Zero-trust API dynamic access control method, computer device and medium

By generating a unified decentralized digital identity identification and DAO governance structure, combined with multi-dimensional risk assessment, the problems of user identity information dispersion and privacy leakage are solved, secure and flexible API access control is achieved, and user experience and system security are improved.

CN120296755APending Publication Date: 2025-07-11BEIJING VRV SOFTWARE CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510292329.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the existing API access control technology, the dispersion of user identity information leads to cumbersome identity authentication, centralized identity authentication servers are prone to becoming a single point of failure and have the risk of privacy leakage, and the dynamic access control mechanism lacks effective protection of user privacy.

Method used

By collecting the original identity information of users in different systems, generating unified decentralized digital identity identifiers, using blockchain and DAO governance structures for identity management and access strategy formulation, combining multi-dimensional risk assessment to achieve dynamic access control, and using zero-knowledge proof and homomorphic encryption technology to protect user privacy.

Benefits of technology

Decentralized identity authentication and access control are realized, system security and user experience are improved, privacy leakage risks are reduced, and they are adapted to different business systems and security environments, with flexibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296755A_ABST
    Figure CN120296755A_ABST
Patent Text Reader

Abstract

The invention discloses a zero-trust API dynamic access control method, a computer device and a medium. The method comprises the following steps: processing all collected original identity information of a user in different systems through a preset aggregation strategy, and generating a unified decentralized digital identity label of the user based on a block chain; a basic governance structure of DAO is configured on a block chain network, and based on the structure, an initial access strategy corresponding to each user is determined in a DAO member voting mode; acquiring multi-dimensional information for initiating access, and performing multi-dimensional risk assessment on the multi-dimensional information including time dimension information, space dimension information, equipment dimension information and network dimension information based on a preset multi-dimensional weight to obtain comprehensive risk assessment information; and obtaining an access control strategy according to the comprehensive risk assessment information and the initial access strategy. The method can adapt to rapid identity authentication in different service systems and security environments, and is high in flexibility and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of access control, and in particular, to a zero-trust API dynamic access control method, a computer device, and a medium. Background Art

[0002] API access control is a key technology in modern distributed systems and microservices architectures, ensuring that only authorized users or applications can access specific API resources. With the popularization of cloud computing and distributed systems, secure access control of APIs has become crucial.

[0003] Currently, common API access control technologies include token-based authentication (such as JWT) and role-based access control (RBAC). These technologies manage API access through predefined role and permission rules and rely on a centralized identity authentication server for authentication. Some advanced solutions adopt a zero-trust architecture, introducing a dynamic access evaluation mechanism that can perform real-time risk assessment based on multi-dimensional information such as user identity, device status, and network environment at each access request and dynamically decide whether to grant access permissions.

[0004] However, there are still some problems in the existing technologies: First, the digital identity information of users is scattered in different systems, resulting in a cumbersome identity authentication process and a poor user experience; Second, the centralized identity authentication server is prone to being a single point of failure and there is a risk of user privacy leakage; Finally, the existing dynamic access control mechanisms lack effective protection for user privacy. Summary of the Invention

[0005] In view of this, the embodiments of the present disclosure provide a zero-trust API dynamic access control method, a computer device, and a medium, which can solve the problems existing in the prior art such as cumbersome identity authentication processes, easy leakage of user privacy, poor flexibility, and poor user experience for different business systems and security environments.

[0006] In a first aspect, the embodiments of the present disclosure provide a zero-trust API dynamic access control method, including:

[0007] Collect the original identity information of users in different systems, and process all the original identity information through a preset aggregation policy to generate a unified decentralized digital identity identifier of the users;

[0008] Configure the basic governance structure of the DAO on the blockchain network; the basic governance structure includes one or more of user identity management, voting mechanism, decision-making process, deployed smart contract addresses, and contract interfaces;

[0009] Based on the basic governance structure, determine the initial access policy corresponding to each user through voting by DAO members;

[0010] Collect multi-dimensional information of the initiated access, and conduct multi-dimensional risk assessment on the multi-dimensional information based on preset multi-dimensional weights to obtain comprehensive risk assessment information;

[0011] The multi-dimensional information includes one or more of time dimension information, space dimension information, device dimension information, and network dimension information;

[0012] Obtain the access control policy according to the comprehensive risk assessment information and the initial access policy.

[0013] Optionally, processing all the original identity information through a preset aggregation policy to generate a unified decentralized digital identity identifier for the user, including:

[0014] Collect the original identity information of the user in different systems;

[0015] Perform privacy protection processing on each original identity information through zero-knowledge proof technology to generate a corresponding encrypted identity data packet;

[0016] Verify the validity of the identity information of each encrypted identity data packet, and record the encrypted identity data packet that passes the verification as the target data packet;

[0017] Aggregate all the target data packets to generate a unified encrypted data packet for the user;

[0018] Establish a blockchain network according to the determined blockchain platform and network construction method, and deploy a smart contract based on the unified encrypted data packet. The smart contract contains the mapping relationship between the unified encrypted data packet of all users and the blockchain address;

[0019] Generate a decentralized identifier according to the W3C DID specification;

[0020] Embed the unified encrypted data packet into the decentralized identifier to generate a unified decentralized digital identity identifier for the user, and record the information containing the unified decentralized digital identity identifier on the blockchain network.

[0021] Optionally, configuring the basic governance structure of the DAO on the blockchain network includes:

[0022] Configure one or more of a member management contract, a proposal management contract, an execution contract, and an asset management contract on the blockchain network;

[0023] Establish a DAO on the blockchain network and handle user identity management through the member management contract;

[0024] The user identity management includes the registration, withdrawal, and permission management of DAO members; the voting mechanism is executed through the proposal management contract for handling the submission, discussion, and voting processes of policy proposals; the decision-making process is executed through the execution contract to ensure the automatic execution of the voting results and policy updates; the incentive mechanism of the DAO is managed through the asset management contract.

[0025] Optionally, based on the basic governance structure, the initial access policy corresponding to each user is determined by voting of DAO members, including

[0026] Based on all different systems, determine the set of access permission items and the set of DAO member roles;

[0027] According to the set of access permission items and the set of DAO member roles, obtain the voting results of DAO members on each access permission item for the user;

[0028] Based on the voting results of each DAO member and the role weights of the corresponding DAO members, determine the comprehensive evaluation information of each access permission item;

[0029] According to the comprehensive evaluation information of all access permission items, determine the initial access policy corresponding to each user.

[0030] Optionally, the comprehensive evaluation information is S i :

[0031]

[0032]

[0033] where role(m l ) is the role to which DAO member m l belongs, is the weight of the role to which member m l belongs, v l,i is the voting result of member m l on the access permission item p i for the user, m is the total number of roles of DAO members, is the weight of the jth role.

[0034] Optionally, the time dimension information includes the abnormal information of the request access time; the space dimension information includes the credibility information of the access location; the device dimension information includes the status information of the device initiating the access; the network dimension information includes the security information of the network connection;

[0035] Performing multi-dimensional risk assessment on the multi-dimensional information based on preset multi-dimensional weights to obtain comprehensive risk assessment information, including:

[0036] Analyzing the time dimension information based on the preset access time range corresponding to the user to obtain a time dimension assessment result;

[0037] Analyzing the space dimension information to obtain a space dimension assessment result;

[0038] Analyzing the device dimension information to obtain a device dimension assessment result;

[0039] Analyzing the network dimension information to obtain a network dimension assessment result;

[0040] Based on the preset multi-dimensional weights, respectively performing weighted summation on the time dimension assessment result, the space dimension assessment result, the device dimension assessment result, and the network dimension assessment result to obtain comprehensive risk assessment information.

[0041] Optionally, before obtaining the access control policy according to the comprehensive risk assessment information and the initial access policy, further including:

[0042] Collecting the historical access data and security events of the user based on the unified decentralized digital identity identifier, and preprocessing the historical access data and the security events to obtain a standard data set;

[0043] Training a preset machine learning model through the standard data set, and denoting the trained preset machine learning model as the target model;

[0044] Analyzing the initial access policy based on the target model to obtain the optimized initial access policy;

[0045] Obtaining the access control policy according to the comprehensive risk assessment information and the optimized initial access policy.

