute RA of the file:
[0157] The identification attribute RA of the file is based on the Merkle Hash Tree (root node value). When a user accesses a data file, the smart contract conducts version verification through the RA node to ensure that the data read by the user is the latest version. The introduction of the RA node allows the smart contract to automatically trigger the verification process when the file changes, notify the user in advance of the modification of the data file, and prevent the user from reading expired or dirty data.
[0158] 4) Deployment of the smart contract:
[0159] In the initialization phase, the smart contract is deployed on the blockchain. The smart contract will record the PA of each user and establish rules based on the attribute set U to control the user's access rights. These smart contracts will also be responsible for subsequent permission changes, revocation, and permission checking operations to ensure the system is automated, efficient, and secure.
[0160] Step2: File access phase:
[0161] 1) User submits an access request:
[0162] When a user needs to access a file, they submit their request to the system. The system receives the user's PA and access intent (such as read, modify, etc. operations). The user's PA contains the permission attributes they possess, such as file read permission, modify permission, etc.
[0163] 2) Path selection and DAG verification:
[0164] The system selects the most appropriate access path based on the user's PA and different paths in the DAG structure. Each node in the DAG represents a different permission level, and the user's access path is determined by the attributes they possess. The advantage of multi-path access control is reflected here: users can access the same file through different paths, and different paths represent different permission combinations. For example, user A may only be able to read the file through path 1, while user B can not only read but also modify the file through path 2.
[0165] 3) Smart contract performs permission checking:
[0166] After receiving the user's request, the smart contract verifies the user's PA to ensure that the set of attributes the user possesses complies with the access control policy. If the user's PA contains RA, then they have read permission; if the user's PA also contains KA, then they have modify permission. If the permission level of the path the user passes through is insufficient (such as not having the KA attribute), the smart contract will restrict the user's operation to read-only or reject the modification request.
[0167] 4) Data file access verification:
[0168] After passing the verification of the smart contract, the user can access the data file. Before accessing, the RA attribute is used to verify the integrity of the data file (verify whether the file has been tampered with through the Merkle tree root node value). If the file verification passes, the user can read or modify the file.
[0169] Step 3: Permission change and revocation phase:
[0170] 1) Initiate a permission change request:
[0171] When the system needs to change or revoke a user's access rights, a user with KA permissions will initiate a change or revocation request. This operation will trigger a smart contract to start verifying the permissions of the initiator to ensure that they have the modification permissions.
[0172] 2) The smart contract verifies KA permissions:
[0173] The system will check through the smart contract whether the PA set of the initiator contains the KA attribute. Only users with the KA attribute have the permission to modify the access rights of other users. If the verification passes, the system will modify the user's PA according to the request and reconfigure their access rights.
[0174] The advantages of multi-path access control are reflected here: During permission change or revocation operations, since different users access the same file through different paths, the permission change will only affect the users in the current path and will not affect the users in other paths. This mechanism can effectively avoid the complexity of "global change" in traditional access control and only adjusts the permissions for specific paths or specific users, greatly reducing the impact on other parts of the system.
[0175] Compared with the existing technology, the present application has the following advantages:
[0176] 1) Improve the accuracy of trust assessment:
[0177] By introducing a time decay function, this technical solution can better reflect the dynamic changes of user trust. Traditional trust assessment often relies on static data and ignores the characteristics of user behavior evolving over time, resulting in the lag and distortion of trust assessment. The application of the time decay function makes the trust value gradually decrease over time, prompting the system to update the user's trust assessment in a timely manner. For example, when a user does not participate in interactions for a period of time, their trust value will gradually decrease, thus truly reflecting the user's current state. Such an improvement can effectively avoid making wrong decisions based on outdated data, thereby enhancing the security and user experience of the system.
[0178] 2) Provide multi-path attribute encryption access:
[0179] By integrating the attribute directed acyclic graph, attribute encryption, and smart contracts, efficient access control and permission management are achieved. First of all, the advantage of multi-path access control is that it greatly reduces the global impact of permission changes, making each change only affect the users in the current path and ensuring the stable access of users in other paths.
[0180] 3) Improve the security of data sharing:
[0181] The introduction of attribute encryption ensures that only users with corresponding attributes can decrypt and access data, further enhancing security. The automated permission management of smart contracts reduces the need for human intervention, ensuring the timeliness and accuracy of permission verification and revocation operations. In addition, due to the DAG design, the impact of revocation operations is restricted to specific paths, greatly reducing the impact on other users and ensuring the stability and security of data access.
[0182] Generally speaking, by comprehensively applying technologies such as trust assessment, attribute encryption, and access control, the security, transparency, and user experience in the data sharing process are improved, providing a more data-private solution for users. At the same time, problems such as inefficient permission management and large global impact in the existing technology are solved, and a flexible and efficient access control model is provided to meet the permission management requirements in complex scenarios.
[0183] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0184] Based on the same inventive concept, the embodiments of the present application also provide a data access device based on time-decaying trust and attribute encryption for implementing the above-mentioned data access method based on time-decaying trust and attribute encryption. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the following data access devices based on time-decaying trust and attribute encryption can refer to the limitations on the data access method in the above text, and will not be repeated here.