[0046] In a second aspect, the present application discloses a zero-trust API dynamic access control system, specifically including:

[0047] A unified decentralized digital identity identifier generation module, configured to collect the original identity information of the user in different systems, and process all the original identity information through a preset aggregation strategy to generate a unified decentralized digital identity identifier of the user;

[0048] A configuration module, configured to configure the basic governance structure of the DAO on the blockchain network; the basic governance structure includes one or more of user identity management, voting mechanism, decision-making process, deployed smart contract addresses, and contract interfaces;

[0049] An initial access policy determination module, configured to determine an initial access policy corresponding to each user based on a basic governance structure by means of voting by DAO members;

[0050] A comprehensive risk assessment information acquisition module, configured to collect multi-dimensional information for initiating an access, and perform multi-dimensional risk assessment on the multi-dimensional information based on preset multi-dimensional weights to obtain comprehensive risk assessment information; the multi-dimensional information includes time-dimensional information, space-dimensional information, device-dimensional information, and network-dimensional information;

[0051] An access control policy acquisition module, configured to obtain an access control policy according to the comprehensive risk assessment information and the initial access policy.

[0052] Thirdly, an embodiment of the present disclosure further provides a computer device, adopting the following technical solution:

[0053] The computer device includes:

[0054] At least one processor; and,

[0055] A memory communicatively connected to the at least one processor; wherein,

[0056] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the zero-trust API dynamic access control method described in any one of the above.

[0057] Fourthly, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute the zero-trust API dynamic access control method described in any one of the above.

[0058] Fifthly, an embodiment of the present disclosure further provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in any one of the above are implemented.

[0059] The zero-trust API dynamic access control method disclosed in this application collects the original identity information of users in different systems, processes all the original identity information through a preset aggregation policy, and generates a unified decentralized digital identity identifier for users based on the blockchain; configures the basic governance structure of the DAO on the blockchain network; the basic governance structure includes user identity management, voting mechanism, decision-making process, deployed smart contract addresses, and contract interfaces; based on the basic governance structure, determines the initial access policy corresponding to each user through the voting of DAO members; collects multi-dimensional information for initiating access, and conducts multi-dimensional risk assessment on the multi-dimensional information including time dimension information, space dimension information, device dimension information, and network dimension information based on a preset multi-dimensional weight to obtain comprehensive risk assessment information; obtains the access control policy according to the comprehensive risk assessment information and the initial access policy; the entire solution is based on the zero-trust concept, by default, does not trust any users and devices, and through dynamic access control and multi-dimensional risk assessment, ensures that only authorized users and devices can access system resources, improving the security of the system; at the same time, it can adapt to different business systems and security environments, realizes decentralized governance and management through the blockchain and DAO, and realizes dynamic access control through machine learning and multi-dimensional risk assessment, with strong flexibility and scalability; on the premise of ensuring security, through personalized access policies and real-time access control decisions, reduces unnecessary access restrictions and improves the access efficiency and experience of users.

[0060] The above description is only an overview of the technical solution of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present disclosure more obvious and understandable, the following preferred embodiments are specifically given and described in detail in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required to be used in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0062] Figure 1 It is a schematic flow chart of the zero-trust API dynamic access control method provided by the embodiment of the present disclosure.

[0063] Figure 2 For Figure 1 It is a schematic flow chart of the generation method of the unified decentralized digital identity identifier in

[0064] Figure 3 For Figure 1Flow diagram of the configuration method for the basic governance structure of the DAO in

[0065] Figure 4 For Figure 1 Flow diagram of the method for determining the initial access policy corresponding to each user by voting of DAO members in

[0066] Figure 5 For Figure 1 Flow diagram of the method for obtaining comprehensive risk assessment information in

[0067] Figure 6 For Figure 1 Flow diagram of the method for obtaining access control policies in

[0068] Figure 7 Flow diagram of the method for optimizing the initial access policy provided by the embodiments of the present disclosure.

[0069] Figure 8 Structural diagram of a computer device provided by the embodiments of the present disclosure. Detailed implementation manners

[0070] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0071] It should be clear that the embodiments of the present disclosure are described through specific specific examples below. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.

[0072] It should be noted that the following description relates to various aspects of embodiments within the scope of the appended claims. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is for illustrative purposes only. Based on this disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of the aspects set forth herein can be used to implement an apparatus and / or practice a method. Additionally, this apparatus and / or method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.

[0073] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure schematically. The diagrams only show the components related to the present disclosure and are not drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0074] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the aspects can be practiced without these specific details.

[0075] Referring to Figure 1 , this application discloses a zero-trust API dynamic access control method, including:

[0076] S100, collecting the original identity information of a user in different systems, processing all the original identity information through a preset aggregation policy, and generating a unified decentralized digital identity identifier for the user based on the blockchain.

[0077] Suppose there are an office automation system, a customer relationship management system, and a financial system within an enterprise. The identity information of a user in the office automation system may be an employee number, name, and department. In the customer relationship management system, there may be a customer account and contact information. In the financial system, there is a financial permission identifier, etc. The original identity information of the user is collected from these different systems through a data interface; then all the original identity information is processed through a preset aggregation policy, and a unified decentralized digital identity identifier for the user is generated based on the blockchain. This identifier is stored on the blockchain and has the characteristics of being immutable and traceable.

[0078] In this step, the identity information of users in different systems is integrated to facilitate unified management and identification, avoiding management chaos caused by scattered identity information. The digital identity identifier generated based on the blockchain has the characteristics of decentralization and immutability, which can effectively prevent the forgery and tampering of identity information and improve the security of user identities. The unified digital identity identifier of users can be used commonly in different systems to achieve cross-system identity mutual recognition and improve the collaboration efficiency between systems.

[0079] S200, configure the basic governance structure of the DAO on the blockchain network;

[0080] Among them, the basic governance structure includes one or more of user identity management, voting mechanism, decision-making process, deployed smart contract addresses, and contract interfaces.

[0081] In this step, the basic governance structure of the DAO can implement a decentralized decision-making mechanism, avoiding the decision-making monopoly of a single centralized institution, and improving the fairness and transparency of decision-making. The use of smart contracts enables decisions to be automatically executed, reducing human intervention and improving the execution efficiency and accuracy. The characteristics of the blockchain ensure the security and credibility of user identity management, voting records, and decision-making processes, preventing data tampering and malicious attacks.

[0082] S300, based on the basic governance structure, determine the initial access policy corresponding to each user by voting of DAO members.

[0083] In this step, the initial access policy is determined by the voting of DAO members, fully reflecting the collective will, avoiding the subjective biases of individual personnel, and improving the rationality and fairness of the policy. If the initial access policy needs to be adjusted, a vote can be initiated again to achieve dynamic update of the policy to adapt to different business requirements and security environments. The transparency and traceability of the voting process enhance the trust among members and make the formulation of access policies more credible.

[0084] S400, collect multi-dimensional information for the initiated access, and conduct multi-dimensional risk assessment on the multi-dimensional information based on preset multi-dimensional weights to obtain comprehensive risk assessment information;

[0085] The multi-dimensional information includes time-dimensional information, space-dimensional information, device-dimensional information, and network-dimensional information.

[0086] In this step, by comprehensively considering multi-dimensional information such as time, space, devices, and networks, the access risk can be evaluated more comprehensively, avoiding the limitations of single-dimensional evaluation. By presetting multi-dimensional weights, the focus of risk assessment can be flexibly adjusted according to different business requirements and security policies, achieving more refined access control. Combining dynamic access policies and multi-dimensional risk assessment can timely detect and prevent potential security threats, improving the security of the system.

[0087] S500. Obtain an access control policy based on the comprehensive risk assessment information and the initial access policy.

[0088] Specifically, according to the risk level reflected by the comprehensive risk assessment information and in combination with the initial access policy, dynamically adjust the access rights of users, thereby generating the final access control policy to ensure the security and availability of the system.

[0089] The zero-trust API dynamic access control method disclosed in this application. The entire solution is based on the zero-trust concept, defaulting to distrusting any users and devices. Through dynamic access control and multi-dimensional risk assessment, it ensures that only authorized users and devices can access system resources, improving the security of the system. At the same time, it can adapt to different business systems and security environments, realizing decentralized governance and management through blockchain and DAO, and realizing dynamic access control through machine learning and multi-dimensional risk assessment, with strong flexibility and scalability. On the premise of ensuring security, through personalized access policies and real-time access control decisions, unnecessary access restrictions are reduced, improving the access efficiency and experience of users.

[0090] Refer to Figure 2 , for "processing all the original identity information through a preset aggregation policy and generating a unified decentralized digital identity identifier for the user based on the blockchain" in S100, that is, the generation method of the unified decentralized digital identity identifier, specifically includes:

[0091] A100. Collect the original identity information of the user in different systems.

[0092] In modern digital ecosystems, the identity information of users is usually scattered in multiple independent systems, such as social media accounts, emails, bank accounts, government departments, etc. These original identity information includes, but is not limited to: the basic identity attributes of the user (such as name, age, address), behavioral characteristics (such as transaction history, credit record), authentication credentials (such as digital certificates, biometric features), etc. Establish connections with each source system through API interfaces or authorization protocols (such as OAuth 2.0) to obtain the identity information of the user after authorization.

[0093] Comprehensively collect the user's identity information in different systems to provide a rich data foundation for generating a unified digital identity identifier in the follow-up; the identity information of different systems complements each other, can more comprehensively and accurately reflect the user's true identity characteristics, and helps to improve the credibility and integrity of the digital identity.

[0094] A200, through zero-knowledge proof technology, performs privacy protection processing on each original identity information to generate a corresponding encrypted identity data packet.

[0095] To protect user privacy, the system uses zero-knowledge proof (Zero-Knowledge Proof, ZKP) technology to process the collected information. Specifically: generate zero-knowledge proofs for each type of identity information: use algorithms such as Schnorr protocol or zk-SNARKs to create proofs for identity attributes, and the proofs can verify the authenticity of the information without exposing the specific content. For example, it can prove that "the age is greater than 18 years old" without exposing the actual age.

[0096] Then, convert the identity information from different sources into a unified data format, establish an attribute mapping relationship, solve the semantic differences across systems, and generate a standardized identity attribute descriptor; finally, encrypt and package the zero-knowledge proof and the normalized data, encrypt it using the user's public key to ensure that only the user himself can decrypt it, and add a digital signature to ensure data integrity. The final output encrypted identity data packet EIP contains: encrypted original identity attributes, corresponding zero-knowledge proofs, data source proofs, timestamps, and signature information.

[0097] Taking the user's ID number as an example, the zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) algorithm in zero-knowledge proof technology can be used. This algorithm allows proving that the ID number is valid without revealing the specific content of the ID number.

[0098] First, take the ID number as the input, and generate a proof through a series of mathematical operations. This proof can prove to the verifier that the ID number meets certain specific conditions (such as correct format, conforming to the ID coding rules, etc.) without revealing the ID number itself; then, encrypt the original identity information and the generated proof together to generate an encrypted identity data packet. For example, use the AES (Advanced Encryption Standard) algorithm to encrypt this information to generate an encrypted data packet.

[0099] In this step, zero-knowledge proof technology plays an important role in protecting user privacy. Without revealing the specific content of the user's original identity information, relevant verification operations can still be carried out, greatly enhancing the security of the user's identity information. Even if the encrypted identity data packet is stolen during transmission or storage, the attacker cannot obtain the user's sensitive information, effectively preventing the leakage of user privacy.

[0100] A300, verify the validity of the identity information for each encrypted identity data packet, and mark the encrypted identity data packet that passes the verification as the target data packet.

[0101] Specifically, homomorphic encryption technology can be used to allow data processing and verification in the encrypted state. The specific implementation includes: verifying the authenticity of the digital signature, checking the correctness of the zero-knowledge proof, verifying the credibility of the data source, and confirming the validity of the timestamp; using fully homomorphic encryption (FHE) or partially homomorphic encryption (PHE) schemes; performing calculations and comparisons of identity information in the encrypted domain to maintain privacy during the data processing process.

[0102] Furthermore, for each encrypted identity data packet, the validity verification can be carried out according to the characteristics and requirements of different identity information. For example, for a mobile phone number, verification can be carried out by sending a verification code and requiring the user to enter the received verification code to verify whether the mobile phone number can receive information normally; for an ID card number, it can be compared with the identity information system of the public security department to verify its authenticity and validity. Only the encrypted identity data packets that pass these verifications are marked as target data packets.

[0103] Through this step, it can be ensured that the identity information entering the subsequent processing process is real and valid; through the validity verification, invalid or false identity information can be filtered out, improving the accuracy and credibility of the digital identity identifier, and avoiding the situation of incorrect or misused digital identity identifiers caused by using invalid information.

[0104] A400, aggregate all the target data packets to generate a unified encrypted data packet for the user.

[0105] Specifically, identify and merge duplicate identity attributes, establish the association relationship between the attributes, and generate a unified encrypted identity representation.

[0106] The unified encrypted data packet includes: the merged set of encrypted identity attributes, verification status information, attribute association graph, and encrypted metadata information.

[0107] In this step, the scattered and verified identity information is integrated into a unified data packet for convenient subsequent processing and management; encrypting the data packet uniformly makes the user's identity information more centralized and orderly, reduces data redundancy and dispersion, and improves data processing efficiency and maintainability.

[0108] A500. Establish a blockchain network according to the determined blockchain platform and network construction method, and deploy a smart contract based on the uniformly encrypted data packet. The smart contract contains the mapping relationship between the uniformly encrypted data packets of all users and the blockchain addresses.

[0109] Specifically, select a suitable blockchain platform, such as Ethereum. According to the network construction method of Ethereum, build a private or consortium blockchain network; then, write a smart contract using the Solidity language. The smart contract contains a mapping table for storing the mapping relationship between the uniformly encrypted data packets of all users and the blockchain addresses; deploy the written smart contract to the blockchain network, and store the uniformly encrypted data packets of users and the corresponding blockchain address information in the smart contract.

[0110] A smart contract is a self-executing contract whose terms and conditions are written into the blockchain in the form of programming code. They can automatically execute the contract agreement when specific conditions are met, thereby reducing the dependence on intermediaries, improving the efficiency and transparency of transactions. The emergence of smart contracts makes the execution process of traditional contracts more automated and decentralized.

[0111] In this embodiment, the characteristics of the blockchain such as decentralization, immutability, and traceability provide a high degree of security and credibility for the storage and management of user identity information; the use of smart contracts enables the mapping relationship of user identity information to be automatically and accurately executed and recorded, avoiding human intervention and errors; at the same time, the openness and transparency of the blockchain network also facilitate the sharing and verification of identity information between different systems.

[0112] A600. Generate a decentralized identifier according to the W3C DID specification.

[0113] Specifically, according to the W3C DID specification, use a specific algorithm to generate a decentralized identifier (DID). For example, use the UUID (Universally Unique Identifier) algorithm to generate a unique identifier, and then format it according to the DID specification format, such as: did:example:123456789.

[0114] In this step, the W3C DID specification is a standardized decentralized identity identification scheme. The digital identity identifier generated according to this specification has good interoperability and universality.

[0115] A700 embeds a unified encrypted data packet into a decentralized identifier to generate a unified decentralized digital identity identifier for the user, and records the information containing the unified decentralized digital identity identifier on the blockchain network.

[0116] In this embodiment, the user's unified encrypted data packet is embedded into this decentralized identifier to form a complete unified decentralized digital identity identifier. Finally, this digital identity identifier information is recorded as a transaction on the blockchain network, and its immutability and traceability are ensured through the consensus mechanism of the blockchain. That is, the unified encrypted data packet of a single user can be embedded into the decentralized identifier, a document regarding the mapping relationship between the two can be established, and then the document can be signed with a private key to ensure the integrity and authenticity of the document.

[0117] Embedding the unified encrypted data packet into the decentralized identifier enables the digital identity identifier to contain the user's complete identity information while ensuring information security. Recording the digital identity identifier information on the blockchain network ensures the authenticity, integrity, and immutability of the digital identity identifier, providing a trusted digital identity for the user.