[0185] In an exemplary embodiment, as Figure 4 shown, a data access device based on time-decaying trust and attribute encryption is provided, including: a data acquisition module 401, a trust assessment module 402, a permission acquisition module 403, and a data access module 404, where:
[0186] The data acquisition module 401 is configured to obtain the user's behavior activity, time decay factor, identity identifier, and attribute information in response to a user's access request for target data stored on the blockchain;
[0187] A trust evaluation module 402, configured to obtain trust evaluation information of a user according to the behavior activity and the time decay factor;
[0188] A permission acquisition module 403, configured to acquire the data access permission of the user based on the user trust evaluation information and the identity identifier, and traverse a pre-set attribute directed acyclic graph according to the attribute information when the data access permission meets the data access condition of the target data, so as to obtain the data access path corresponding to the access request;
[0189] A data access module 404, configured to perform data access on the target data through the data access path.
[0190] In one embodiment, the permission acquisition module 403 further includes an initial permission acquisition sub-module and an initial permission adjustment sub-module, where:
[0191] The initial permission acquisition sub-module is configured to acquire the initial data access permission corresponding to the user according to the identity identifier;
[0192] The initial permission adjustment sub-module is configured to adjust the initial data access permission based on the user trust evaluation information to obtain the data access permission of the user.
[0193] In one of the embodiments, the data access device further includes an initial permission construction module, configured to acquire the user behavior information and the initial attribute information of the user, and generate the initial trust degree of the user according to the information integrity of the user behavior information and the initial attribute information; generate the initial data access permission corresponding to the user based on the initial attribute information and the initial trust degree.
[0194] In an exemplary embodiment, the data access module 404 is further configured to obtain the corresponding decryption key according to the attribute information; the decryption key corresponds to the encryption key used when encrypting the target data stored on the blockchain; obtain the target data through the data access path, and decrypt the target data by using the decryption key.
[0195] In one embodiment, the data acquisition module 401 is further configured to acquire the data update times and the data update time of the user; the data update time includes the current time and the last data update time; construct the behavior activity of the user according to the data update times and the pre-set time interval length; construct the time decay factor of the user based on the current time and the last data update time.
[0196] In one embodiment, the trust evaluation module 402 is further configured to obtain a first weight corresponding to the behavior activity level and a second weight corresponding to the time decay factor; and use the first weight and the second weight to perform a weighted sum of the behavior activity level and the time decay factor to obtain the user trust degree evaluation information of the user.
[0197] Each module in the above data access device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0198] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the behavior activity level, the time decay factor, the identity identifier, the attribute information, the trust degree evaluation information, and the target data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data access method.
[0199] Those skilled in the art can understand that Figure 5 the structure shown in
[0200] merely represents a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0201] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the data access method based on time-decaying trust and attribute encryption in the above embodiment is implemented.
[0202] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the data access method based on time-decaying trust and attribute encryption in the above embodiment is implemented.
[0203] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0204] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0205] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0206] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A data access method based on time decay trust and attribute encryption, characterized in that: The method comprises: In response to a user's access request for target data stored on the blockchain, obtaining the user's behavioral activity, time decay factor, identity, and attribute information; Obtaining trust evaluation information of the user according to the behavior activity and the time decay factor; Based on the user trust evaluation information and the identity identifier, obtain the user's data access permission, and if the data access permission meets the data access condition of the target data, traverse a preset attribute directed acyclic graph according to the attribute information to obtain a data access path corresponding to the access request; The target data is accessed through the data access path.
2. The method according to claim 1, characterized in that The obtaining the data access permission of the user based on the user trust evaluation information and the identity identifier includes: According to the identity identifier, obtaining an initial data access permission corresponding to the user; The initial data access permission is adjusted based on the user trust evaluation information to obtain the data access permission of the user.
3. The method according to claim 2, characterized in that The initial data access permission is constructed by the following steps: Acquiring user behavior information and initial attribute information of the user, and generating an initial trust degree of the user according to the information completeness of the user behavior information and the initial attribute information; Based on the initial attribute information and the initial trust level, an initial data access permission corresponding to the user is generated.
4. The method according to claim 1, characterized in that: The step of accessing the target data through the data access path includes: Obtaining a corresponding decryption key according to the attribute information; the decryption key corresponds to the encryption key used when encrypting the target data stored on the blockchain; The target data is acquired through the data access path, and the target data is decrypted using the decryption key.
5. The method according to claim 1, characterized in that The user's behavior activity and time decay factor are obtained by following the steps below: Obtain the number of data updates and the data update time of the user; the data update time includes the current time and the last data update time; Constructing the user's behavioral activity according to the data update times and the preset time interval length; A time decay factor of the user is constructed based on the current time and the last data update time.
6. The method according to claim 1, characterized in that The obtaining the trust evaluation information of the user according to the behavior activity and the time decay factor includes: Obtaining a first weight corresponding to the activity of the behavior, and obtaining a second weight corresponding to the time decay factor; The first weight and the second weight are used to perform a weighted summation on the behavior activity and the time decay factor to obtain user trust evaluation information of the user.
7. A data access device based on time decay trust and attribute encryption, characterized in that: The device comprises: A data acquisition module, for obtaining the user's behavioral activity, time decay factor, identity, and attribute information in response to a user's access request for target data stored on the blockchain; A trust evaluation module, used to obtain trust evaluation information of the user according to the behavior activity and the time decay factor; A permission acquisition module, configured to acquire the data access permission of the user based on the user trust evaluation information and the identity identifier, and, if the data access permission meets the data access condition of the target data, traverse a preset attribute directed acyclic graph according to the attribute information to acquire a data access path corresponding to the access request; A data access module is used to access the target data through the data access path.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.