[0118] The method for generating the unified decentralized digital identity identifier disclosed by A100 - A700 effectively protects the user's original identity information through zero - knowledge proof technology and encryption processing, realizes the verification and use of identity information without disclosing sensitive information, and greatly reduces the risk of user privacy leakage; through validity verification and blockchain recording, the user's digital identity identifier has high authenticity, integrity, and immutability, improving the credibility of identity information and facilitating reliable identity verification in different systems and scenarios; integrating the user's identity information in different systems into a unified decentralized digital identity identifier facilitates the user's management and use of their own identity information, and also facilitates the sharing and mutual recognition of identity information between different systems; a reliable digital identity identifier is the basis for the development of the digital economy, and this solution provides a secure and trusted identity verification mechanism for various transactions and activities in the digital economy, contributing to the healthy development of the digital economy.

[0119] Refer to Figure 3 , for "configuring the basic governance structure of the DAO on the blockchain network" in S200, that is, the configuration method of the basic governance structure of the DAO, specifically includes:

[0120] B100 configures a member management contract, a proposal management contract, an execution contract, and an asset management contract on the blockchain network.

[0121] Specifically, a suitable blockchain platform can be selected, such as Ethereum; Solidity language is used to write each smart contract. After writing, these contracts are deployed to the blockchain network through Ethereum's development tools (such as Truffle or Remix).

[0122] Each contract is responsible for different functions, making the code structure clear and easy to maintain and expand. For example, if the voting rules for a proposal need to be modified, only the proposal management contract needs to be modified, without affecting the functions of other contracts. Different contracts handle different business logics, improving the security and reliability of the system. The member management contract is specifically responsible for member identity management, the proposal management contract focuses on proposal handling, the execution contract ensures the execution of the voting results, and the contract management contract manages the incentive mechanism. Each contract collaborates with and is independent of each other.

[0123] B200, establish a DAO on the blockchain network and handle user identity management through the member management contract.

[0124] Among them, user identity management includes the registration, withdrawal, and permission management of DAO members; the voting mechanism is executed through the proposal management contract, which is used to handle the submission, discussion, and voting processes of policy proposals; the decision-making process is executed through the execution contract, which is used to ensure the automatic execution of the voting results and policy updates; the incentive mechanism of the DAO is managed through the asset management contract.

[0125] Specifically, for user identity management: when a member wants to join the DAO, they call the registerMember function of the member management contract for registration. For example, the user initiates a transaction in their wallet, calls this function and passes in their wallet address, and the contract will mark this user as a member and assign default permissions. When a member wants to withdraw, they call the exitMember function. The administrator can call the setMemberPermissions function to adjust the member's permission level.

[0126] For proposal handling: members can submit proposals through the submitProposal function of the proposal management contract, describing the specific content of the proposal. Other members can call the vote function to vote on the proposal, supporting or opposing it. The proposal initiator or administrator can call the closeProposal function to close the voting period of the proposal at an appropriate time.

[0127] For executing the voting results: the execution contract will call the executeProposal function to perform corresponding operations according to the voting results of the proposals in the proposal management contract. For example, if the proposal is about the use of DAO funds, the execution contract can transfer the funds to the specified address according to the voting results.

[0128] The configuration method of the basic governance structure of the DAO disclosed in B100 - B200. All operations are executed on the blockchain through smart contracts, featuring high automation and transparency. Members can view the operation status of the DAO at any time, including the member list, proposal content, voting results, etc., ensuring the fairness and impartiality of the DAO. The characteristics of the blockchain guarantee the security and immutability of the contract execution and data storage. Once the member registration information, proposal content, and voting results are recorded on the blockchain, they cannot be maliciously modified, protecting the rights and interests of DAO members. Through the incentive mechanism, the enthusiasm and participation of members can be stimulated. Members can obtain rewards by contributing to the DAO, thus promoting the development and growth of the DAO.

[0129] Refer to Figure 4 , the method of "determining the initial access policy corresponding to each user through the voting of DAO members" in S300 specifically includes:

[0130] S310, based on all different systems, determine the access permission item set and the DAO member role set.

[0131] Specifically, the access permission item set is P, P = {p1, p2, …, p n}, where n is the total number of access permission items. The DAO member role set is R, R = {r1, r2, …, r m}, where m is the total number of roles.

[0132] For example, p1 can represent whether there is the permission to read data, p2 can represent whether there is the permission to write data, etc.

[0133] Furthermore, a weight w i can also be assigned to each permission item p i , and the sum of all weights is 1. The size of the weight can reflect the importance of the access permission item in the overall access policy.

[0134] For the DAO member role set, for example, r1 is the administrator role, r2 is the ordinary member role, etc.

[0135] Furthermore, a role weight s j can also be assigned to each role r j , and the sum of all weights is 1. The role weight can reflect the influence of different roles in the voting decision.

[0136] Through this step, the access permission item set and the DAO member role set can be clarified, enabling subsequent voting and policy formulation to have clear objects and scopes. Members clearly know which permissions to vote on during voting and the roles of different roles in this process. Classifying and organizing permissions and roles helps the DAO effectively manage and organize resources and personnel. Different systems correspond to different permissions, and different roles correspond to different responsibilities, improving the efficiency and accuracy of management.

[0137] S320. Obtain the voting results of DAO members on each access permission item of the user according to the access permission item set and the DAO member role set.

[0138] DAO members vote on each permission item of each user, and the voting results are preferably represented by scores.

[0139] Suppose the DAO member set is M = {m1, m2, …, m k}, and the voting score of member m l on the access permission item p i of user u is v l,i . The scoring range can be set as [0, 1], where 0 means not granting this permission at all, and 1 means fully granting this permission.

[0140] Or DAO members vote on each permission item according to their own judgments, and the voting results can be "agree", "disagree" or "abstain". For example, member A votes "agree" on the "right to view financial statements" and "disagree" on the "right to transfer funds", etc. The voting results will be recorded on the blockchain, and can be conveniently queried and statistically analyzed through smart contracts.

[0141] In this step, determining the access permissions of users through member voting reflects the democracy of the DAO. Each member has the opportunity to express their opinions, making the decision-making more fair and just. The voting results are recorded on the blockchain, which has the characteristics of being immutable and traceable, ensuring the transparency of the voting process. Members can view the voting records at any time to supervise the fairness of the decision-making.

[0142] S330. Determine the comprehensive evaluation information of each access permission item based on the voting results of each DAO member and the role weights of the corresponding DAO members.

[0143] Specifically, the comprehensive evaluation information is S i :

[0144]

[0145]

[0146] Among them, role(ml ) is a DAO member m l The role you belong to, For member m l The weight of the role, v l,i For member m l Access rights for users i The voting result (i.e., score), m is the total number of roles of DAO members, is the weight of the jth role.

[0147] Different roles have different responsibilities and expertise in a DAO. By assigning different weights to different roles, the influence of different roles in decision-making can be more reasonably reflected. For example, administrators usually have more experience and a more comprehensive perspective, and their opinions should have a higher weight in decision-making. The weighted calculation method makes decisions not only based on the number of votes, but also takes into account the roles and professional backgrounds of members, which improves the scientificity and rationality of decision-making.

[0148] S340: Determine an initial access policy corresponding to each user based on comprehensive evaluation information of all access permission items.

[0149] According to the comprehensive score S of each permission item i and a preset threshold θ (e.g. θ = 0.5) to determine whether user u is granted the permission. i ≥θ, then user u is granted permission item p i ; otherwise, the permission is not granted.

[0150] Through this embodiment, the initial access strategy of each user is determined based on the voting results and comprehensive evaluation information, and can be customized according to the user's actual situation and the needs of the DAO. Different users may have different responsibilities and needs. In this way, appropriate access rights can be provided to each user; reasonable access strategies can effectively control user access to system resources and reduce security risks. Only authorized users can access specific resources to prevent the leakage and abuse of sensitive information.

[0151] The initial access policy corresponding to each user is determined through the voting of DAO members as disclosed in S310 - S340. Determining the initial access policy of users through member voting not only reflects the democracy of the DAO but also improves the scientific nature of decision - making through the setting of role weights. This method makes the decision - making process more reasonable and fair, and can fully consider the opinions and professional backgrounds of different members. Determining the access policy of users based on comprehensive evaluation information can ensure that users only have the necessary access rights, improving the security and compliance of the system. At the same time, the transparency and traceability of the voting process also help to meet compliance requirements. Members participating in voting to decide the access policy of users enhances their sense of participation and responsibility, and they will pay more attention to the operation and management of the DAO and actively offer suggestions for the development of the DAO. As the DAO develops and business requirements change, the access policy of users can be adjusted by voting again. This flexibility enables the DAO to better adapt to changes and maintain efficient operation.

[0152] In this embodiment, the time - dimension information includes abnormal information of the requested access time; the space - dimension information includes credibility information of the access location; the device - dimension information includes status information of the device initiating the access; and the network - dimension information includes security information of the network connection.

[0153] Refer to Figure 5 For "performing multi - dimensional risk assessment on multi - dimensional information based on preset multi - dimensional weights to obtain comprehensive risk assessment information" in S400, that is, the method for obtaining comprehensive risk assessment information, specifically includes:

[0154] C100, analyzing the time - dimension information based on the preset access time range corresponding to the user to obtain the time - dimension assessment result.

[0155] Suppose a system sets the preset access time range of a user as 9:00 - 17:00 on weekdays. The system records the access time of the user each time. When the user initiates an access, its access time information is extracted. For example, user A initiates an access at 10:30 on Friday. This time is within the preset access time range, and it can be determined that the risk of this access in the time dimension is relatively low. If user A initiates an access at 14:00 on Saturday, which exceeds the preset access time range, then it is determined that the risk of this access in the time dimension is relatively high. Corresponding scores can be set for different time - dimension risk situations. For example, the risk score for accessing within the preset time range is 10 points (with a full score of 100 points, and the lower the score, the lower the risk), and the risk score for accessing outside the preset time range is 80 points.

[0156] In this step, by analyzing the access time, it is possible to promptly detect the user's access behavior at non-preset times, effectively preventing criminals from exploiting the security vulnerabilities of the system during non-working hours for attacks or data theft; most businesses have their specific working hours, and restricting the access time can ensure that the user's access behavior conforms to the business logic, improving the security and stability of the system.

[0157] C200, analyze the spatial dimension information to obtain the spatial dimension evaluation result.

[0158] Specifically, the user's spatial location information can be obtained through methods such as IP address location and GPS location. Assume that the system presets the user's access spatial range within the company's office area (determined by the IP segment range of the office area and the geographical fence of GPS positioning). When the user initiates an access, obtain their IP address or GPS location information. If the user's IP address is within the IP segment of the company's office area, or their GPS positioning shows within the geographical fence of the office area, it is determined that the risk of this access in terms of spatial dimension is relatively low; if the user's IP address comes from a certain region abroad, or the GPS positioning shows in a non-preset spatial range such as a remote area, it is determined that the risk of this access in terms of spatial dimension is relatively high. Risk scores can also be set, for example, the risk score for accessing within the preset spatial range is 15 points, and the risk score for accessing outside the preset spatial range is 85 points.

[0159] In this step, restricting the user's access space can effectively prevent illegal access from external non-trusted areas and reduce the risk of network attacks; within a specific spatial range, the system can better monitor and manage the user's access behavior to ensure that sensitive data is not leaked to insecure areas.

[0160] C300, analyze the device dimension information to obtain the device dimension evaluation result.

[0161] Specifically, the system can pre-register the device information that users can use, including the device model, serial number, operating system version, etc. When the user initiates an access, obtain their device information and compare it with the pre-registered information. For example, user B has always used a laptop with the model XYZ123 to access the system. If the device information used for this access is consistent with the registered information, it is determined that the risk of this access in terms of device dimension is relatively low; if user B uses an unregistered tablet for access, it is determined that the risk of this access in terms of device dimension is relatively high. Corresponding risk scores can be set, for example, the risk score for accessing with a registered device is 20 points, and the risk score for accessing with an unregistered device is 90 points.

[0162] In this step, the analysis of device information can ensure that only authorized devices can access the system, prevent unauthorized individuals from using others' devices for access, protect the security of the system and data, ensure that the devices used by users meet the requirements and standards of the system, and avoid system failures or data losses caused by device incompatibility.

[0163] C400, analyze the network dimension information to obtain the network dimension evaluation result.

[0164] Specifically, the analysis of network dimension information can include network type (such as Wi-Fi, mobile data network), network security (whether it is an encrypted network), etc. Assume that the system presets that users should access through the encrypted Wi-Fi network within the company. When a user initiates an access, obtain their network information. If the user is using the encrypted Wi-Fi network within the company, it is determined that the risk of this access in the network dimension is relatively low; if the user is using a public unencrypted Wi-Fi network, it is determined that the risk of this access in the network dimension is relatively high. Risk scores can be set, such as the risk score for accessing with a preset secure network is 25 points, and the risk score for accessing with an insecure network is 95 points.

[0165] In this step, using a secure network can effectively prevent security threats such as network eavesdropping and man-in-the-middle attacks, and protect the transmission security of user data; a stable network environment can ensure the normal operation of the system, improve the user's access experience and business processing efficiency.

[0166] C500, based on the preset multi-dimensional weights, respectively perform weighted summation on the time dimension evaluation result, space dimension evaluation result, device dimension evaluation result, and network dimension evaluation result to obtain the comprehensive risk assessment information.

[0167] Among them, the preset multi-dimensional weights include time dimension weight, space dimension weight, device dimension weight, and network dimension weight.

[0168] In C500, the comprehensive risk assessment information = time dimension weight × time dimension evaluation result + space dimension weight × space dimension evaluation result + device dimension weight × device dimension evaluation result + network dimension weight × network dimension evaluation result.

[0169] Suppose the preset time dimension weight is 0.2, the space dimension weight is 0.3, the device dimension weight is 0.3, and the network dimension weight is 0.2. The risk score of user C's time dimension evaluation result is 80 points, the risk score of the space dimension evaluation result is 85 points, the risk score of the device dimension evaluation result is 90 points, and the risk score of the network dimension evaluation result is 95 points. Then the score of the comprehensive risk assessment information is: 80×0.2 + 85×0.3 + 90×0.3 + 95×0.2 = 87.5 points. According to the set risk level classification standard (such as 0 - 30 points for low risk, 31 - 60 points for medium risk, 61 - 100 points for high risk), it can be determined that user C's this access is a high risk.

[0170] In this step, considering the information of multiple dimensions and performing weighted summation can more comprehensively and objectively evaluate the risk of user access, avoiding the limitations of single - dimension evaluation; the comprehensive risk assessment information can provide an accurate basis for the security management of the system, and the system can take corresponding measures according to the risk level, such as restricting access, requiring additional authentication, etc.

[0171] The method for obtaining the comprehensive risk assessment information disclosed in C100 - C500, through multi - dimensional risk assessment, monitors and evaluates user access from multiple aspects such as time, space, device, and network, can comprehensively and effectively identify and prevent various potential security risks, and improve the overall security of the system; different users and different business scenarios may have different risk sensitivities to each dimension. By presetting multi - dimensional weights, personalized risk assessment can be carried out according to the actual situation, making the assessment results more in line with actual needs; as time, user behavior, and system environment change, the risk situation of each dimension will also change. This solution can perform multi - dimensional risk assessment on user access in real time, realize dynamic risk management, adjust security policies in a timely manner, and ensure the safe and stable operation of the system; on the premise of ensuring security, this solution can perform flexible security control according to the comprehensive risk assessment information, and for low - risk access, unnecessary verification steps can be reduced, improving the user's access efficiency and experience.

[0172] Refer to Figure 6 , for S500 "Obtain the access control policy according to the comprehensive risk assessment information and the initial access policy", that is, the method for obtaining the access control policy specifically includes:

[0173] S510, define the risk level classification.

[0174] Specifically, according to the value range [0, 1] of the comprehensive risk assessment result Rtotal, the risk is divided into different levels. For example: Low risk: 0 ≤ Rtotal < 0.3; Medium risk: 0.3 ≤ Rtotal < 0.7; High risk: 0.7 ≤ Rtotal ≤ 1.

[0175] Taking an enterprise-level file management system as an example, the comprehensive risk assessment result \(R_{total}\) is obtained by weighted calculation of multiple factors such as the user's login behavior, operation frequency, and sensitivity of the accessed files. According to the value range of \(R_{total}\) within \([0, 1]\), the risks are divided into three levels: low, medium, and high. For example, a user who logs in to the system during normal working hours for a long time, only accesses ordinary business documents, and whose operation frequency also conforms to the daily work habits may have an \(R_{total}\) of 0.2 and be judged as a low-risk user; while a user who recently frequently tries to log in to different accounts and attempts to access confidential files may have an \(R_{total}\) reaching 0.8 and be judged as a high-risk user.

[0176] In this step, the clear risk level division enables the system to quickly and intuitively classify the comprehensive risks of users, facilitating subsequent adoption of corresponding measures according to different levels, providing a unified risk measurement standard for the entire access control process, and making the risk assessment results of different users comparable; different risk levels correspond to different processing strategies, which helps system administrators make decisions quickly and improve the efficiency of risk response.

[0177] S520, clarify the initial access policy.

[0178] The initial access policy stipulates the access permissions of users under normal circumstances, usually including the list of resources allowed to be accessed, access operation types (such as read, write, modify, etc.), and time limits for access, etc.

[0179] Furthermore, still taking the enterprise-level file management system as an example, the initial access policy may stipulate that ordinary employees can access the business documents of their own departments from 9:00 to 17:00 on normal working days and can only perform read operations; department managers can, in addition to reading the documents of their own departments during the same period, also modify and write some documents; senior management personnel can access more sensitive enterprise strategic documents during working hours.

[0180] In this step, the initial access policy provides clear rules and scopes for users' access behaviors, ensuring that users' accesses under normal circumstances are orderly and meet the enterprise's security and management requirements; users clearly know their access permissions, can quickly find the resources they need and perform corresponding operations, reducing the time waste caused by unclear permissions; the initial access policy provides a basis for adjusting the access policy according to the risk level later and is an important basis for ensuring the basic security of the system.

[0181] S530, adjust the access policy according to the risk level.

[0182] Formulate corresponding access policy adjustment rules for different risk levels; for example, for low risks: maintain the initial access policy unchanged because the risk of the user's access behavior is low at this time, and the system can trust the user's operations. For medium risks: take partial restrictive measures, such as reducing the number of resources allowed to be accessed, restricting certain sensitive operations, or shortening the access time, etc. For high risks: take strict restrictive measures, such as prohibiting the user from accessing all resources or requiring the user to perform additional authentication.

[0183] Furthermore, assume that an employee has been operating according to the normal work process and their risk assessment is low risk (Rtotal = 0.2), then maintain their initial access policy unchanged. For example, this employee can still access and read the business documents of their own department from 9:00 to 17:00.

[0184] If a certain user's recent operation frequency is abnormal and the risk assessment is medium risk (Rtotal = 0.5), the system can take partial restrictive measures. For example, a user who could originally access the documents of multiple departments can now only access the documents of their own department; or a user who could originally perform modification operations can now only perform read operations; or shorten their access time from 9:00 - 17:00 to 10:00 - 16:00.

[0185] When the risk assessment of a certain user is high risk (Rtotal = 0.8), the system takes strict restrictive measures. For example, prohibit this user from accessing all resources until they perform additional authentication, such as re - verifying their identity through methods like SMS verification codes, face recognition, etc.

[0186] In this step, adjusting the access policy according to the user's real - time risk level can timely respond to different degrees of risks and improve the security of the system; for low - risk users, maintaining the initial policy ensures that their normal work is not affected; for medium - and high - risk users, taking corresponding restrictive measures can minimize the impact on the business while ensuring security; the strict high - risk restrictive measures can deter potential malicious users and reduce the possibility of the system being attacked.

[0187] S540, generate the final access control policy.

[0188] According to the above - mentioned adjustment rules, combined with the comprehensive risk assessment information and the initial access policy, generate the final access control policy.

[0189] Specifically, based on the previous risk levels and the adjusted initial access policies, the final access control policy is generated. For example, for an ordinary employee with a low risk level, the final access control policy is their initial access policy, which is to access and read the business documents of their own department from 9:00 to 17:00; for a department manager with a medium risk level, the final access control policy may be to only access some documents of their own department and only perform read operations from 10:00 to 16:00; for a senior management personnel with a high risk level, the final access control policy may be to prohibit access to all resources until additional authentication is completed.

[0190] The final access control policy provides clear and specific rules for the access behavior of users. Based on this, the system can accurately judge and process users' access requests. The clear policy enables the system to conveniently implement access control and ensure that users' access behaviors comply with the security requirements of the system. The final access control policy clarifies users' access rights and restrictions. In case of security issues, responsibility can be traced according to the policy.

[0191] The method for obtaining the access control policy disclosed in S510 - S540 can timely detect and respond to security risks of different levels by classifying risk levels and adjusting access policies according to risks, effectively protecting the security of system resources; the overall solution has the ability of dynamic adjustment, can flexibly adjust access policies according to users' real - time risk situations, and adapt to different security scenarios and changes in user behaviors; on the premise of ensuring security, normal access rights are maintained for low - risk users, unnecessary restrictions are reduced, and users' work efficiency and experience are improved; access control policies can be formulated and adjusted according to the enterprise's security policies and relevant regulatory requirements to ensure that the access management of the system complies with compliance requirements.

[0192] Refer to Figure 7 , before obtaining the access control policy according to the comprehensive risk assessment information and the initial access policy, the disclosed zero - trust API dynamic access control method of the present application further includes: optimizing the initial access policy. Specifically, the method for optimizing the initial access policy includes:

[0193] D100, collecting the historical access data and security events of users based on a unified decentralized digital identity identifier, pre - processing the historical access data and security events to obtain a standard data set.

[0194] Specifically, a unified decentralized digital identity identifier (DID) is used to uniquely identify users, and the historical access data and security events of users are collected through data sources such as system logs and API call records. The historical access data may include users' access time, accessed API interfaces, request parameters, response status, etc.; the security events may include information such as abnormal logins and malicious attack attempts.

[0195] Data preprocessing includes data cleaning, data normalization, and data decoding. Data cleaning is used to remove duplicate, incorrect, or incomplete data records; data normalization is used to convert data with different ranges and scales into a unified scale, and common methods include Min-Max normalization and Z-Score normalization; data encoding is used to convert data such as user roles and security event types into numerical types, and common methods include One-Hot Encoding.

[0196] In this step, cleaning and standardization operations can ensure the quality of the data and avoid affecting subsequent analysis due to incorrect or inconsistent data; decentralized digital identity identifiers can protect user privacy and prevent the leakage or abuse of user identity information; feature extraction makes the data more structured and analyzable, facilitating the processing of subsequent machine learning models.

[0197] D200, train a preset machine learning model with a standard dataset, and record the trained preset machine learning model as the target model.

[0198] Among them, the preset machine learning model can select common machine learning models such as logistic regression, decision tree, random forest, and support vector machine.

[0199] Specifically, select a suitable machine learning model, such as a random forest classifier. Random forests have the ability to handle high-dimensional data and handle missing values, and are suitable for analyzing user access behaviors and security risks; divide the standard dataset into a training set and a test set according to a ratio of 80:20. Use the training set to train the random forest model, and by continuously adjusting the model parameters (such as the number of trees, the depth of the trees, etc.), enable the model to learn the characteristics of normal and abnormal user access behaviors. During the training process, use the test set to evaluate the model until the model reaches satisfactory accuracy and recall rates, and at this time, the trained target model is obtained.

[0200] In this step, the machine learning model can automatically learn patterns and rules from the data, discover potential security risks, and is more intelligent and adaptable than traditional rule-based methods; the trained target model can predict the future access behaviors of users and discover possible security threats in advance; as new data is continuously added, the target model can be continuously trained and optimized to improve the performance of the model.

[0201] D300, analyze the initial access policy based on the target model to obtain an optimized initial access policy.

[0202] Specifically, it includes: 1) Initial access policy characterization; that is, before analyzing the initial access policy with the target model, the policy needs to be first converted into a feature vector form that the target model can handle. Since the initial access policy covers various aspects of information, there are different characterization methods for different types of information.

[0203] User-related information includes user roles and user historical behavior metrics; user roles can be different user roles such as administrator, ordinary user, and visitor, and will be converted into numerical features using one-hot encoding. For example, if there are three roles: administrator, ordinary user, and visitor, then the administrator is represented by "100", the ordinary user by "010", and the visitor by "001". Continuous data such as user historical behavior metrics like historical access frequency and average access duration, although can be directly used, usually need to be normalized in order to have the same weight in the model.

[0204] 2) Information related to accessed resources, such as API type and resource sensitivity level; different types of APIs may have different security risks, and one-hot encoding is also used. For example, for three types of APIs: data query API, data modification API, and system configuration API, the data query API can be represented by "100". Resource sensitivity levels such as public, internal, and confidential will also be characterized through one-hot encoding.

[0205] 3) Information related to the access environment, such as access time and access location. The access time will convert the time information into different features, such as determining whether it is during working hours, or dividing a day into different time periods and then representing them with one-hot encoding. For example, a day is divided into four time periods: 0 - 6 o'clock, 6 - 12 o'clock, 12 - 18 o'clock, 18 - 24 o'clock, and the corresponding encoding is used to represent each time period. The access location determines the approximate geographical location based on the IP address, such as domestic, foreign, or specific to a province, city, etc., and then encoding is performed.

[0206] Combining the features of the above aspects together forms the feature vector of the initial access policy.

[0207] Using the target model for prediction specifically includes: inputting the feature vector into the trained target model. Since the model types are different, different output results will be obtained.

[0208] If the target model belongs to a classification model, such as a decision tree classifier, a random forest classifier, etc., the model will output a class label, such as "Allow access", "Restrict access", "Prohibit access".

[0209] If the target model is a regression model, such as linear regression or logistic regression, the model may output a risk score, which generally ranges from 0 to 1. The larger the value, the higher the risk.

[0210] Optimize the initial access policy according to the prediction results of the target model and the pre-set rules.

[0211] For optimization based on the risk score, when the risk score is higher than a certain threshold (e.g., 0.7), strict restrictive measures will be taken, such as prohibiting access to certain highly sensitive APIs or shortening the access time range. For medium-risk situations (risk score between 0.3 - 0.7), partial restrictions will be imposed in this case, such as adding additional authentication steps or reducing the number of allowed APIs; for low-risk situations (risk score below 0.3), the initial policy can be kept unchanged or the restrictions can be appropriately relaxed, such as appropriately widening the access time range.

[0212] For optimization based on the classification results, if the prediction result is "prohibit access", directly modify the initial access policy to prohibit all access; if the prediction result is "restrict access", the policy will be adjusted according to the specific situation, such as restricting the access frequency or reducing the accessible resources.

[0213] After the above steps, the analysis and optimization of the initial access policy are completed, and the optimized initial access policy is finally obtained.

[0214] Through the analysis and optimization of the target model, potential security vulnerabilities in the initial access policy can be discovered, adjusted in a timely manner, and the risk of system attacks can be reduced; on the premise of ensuring security, the access policy can be reasonably adjusted to reduce unnecessary restrictions and improve the access efficiency and experience of users; as user behavior and the security environment change, the target model can evaluate and optimize the access policy in real time, making the access policy dynamically adaptable.

[0215] D400, obtain the access control policy according to the comprehensive risk assessment information and the optimized initial access policy.

[0216] Specifically, integrate the comprehensive risk assessment information (such as the user's real-time risk score, risk level, etc.) with the optimized initial access policy. For example, if the comprehensive risk assessment shows that a certain user has a high risk level, and the optimized initial access policy allows the user to partially access some sensitive resources, then further restrict the user's access rights according to the risk level, such as only allowing viewing but not modification. Generate the final access control policy based on the integrated information. The access control policy will clearly stipulate the scope of resources that users can access, the time limit for access, the types of operations for access, etc. For example, for high-risk users, only allow access to some non-sensitive resources within a specific time period and only allow query operations.

[0217] In this step, by combining the comprehensive risk assessment information and the optimized initial access policy, a more accurate and practical access control policy can be formulated, effectively balancing security and efficiency; by comprehensively considering multiple factors, the access behavior of users can be comprehensively protected, reducing various security risks; the access control policy can be adjusted according to security regulations and enterprise internal regulations to ensure that the access management of the system complies with relevant compliance requirements.

[0218] The solution disclosed in D100 - D400, through a data-driven method, uses a machine learning model to optimize and adjust the access policy, can more accurately identify and prevent security risks, and improve the overall security of the system; on the premise of ensuring security, reasonably optimize the access policy, reduce unnecessary restrictions, improve the access efficiency and experience of users, and make security measures not cause too much interference to the normal operations of users; this solution can dynamically adjust the access control policy according to the historical behavior and real-time risk situation of users, adapting to the changing security environment and user needs; it can flexibly adjust the access control policy according to relevant security regulations and enterprise internal regulations to ensure that the access management of the system complies with compliance requirements.

[0219] The zero-trust API dynamic access control method disclosed in this application innovatively proposes the concept of a privacy protection digital identity bridge, realizes the secure aggregation of identity information through zero-knowledge proof and homomorphic encryption technologies; introduces a DAO governance mechanism to achieve decentralized identity authentication and authorization policy management; designs an adaptive dynamic access control mechanism that can make intelligent authorization decisions based on the results of real-time risk assessment; the entire system forms a closed loop, protecting user privacy while providing flexible and reliable access control.

[0220] Regarding the problems in the prior art, such as the dispersion of users' digital identity information, the cumbersome identity authentication process, and the poor user experience, the zero-trust API dynamic access control method disclosed in this application collects the original identity information of users in different systems, processes it through a preset aggregation strategy, and generates a unified decentralized digital identity identifier for users based on the blockchain. The characteristics of the blockchain enable the integration and unified management of users' identity information, which is no longer scattered in various different systems. In this way, when performing identity authentication, only this unified digital identity identifier needs to be verified, instead of separately authenticating in multiple systems, greatly simplifying the identity authentication process and thus enhancing the user experience.

[0221] Regarding the problems in the prior art, such as the centralized identity authentication server being prone to single-point failures and having the risk of user privacy leakage, the zero-trust API dynamic access control method disclosed in this application, based on the unified decentralized digital identity identifier generated by the blockchain, gets rid of the dependence on the centralized identity authentication server. The blockchain is a distributed ledger without a single central node, so there is no problem of single-point failure. At the same time, the encryption technology and consensus mechanism of the blockchain can ensure the security and privacy of users' identity information. The users' identity information is stored on the blockchain in an encrypted form, and only authorized nodes can access it, effectively reducing the risk of user privacy leakage. Configure the basic governance structure of the DAO (Decentralized Autonomous Organization) on the blockchain network, including user identity management, voting mechanism, decision-making process, etc. The decentralized characteristics of the DAO enable the management of identity and the formulation of access policies to no longer depend on a single centralized institution, but are jointly participated in and decided by community members, further enhancing the security and reliability of the system and reducing the risks brought by centralized management.

[0222] Regarding the problem in the prior art that the dynamic access control mechanism lacks effective protection for user privacy, the zero-trust API dynamic access control method disclosed in this application collects multi-dimensional information (time dimension information, space dimension information, device dimension information, network dimension information) of the initiated access for multi-dimensional risk assessment. In this process, for users' privacy information, such as space dimension information (which may involve the user's geographical location), etc., encryption and desensitization processing methods can be adopted to only extract the feature information related to risk assessment, without directly using the original privacy data, thus effectively protecting users' privacy while performing dynamic access control.

[0223] The zero-trust API dynamic access control method disclosed in this application, based on the unified decentralized digital identity identifier and DAO governance structure of the blockchain, makes the system have higher security. The decentralized architecture avoids single points of failure and prevents hackers from destroying the entire system or obtaining user information by attacking the central node. At the same time, the encryption and consensus mechanisms of the blockchain ensure the integrity and immutability of data, ensuring the security of user identity information and access policies.

[0224] The zero-trust API dynamic access control method disclosed in this application can more comprehensively and accurately evaluate the risk of access requests by collecting multi-dimensional information for risk assessment. For example, combining time-dimensional information can determine whether the user's access is within normal working hours; spatial-dimensional information can detect whether the user's access is from an abnormal geographical location. This multi-dimensional evaluation method can effectively prevent illegal access and improve the security of the system.

[0225] In the zero-trust API dynamic access control method disclosed in this application, the unified decentralized digital identity identifier simplifies the user's identity authentication process. Users do not need to perform complex authentication operations in different systems separately, improving the user's usage efficiency and convenience, and thus enhancing the user experience. Obtaining the access control policy based on the comprehensive risk assessment information and the initial access policy can achieve dynamic and flexible access control. For low-risk access requests, access permissions can be quickly granted, reducing the user's waiting time; for high-risk access requests, strict review and restrictions are carried out, ensuring security while minimizing the impact on the user's normal use. The basic governance structure of the DAO introduces a mechanism of community member voting, enabling each user to participate in the formulation and management of access policies. This democratic governance model not only enhances the user's trust and sense of belonging to the system but also makes full use of the wisdom and experience of community members to formulate more reasonable and effective access policies, promoting the healthy development of the system.

[0226] In the process of multi-dimensional risk assessment, the encryption and desensitization processing of user privacy information and the protection of user identity information by decentralized identity management both reflect the importance of this application to user privacy. This helps to establish the user's trust in the system and meets the current requirements and trends for user privacy protection.

[0227] In the second aspect, this application discloses a zero-trust API dynamic access control system for implementing the zero-trust API dynamic access control method disclosed in the first aspect of this application, specifically including:

[0228] A unified decentralized digital identity identifier generation module, configured to collect the original identity information of users in different systems, process all the original identity information through a preset aggregation policy, and generate a unified decentralized digital identity identifier of the user based on the blockchain;

[0229] A configuration module for configuring the basic governance structure of a DAO on a blockchain network; the basic governance structure includes user identity management, a voting mechanism, a decision-making process, deployed smart contract addresses, and contract interfaces;

[0230] An initial access policy determination module for determining the initial access policy corresponding to each user based on the basic governance structure through voting by DAO members;

[0231] A comprehensive risk assessment information acquisition module for collecting multi-dimensional information for initiating access and performing multi-dimensional risk assessment on the multi-dimensional information based on preset multi-dimensional weights to obtain comprehensive risk assessment information; the multi-dimensional information includes time-dimensional information, space-dimensional information, device-dimensional information, and network-dimensional information;

[0232] An access control policy acquisition module for obtaining an access control policy according to the comprehensive risk assessment information and the initial access policy.

[0233] The computer device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0234] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the zero-trust API dynamic access control method of the foregoing embodiments of the present disclosure.

[0235] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included in the protection scope of the present disclosure.

[0236] As Figure 8 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiments of the present disclosure. Figure 8The computer device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present disclosure.

[0237] As Figure 8 shown, the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.

[0238] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device, etc.; an output device including, for example, a display screen, etc.; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 8 a computer device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0239] Specifically, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processor, all or part of the steps of the zero-trust API dynamic access control method of the embodiments of the present disclosure are executed.

[0240] For the detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.

[0241] A computer-readable storage medium according to the embodiments of the present disclosure stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the zero-trust API dynamic access control methods of the foregoing embodiments of the present disclosure are executed.

[0242] The above computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or removable hard disk), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0243] For the detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, which will not be elaborated herein again.

[0244] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for illustrative purposes and for the convenience of understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0245] In the present disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0246] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a separate listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). In addition, the term "exemplary" does not mean that the described examples are preferred or better than other examples.

[0247] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.

[0248] Various changes, substitutions, and alterations to the technology described herein can be made without departing from the teachings defined by the appended claims. Additionally, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0249] The foregoing description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0250] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although numerous example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.

Claims

1. A zero-trust API dynamic access control method, characterized in that, Including: Collect the original identity information of users in different systems, and process all the original identity information through a preset aggregation strategy to generate a unified decentralized digital identity identifier for the users; Configure the basic governance structure of the DAO on the blockchain network; The basic governance structure includes one or more of user identity management, voting mechanism, decision-making process, deployed smart contract addresses, and contract interfaces; Based on the basic governance structure, determine the initial access policy corresponding to each user through the voting of DAO members; Collect multi-dimensional information for initiating access, and conduct multi-dimensional risk assessment on the multi-dimensional information based on a preset multi-dimensional weight to obtain comprehensive risk assessment information; The multi-dimensional information includes one or more of time dimension information, space dimension information, device dimension information, and network dimension information; Obtain an access control policy according to the comprehensive risk assessment information and the initial access policy.

2. The zero-trust API dynamic access control method according to claim 1, wherein, The processing of all the original identity information through a preset aggregation strategy to generate a unified decentralized digital identity identifier for the users includes: Collect the original identity information of users in different systems; Perform privacy protection processing on each original identity information through zero-knowledge proof technology to generate a corresponding encrypted identity data packet; Verify the validity of the identity information for each encrypted identity data packet, and record the encrypted identity data packet that passes the verification as the target data packet; Aggregate all the target data packets to generate a unified encrypted data packet for the users; Establish a blockchain network according to the determined blockchain platform and network construction method, and deploy a smart contract based on the unified encrypted data packet. The smart contract contains the mapping relationship between the unified encrypted data packet of all users and the blockchain address; Generate a decentralized identifier according to the W3C DID specification; Embed the unified encrypted data packet into the decentralized identifier to generate a unified decentralized digital identity identifier for the users, and record the information containing the unified decentralized digital identity identifier on the blockchain network.

3. The zero-trust API dynamic access control method according to claim 2, wherein The configuration of the basic governance structure of the DAO on the blockchain network includes: Configure one or more of a member management contract, a proposal management contract, an execution contract, and an asset management contract on the blockchain network; Establish a DAO on the blockchain network, and process user identity management through the member management contract; The user identity management includes the registration, withdrawal, and permission management of DAO members; execute the voting mechanism through the proposal management contract to handle the submission, discussion, and voting process of policy proposals; execute the decision-making process through the execution contract to ensure the automatic execution of the voting results and policy updates; manage the incentive mechanism of the DAO through the asset management contract.

4. The zero-trust API dynamic access control method according to claim 1, wherein The determination of the initial access policy corresponding to each user through the voting of DAO members based on the basic governance structure includes Based on all different systems, determine the set of access permission items and the set of DAO member roles; Obtain the voting results of each DAO member on each access right item for the user according to the set of access right items and the set of DAO member roles; Determine the comprehensive evaluation information of each access right item based on the voting results of each DAO member and the role weights of the corresponding DAO members; Determine the initial access policy corresponding to each user according to the comprehensive evaluation information of all access right items; 5. The zero-trust API dynamic access control method according to claim 4, wherein The comprehensive evaluation information is S i : Among them, role(m l ) is the role to which DAO member m l belongs, is the weight of the role to which member m l belongs, v l,i is the voting result of member m l on the user access permission item p i , m is the total number of roles of DAO members, is the weight of the j-th role.

6. The zero-trust API dynamic access control method according to claim 1, wherein The time dimension information includes abnormal information of the request access time; the space dimension information includes credibility information of the access location; the device dimension information includes status information of the initiating access device; the network dimension information includes security information of the network connection; The multi-dimensional risk assessment of the multi-dimensional information based on the preset multi-dimensional weights to obtain the comprehensive risk assessment information includes: Analyze the time dimension information based on the preset access time range corresponding to the user to obtain the time dimension assessment result; Analyze the space dimension information to obtain the space dimension assessment result; Analyze the device dimension information to obtain the device dimension assessment result; Analyze the network dimension information to obtain the network dimension assessment result; Based on the preset multi-dimensional weights, perform weighted summation on the time dimension assessment result, the space dimension assessment result, the device dimension assessment result, and the network dimension assessment result respectively to obtain the comprehensive risk assessment information.

7. The zero-trust API dynamic access control method according to claim 1, characterized in that Before obtaining the access control policy according to the comprehensive risk assessment information and the initial access policy, it further includes: Collect the historical access data and security events of the user based on the unified decentralized digital identity identifier, and preprocess the historical access data and the security events to obtain a standard data set; Train the preset machine learning model with the standard data set, and record the trained preset machine learning model as the target model; Analyze the initial access policy based on the target model to obtain the optimized initial access policy; Obtain the access control policy according to the comprehensive risk assessment information and the optimized initial access policy.

8. A computer device, characterized in that, The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the zero-trust API dynamic access control method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, This computer-readable storage medium stores computer instructions for causing a computer to execute the zero-trust API dynamic access control method according to any one of claims 1-7.

10. A computer program product, comprising computer instructions, characterized in that, When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.

Citation Information

Cited By

  • Access authority management method and system of industrial internet

    CN120474843A

  • Dynamic security authentication method for cross-platform information system integration

    CN121283598A